Security researchers detected multiple StagedC2 command and control server configurations on July 23, 2026. The malicious configurations were staged on Pastebin and employed various C2 endpoints including ngrok tunnels and custom domains.
Between August 19 and 22, 2026, security researchers documented at least six distinct command-and-control (C2) server configurations for a malware variant called StagedC2, posted via Pastebin, with C2 addresses spanning multiple IP ranges and portmap.host domains primarily linked to 193.161.193.99.
Infosec monitors detected six StagedC2 malware command-and-control (C2) configurations posted to Pastebin between August 24-26, 2026. The C2 servers used obfuscated hostnames via portmap.host services, with multiple instances resolving to IP 193.161.193.99, indicating coordinated malware infrastructure activity.
Between August 26 and August 27, 2026, infosec researchers documented six staged malware command-and-control (C2) configurations hosted on Pastebin and routed through IP 193.161.193.99 via dynamic DNS providers. Active surveillance of these infrastructure components occurred over 24 hours.
Between 28–30 August 2026, infosec-exchange Mastodon posts tracked six StagedC2 malware command-and-control (C2) server configurations, observed between 13:12 UTC on 28 August and 06:13 UTC on 30 August. Domains and IP addresses were logged from pastebin and ngrok infrastructure.
Between 30 August and 2 September 2026, the infosec-exchange Mastodon community tracked six active StagedC2 command-and-control configurations using various hosting methods, including Pastebin, DNS domains, and port-mapping services across multiple IP addresses. This represents continuous monitoring of active malware infrastructure.
Between September 2–4, 2026, infosec researchers tracked active StagedC2 command-and-control configurations hosted on Pastebin and using ngrok tunnels and direct IP connections, with six observed instances spanning multiple IPs and ports. The activity represents active malware C2 infrastructure deployment.
# StagedC2 config observed at Sat Sep 5 00:57:02 2026 UTC, located at hXXps://pastebin[.]com/raw/9qs2WJVJ C2: X86-62011[.]portmap[.]host:62011 (IP: 193.161.193.99)
Between 2026-09-08 and 2026-09-10, infosec researchers on Mastodon reported six independent observations of StagedC2 malware configurations posted to Pastebin, each with command-and-control server details and IP addresses (147.185.221.214, 193.161.193.99, 64.89.160.127). Ongoing malware deployment activity.