Ransomware C2 Infrastructure Abuse — Bulletproof Hosting Procurement, VPS Exploitation, Hosting Panel Compromise, Cobalt Strike on Legitimate Infrastructure, Multi-Jurisdictional Takedown Complexity
Ransomware C2 Infrastructure Abuse (TL-2026-0099) is a high-severity ransomware operation, first published 2026-02-16. It is attributed to LockBit (Russia) with high confidence, maps to 28 MITRE ATT&CK techniques (T1001.003, T1003.001, T1021.001), and is covered by 9 detection rules and 24 indicators of compromise.
Key facts for TL-2026-0099
- Threat ID
- TL-2026-0099
- Severity
- HIGH
- Status
- ACTIVE
- Category
- RANSOMWARE
- First published
- 2026-02-16
- Last reviewed
- 2026-02-16
- Attribution
- LockBit
- Attribution confidence
- HIGH
- Nation-state nexus
- Russia
- Motivation
- FINANCIAL
- Target sectors
- Critical Infrastructure, Healthcare, Financial Services, Government, Manufacturing, Technology, Legal
- Target regions
- North America, Europe, Global
- Detection rules
- 9
- Indicators of compromise
- 24
Malware and tooling in Ransomware C2 Infrastructure Abuse
Malware and tooling: Bianlian, Black Basta - S1070, LockBit, Cobalt Strike, Rclone - S1040, ngrok - S0508
Ransomware groups systematically abuse legitimate hosting and virtual machine infrastructure for stealthy command-and-control (C2) operations. Rather than operating dedicated malicious infrastructure, modern ransomware-as-a-service (RaaS) ecosystems procure VPS instances from legitimate hosting providers, abuse compromised hosting panels, and leverage bulletproof hosting services that operate within legitimate ISP networks. This 'living off the infrastructure' approach makes C2 traffic indistinguishable from legitimate customer workloads, defeats IP reputation-based blocking, and complicates law enforcement takedown operations. Documented by CISA across multiple #StopRansomware advisories: LockBit affiliates used compromised VPS and legitimate hosting for C2 (AA23-165a), BianLian used Ngrok reverse proxy and Rsocks SOCKS5 tunnels (AA23-136a), Black Basta leveraged Cobalt Strike on legitimate infrastructure (AA24-131a). The Conti leaks (2022) revealed internal procurement of hosting services from Russian-language forums. ISPsystem (Russian, est. 2004, VMmanager/DCImanager/BILLmanager, 200K+ servers, 100+ countries) represents the class of hosting management platforms that enable rapid VM provisioning — the same capability ransomware operators exploit when they gain access to hosting provider panels. ⚠️ V1 CORRECTION: The original v1 title 'Ransomware Gangs Abuse ISPsystem VMs for Stealthy C2 Infrastructure' implied ISPsystem-SPECIFIC abuse — NO primary source documents this specific connection. The broader trend is real and well-documented; the ISPsystem-specific claim appears fabricated. V1 conflated a real product with a real trend to create a plausible but unverifiable narrative.
How Ransomware C2 Infrastructure Abuse works
Modern ransomware-as-a-service (RaaS) operations have evolved far beyond simple malware deployment. A critical but underreported component of successful ransomware campaigns is the infrastructure layer — the servers, VPS instances, and cloud resources that host C2 channels, staging servers, data exfiltration endpoints, and ransomware payload delivery systems.
Ransomware operators employ a spectrum of hosting strategies:
1. BULLETPROOF HOSTING: Services that explicitly or tacitly tolerate malicious activity, typically operating from jurisdictions with weak cybercrime enforcement. These providers often advertise on Russian-language cybercrime forums with guarantees of no-takedown policies. The Conti group's leaked internal communications (Feb 2022) revealed systematic procurement of hosting from multiple providers, with dedicated team members managing infrastructure procurement and rotation.
2. COMPROMISED HOSTING PANELS: Attackers gain access to hosting provider management panels (like VMmanager, cPanel, Plesk, or WHM) through stolen credentials or exploited vulnerabilities, then spin up new VMs on legitimate provider infrastructure. These VMs inherit the IP reputation and network trust of the legitimate hosting provider, making C2 traffic indistinguishable from normal customer workloads.
3. LEGITIMATE CLOUD ABUSE: Ransomware operators create accounts on major cloud providers (AWS, Azure, GCP, DigitalOcean, Linode, Vultr) using stolen or synthetic identities, cryptocurrency payment, and minimal verification. C2 infrastructure on these platforms benefits from the providers' high-reputation IP ranges.
4. REVERSE PROXY AND TUNNELING: Rather than hosting C2 directly, groups use services like Ngrok, Cloudflare Tunnels, or custom SOCKS5 proxies (like Rsocks) to relay C2 traffic through legitimate infrastructure. BianLian group was documented by CISA/FBI using modified Rsocks for SOCKS5 tunneling and Ngrok for reverse proxy C2.
5. COBALT STRIKE AND C2 FRAMEWORKS: Commercial and open-source C2 frameworks (Cobalt Strike, Brute Ratel, Sliver, Havoc) are deployed on legitimate hosting, with operators using domain fronting, malleable C2 profiles, and HTTPS encryption to blend with normal web traffic. LockBit, Black Basta, and BianLian affiliates all documented using Cobalt Strike beacons on legitimate infrastructure.
The hosting management platform ecosystem — including ISPsystem (VMmanager, DCImanager, BILLmanager), Virtuozzo, Proxmox, OpenStack, and similar platforms — enables rapid, automated VM provisioning that benefits both legitimate operators and threat actors. When credentials to hosting management panels are compromised (via phishing, credential stuffing, or exploitation), attackers can provision C2 infrastructure at scale on legitimate provider networks.
ISPsystem specifically: A Russian company founded in 2004, with software installed on 200,000+ servers across 100+ countries. VMmanager provides scalable VM provisioning, BILLmanager handles billing automation, DCImanager manages physical datacenter infrastructure. Their client base includes hosting providers, data centers, educational institutions, and financial organizations. While NO published research specifically documents ransomware abuse of ISPsystem-managed infrastructure, the platform represents the CLASS of hosting management tools that are inherently at risk when access credentials are compromised.
Law enforcement implications: Operation Cronos (LockBit takedown, Feb 2024) specifically targeted LockBit's hosting infrastructure, seizing 34 servers across multiple countries. The multi-jurisdictional nature of hosting infrastructure makes takedowns complex — servers in different countries require coordination across multiple legal frameworks.
The defensive challenge: Traditional IP blocklisting fails against C2 hosted on legitimate infrastructure. Network-based detection must shift from reputation-based approaches to behavioral analysis: anomalous DNS patterns, unusual data transfer volumes, beacon-like periodic communications, and TLS certificate analysis.
MITRE ATT&CK techniques used in TL-2026-0099
command-and-control
T1001.003 Protocol or Service Impersonation; T1071.001 Web Protocols; T1090.002 External Proxy; T1095 Non-Application Layer Protocol; T1105 Ingress Tool Transfer; T1219 Remote Access Tools; T1572 Protocol Tunneling; T1573.002 Asymmetric Cryptography
credential-access
lateral-movement
T1021.001 Remote Desktop Protocol
defense-evasion
T1036 Masquerading; T1078 Valid Accounts; T1205 Traffic Signaling
exfiltration
T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service
discovery
T1046 Network Service Discovery
execution
persistence
T1133 External Remote Services
impact
T1486 Data Encrypted for Impact
initial-access
resource-development
T1583.003 Virtual Private Server; T1583.004 Server; T1583.005 Botnet; T1583.006 Web Services; T1584.004 Server; T1588.002 Tool; T1608.001 Upload Malware
defense-impairment
Remediation for Ransomware C2 Infrastructure Abuse
Immediate actions
- Enforce MFA on all hosting panel access (VMmanager, cPanel, Plesk, WHM, cloud consoles)
- Monitor for anomalous VM creation patterns (unusual times, burst provisioning, crypto-only payment)
- Implement outbound C2 beacon detection on hosted customer VMs
- Block known malicious tool signatures (Cobalt Strike, Brute Ratel) on hosting network egress
Workarounds
- Rate-limit VM creation per account to prevent burst provisioning of C2 infrastructure
- Implement IP reputation scoring for outbound traffic from hosted VMs
- Require human verification for accounts created with cryptocurrency-only payment methods
Longer-term hardening
- Implement behavioral analysis for hosted VM traffic (beacon detection, DNS anomalies, data exfiltration patterns)
- Deploy identity verification for new hosting accounts beyond simple email verification
- Participate in threat intelligence sharing with law enforcement (FBI, Europol, national CERTs)
- Implement network segmentation isolating management planes from customer data planes
- Deploy automated abuse detection correlating VM creation, network behavior, and payment patterns
- Monitor for Ngrok, Cloudflare Tunnel, and SOCKS5 proxy usage from customer VMs
Timeline of Ransomware C2 Infrastructure Abuse
- ISPsystem founded, begins developing hosting management platforms. Over next two decades grows to 200K+ server installations across 100+ countries. Source: https://www.ispsystem.com/
- LockBit ransomware first observed in the United States, beginning systematic use of legitimate hosting infrastructure for C2 operations. By 2022, LockBit would become the most deployed ransomware globally. Source: CISA AA23-165a
- Conti group internal communications leaked, revealing systematic procurement of hosting infrastructure from Russian-language cybercrime forums. Leaks showed dedicated infrastructure team managing VPS rotation, bulletproof hosting procurement, and C2 server deployment across multiple providers. Source: Conti Leaks (public domain)
- Black Basta ransomware emerges, leveraging Cobalt Strike beacons on legitimate hosting infrastructure for C2. By May 2024, Black Basta affiliates impact 500+ organizations globally. Source: CISA AA24-131a
- BianLian ransomware group begins operations, using custom Go backdoors and legitimate hosting for C2. Later documented using Ngrok reverse proxy and modified Rsocks SOCKS5 tunneling through legitimate infrastructure. Source: CISA AA23-136a
- CISA/FBI/international partners publish comprehensive LockBit advisory (AA23-165a) documenting ~1,700 US attacks, $91M in ransom payments, and systematic use of VPS/hosting infrastructure. Source: https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-165a
- Operation Cronos: international law enforcement takedown of LockBit infrastructure. 34 servers seized across multiple countries. Demonstrates the multi-jurisdictional challenge of ransomware hosting infrastructure takedowns. Source: Europol/FBI/NCA
- CISA updates Black Basta advisory (AA24-131a) documenting new social engineering TTPs via Microsoft Teams and continued use of Cobalt Strike, RClone, and remote access tools on legitimate infrastructure. Source: CISA AA24-131a
- CISA updates BianLian advisory (AA23-136a) documenting use of Ngrok reverse proxy and modified Rsocks for SOCKS5 tunneling through legitimate infrastructure, Russia-based attribution. Source: CISA AA23-136a
- As of 2026-05-29, this multi-actor ransomware C2-infrastructure-abuse trend remains fully ACTIVE: LockBit 5.0 rebounded to 163 victims in Q1 2026 (+106%, 4th globally, cross-platform) and bulletproof/legit-hosting C2 drove escalating OFAC action (Zservers Feb 2025, Aeza hosting BianLian C2 Jul 2025, Media Land Nov 2025). No CVE to patch; though Black Basta collapsed in early 2025, the technique class is broadly exploited with no successor superseding it.
Sources cited for Ransomware C2 Infrastructure Abuse
- CISA #StopRansomware: LockBit (AA23-165a) — 1,700 US attacks, $91M ransoms
- CISA #StopRansomware: BianLian (AA23-136a) — Ngrok/Rsocks C2 tunneling
- CISA #StopRansomware: Black Basta (AA24-131a) — 500+ victims, Cobalt Strike C2
- ISPsystem — IT Infrastructure Management Platforms (200K+ servers)
- ISPsystem VMmanager — Virtualization Management Platform
- ISPsystem News — no security incidents documented
More in ransomware
- Magniber Ransomware: Rewritten 2022 Variant Uses MSI Installer, AES-NI Encryption, and UAC Bypass
- Hyadina Rebrands Beast Ransomware as 'GodDamn' and Uses PoisonX Signed Kernel Driver to Disable Endpoint Defenses
- DragonForce Ransomware Attack on RubberMill, Inc. — ~340GB Data Exfiltration Including PII, Credentials, CAD Files with Defense Mil-Spec References
- Vexy Ransomware hits Mega Velocity — 46.68 GB exfiltrated, double extortion
- Rhysida Ransomware Campaign Targeting German Public Administration (Stuttgart and Berlin, 2026)
Detection coverage for TL-2026-0099
As of 2026-02-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0099 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.