Infosec monitors detected six StagedC2 malware command-and-control (C2) configurations posted to Pastebin between August 24-26, 2026. The C2 servers used obfuscated hostnames via portmap.host services, with multiple instances resolving to IP 193.161.193.99, indicating coordinated malware infrastructure activity.
11 social postsother
Claim audit
No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.
# StagedC2 config observed at Mon Aug 24 18:24:03 2026 UTC, located at hXXps://pastebin[.]com/raw/P7FQszYH C2: Si-One1-38162[.]portmap[.]host:38162 (IP: 193.161.193.99)
# StagedC2 config observed at Tue Aug 25 10:07:03 2026 UTC, located at hXXps://pastebin[.]com/raw/gg3eK2Jp C2: eon[.]cantdown[.]su:1517 (IP: 91.92.40.138)
# StagedC2 config observed at Tue Aug 25 14:54:02 2026 UTC, located at hXXps://pastebin[.]com/raw/PGbmhug4 C2: btc56-40409[.]portmap[.]host:40409 (IP: 193.161.193.99)
# StagedC2 config observed at Tue Aug 25 15:48:04 2026 UTC, located at hXXps://pastebin[.]com/raw/D2K5kJS0 C2: smart-ads-create[.]loca[.]lt:4444 (IP: 193.34.76.44)
# StagedC2 config observed at Tue Aug 25 18:12:05 2026 UTC, located at hXXps://pastebin[.]com/raw/hR8uXDrv C2: pregwind-58358[.]portmap[.]host:58358 (IP: 193.161.193.99)
# StagedC2 config observed at Tue Aug 25 21:43:02 2026 UTC, located at hXXps://pastebin[.]com/raw/cHc9keNk C2: Cursor1233322-48728[.]portmap[.]host:48728 (IP: 193.161.193.99)
# StagedC2 config observed at Wed Aug 26 00:32:02 2026 UTC, located at hXXps://pastebin[.]com/raw/aSm5rNj6 C2: marwan5555-39474[.]portmap[.]host:39474 (IP: 193.161.193.99)
# StagedC2 config observed at Wed Aug 26 05:55:07 2026 UTC, located at hXXps://pastebin[.]com/raw/bjPbrHpD C2: FEMBOY67-41793[.]portmap[.]host:41793 (IP: 193.161.193.99)