Global Threat Infrastructure
Nation-state C2 activity · Real-time IOC geo-distribution
8,197High-conf IPs
60Countries
40Attack paths
18,025Actor IOCs
13,680Persistent IPs
21APT Groups
Actors
Russia
China
North Korea
Iran
C2 Density
Critical
High
Medium
Low
Scroll to zoom · Drag to pan
Top C2 Countriesby high-conf IPs
1🇺🇸United States1,722
4,818 total
2🇨🇳China1,519
2,450 total
3🇭🇰Hong Kong901
1,406 total
4🇩🇪Germany599
1,239 total
5🇳🇱The Netherlands446
542 total
6🇫🇷France275
598 total
7🇸🇬Singapore264
709 total
8🇬🇧United Kingdom203
598 total
9🇳🇱Netherlands193
627 total
10🇷🇺Russia168
241 total
11🇯🇵Japan146
369 total
12🇨🇦Canada119
388 total
13🇮🇳India118
642 total
14🇨🇭Switzerland109
164 total
15🇧🇷Brazil104
487 total
Nation-State ActorsIOC · groups · routes
🇷🇺Russia10,996
8 APT groups23 attack routes
Top targets
→🇨🇳China644
→🇺🇸United States597
→🇭🇰Hong Kong307
TurlaSandwormGamaredonAPT28+2
🇰🇵North Korea6,618
4 APT groups17 attack routes
Top targets
→🇨🇳China442
→🇺🇸United States436
→🇭🇰Hong Kong162
KimsukyAPT37Lazarus GroupAPT38
🇨🇳China397
6 APT groups0 attack routes
Top targets
APT10Salt TyphoonVolt TyphoonAPT41+2
🇮🇷Iran14
2 APT groups0 attack routes
Top targets
MuddyWaterAPT35
🇺🇦UA0
1 APT groups0 attack routes
Top targets
FIN7
Attack Routesorigin → C2 infra
🇷🇺RU→🇨🇳China644
🇷🇺RU→🇺🇸United States597
🇰🇵KP→🇨🇳China442
🇰🇵KP→🇺🇸United States436
🇷🇺RU→🇭🇰Hong Kong307
🇷🇺RU→🇩🇪Germany167
🇰🇵KP→🇭🇰Hong Kong162
🇰🇵KP→🇩🇪Germany149
🇷🇺RU→🇸🇬Singapore123
🇰🇵KP→🇳🇱The Netherlands122
🇷🇺RU→🇳🇱The Netherlands114
🇷🇺RU→🇫🇷France89
🇷🇺RU→🇳🇱Netherlands88
🇰🇵KP→🇸🇬Singapore82
🇷🇺RU→🇨🇦Canada69
🇰🇵KP→🇫🇷France67
🇰🇵KP→🇳🇱Netherlands57
🇷🇺RU→🇯🇵Japan55
🇷🇺RU→🇬🇧United Kingdom49
🇰🇵KP→🇷🇺Russia44
Shared Infrastructuremulti-actor C2
🇨🇳1086
China
RUKP
🇺🇸1033
United States
RUKP
🇭🇰469
Hong Kong
RUKP
🇳🇱381
The Netherlands
KPRU
🇩🇪316
Germany
RUKP
🇸🇬205
Singapore
RUKP
🇫🇷156
France
RUKP
🇨🇦110
Canada
RUKP