A high-precision feed of command-and-control (C2) servers attacking Russian infrastructure right now. High precision — minimal false positives.
ThreatCat Feed includes only verified C2 servers that are active right now — collected and confirmed by hand by our lab.
ThreatCat Feed doesn't replace your primary sources — it strengthens them, adding verified indicators where sheer data volume erodes precision.
Every indicator is an active command server, manually verified by analysts. We exclude background scans, CDNs, and legitimate services.
Indicators are relevant specifically to Russian organizations. We don't ship global "noise" — we track threats targeting our region.
Updated daily. The feed contains only servers that are active right now and used in ongoing attacks.
All data comes from our own in-house analysis. No resale or aggregation of open OSINT sources.
A high-precision feed requires large-scale analytical infrastructure. We analyze massive volumes of network metadata to surface attacker activity patterns.
Auto-load the feed into your NGFW and IPS to instantly block any attempt by network hosts to reach C2 servers.
Import indicators into your SIEM to flag suspicious connections in real time and prioritize SOC workload.
Automated search through historical network and proxy logs — surfacing hidden compromises from the past.
The feed ships in a universal format — it integrates with any modern security and incident-response system.
{ "value": "185.246.220.107", "id": "d9301b48…22d5e", "source": "threatcat", "type": "ip", "first_seen": "2026-04-09", "last_seen": "2026-07-03", "category": "bo_team", "related": [ "rlon.fun" ] }
Behind ThreatCat Feed is a network-metadata collection pipeline — the same one used to verify C2 indicators. The same source data is available separately: DNS records and WHOIS history, including the stream of newly registered domains (~300K/day) — including NRD lists for proactive scoring and phishing/brandsquatting detection.
Suited for teams that need raw material for their own analytics, scoring, or detection-building — not a ready-made indicator list.
~1.5B records per day — A, AAAA, MX, NS, TXT, and other types. Suited for passive DNS, infrastructure graph building, and retrospective search.
A database of ~500M records with a full change history. Registrar, owner, registration and renewal dates — for attribution and domain linkage.
This data is delivered as raw datasets (bulk / stream), independent of the verified C2 feed — for teams that need material for their own analysis, not ready-made indicators.
Beyond the main C2 feed and raw data, we ship six more specialized streams — live and incremental, broader in coverage and earlier in the detection funnel. Some of this data is published in the open at ThreatCat Public Feeds ↗.