ThreatCat — cyber eye
Verified C2 indicators

Every indicator —
a confirmed threat

A high-precision feed of command-and-control (C2) servers attacking Russian infrastructure right now. High precision — minimal false positives.

~500
active C2s in the feed
-> 0%
false positives
10–15
APT groups tracked
About the main C2 feed

Quality over quantity

ThreatCat Feed includes only verified C2 servers that are active right now — collected and confirmed by hand by our lab.

ThreatCat Feed doesn't replace your primary sources — it strengthens them, adding verified indicators where sheer data volume erodes precision.

~500
current indicators in the feed
-> 0
false positives trending to zero
24h
data refresh cycle
01 / VERIFIED

Only confirmed C2

Every indicator is an active command server, manually verified by analysts. We exclude background scans, CDNs, and legitimate services.

02 / FOCUS RU

Focused on attacks against Russia

Indicators are relevant specifically to Russian organizations. We don't ship global "noise" — we track threats targeting our region.

03 / REALTIME

Maximum freshness

Updated daily. The feed contains only servers that are active right now and used in ongoing attacks.

04 / OWN RESEARCH

Proprietary research

All data comes from our own in-house analysis. No resale or aggregation of open OSINT sources.

How it works

How we collect
and process data

A high-precision feed requires large-scale analytical infrastructure. We analyze massive volumes of network metadata to surface attacker activity patterns.

1.5B
DNS records / day
300K
new domains / day
500M
WHOIS records in our DB
Use cases

Scenarios in your infrastructure

01 / Preventive defense

Perimeter blocking

Auto-load the feed into your NGFW and IPS to instantly block any attempt by network hosts to reach C2 servers.

02 / Monitoring & correlation

SIEM / SOAR enrichment

Import indicators into your SIEM to flag suspicious connections in real time and prioritize SOC workload.

03 / Retrospective analysis

Threat hunting

Automated search through historical network and proxy logs — surfacing hidden compromises from the past.

Integration

Fits seamlessly into your stack

The feed ships in a universal format — it integrates with any modern security and incident-response system.

SIEM systems

JSON Import

TI platforms

JSON Import

Network perimeter

NGFWIDS/IPSDNS filters

Automation

SOARIRPAPI / scripts
main_ips.json
{
  "value":      "185.246.220.107",
  "id":         "d9301b48…22d5e",
  "source":     "threatcat",
  "type":       "ip",
  "first_seen": "2026-04-09",
  "last_seen":  "2026-07-03",
  "category":   "bo_team",
  "related": [
    "rlon.fun"
  ]
}
Specification

Main C2 feed

Full catalog of all 8 feeds and API →
Indicator typesIP addresses and C2 domains
Data formatJSON
Update frequencyDaily
Volume (active)~500 indicators
False Positive-> 0%
SourceProprietary research
Raw data

Infrastructure beyond the feed

Behind ThreatCat Feed is a network-metadata collection pipeline — the same one used to verify C2 indicators. The same source data is available separately: DNS records and WHOIS history, including the stream of newly registered domains (~300K/day) — including NRD lists for proactive scoring and phishing/brandsquatting detection.

Suited for teams that need raw material for their own analytics, scoring, or detection-building — not a ready-made indicator list.

Incremental 01 / DNS

DNS record stream

~1.5B records per day — A, AAAA, MX, NS, TXT, and other types. Suited for passive DNS, infrastructure graph building, and retrospective search.

Incremental 02 / WHOIS

WHOIS / RDAP history

A database of ~500M records with a full change history. Registrar, owner, registration and renewal dates — for attribution and domain linkage.

Data access

Delivered separately from the feed

This data is delivered as raw datasets (bulk / stream), independent of the verified C2 feed — for teams that need material for their own analysis, not ready-made indicators.

DNS records~1.5B / day
WHOIS / RDAP~500M records
New domains~300K / day
Delivery formatJSON, bulk
Access termsOn request
Feed catalog

Eight specialized streams

Beyond the main C2 feed and raw data, we ship six more specialized streams — live and incremental, broader in coverage and earlier in the detection funnel. Some of this data is published in the open at ThreatCat Public Feeds ↗.

IP C2 Frameworks Suspicious IP Suspicious Domains DGA Scam OSINT
Full catalog of feeds and API