Mapping the Attack Ladder: High- and Medium-Risk Infrastructure in Observed Traffic

In today’s threat landscape, attackers rarely operate from a single infrastructure tier. They move methodically up a “ladder” — beginning with low-signal reconnaissance and proxying, then escalating to more resilient and aggressive command-and-control (C2) and brute-force operations.

Recent analysis of a substantial set of observed IPs (1,676 unique addresses) revealed a clear risk hierarchy that perfectly illustrates this progression. Eleven IPs stood out as high-risk, concentrated in known abusive hosting ranges. Another 996 fell into the medium-risk category, serving as the supporting layer beneath them.

This article breaks down the findings, highlights the primary suspected threat actors involved (with a spotlight on TeamPCP), and examines how medium-risk infrastructure feeds into sophisticated operations.

High-Risk Infrastructure: The Execution Layer

Eleven IPs clustered in a handful of Netherlands-based abusive hosting ranges demonstrated the highest risk. These are not random — they function as active hubs for scanning, initial access, and C2.

Primary Cluster: 45.x.x.x/24 (including .67, .121, and related addresses such as .212)

This range, hosted by TECHOFF SRV LIMITED, shows direct links to TeamPCP (also tracked as PCPcat, ShellForce, DeadCatx3, UNC6780). Specific infrastructure within the range has hosted Havoc C2 servers used in large-scale supply chain attacks.

TeamPCP Profile‍ ‍

TeamPCP is an emerging, cloud-native threat actor that first gained significant attention in late 2025. The group specializes in sophisticated supply chain compromises targeting developer tools, security scanners, and AI/ML infrastructure. Notable campaigns include poisoning packages in ecosystems such as GitHub Actions, Docker Hub, npm, PyPI, and tools like LiteLLM, Trivy, and KICS.

Their trade craft includes:

• Dual C2 frameworks (Havoc and AdaptixC2)

• Innovative decentralized C2 via CanisterWorm (leveraging Internet Computer Protocol blockchain canisters for resilience)

• Memory scraping and credential harvesting from CI/CD pipelines

• Collaboration with ransomware groups (notably Vect)

Monetization paths include data extortion, ransomware deployment, and cryptomining. The FBI has issued alerts on their operations. The presence of their infrastructure in observed traffic is a strong indicator of exposure to modern supply chain and cloud-native threats.

Secondary High-Risk Clusters

• 89.248.x (Recyber Project netblocks): Frequently associated with scanning and brute-force activity that feeds ransomware initial access brokers.

• 92.6xx.197.x, 147.xxx.13x, and 185.xxx.73.x: Commodity abusive hosting supporting reconnaissance and foothold establishment.

These ranges are commonly leveraged by ransomware ecosystems, including affiliates and splinters connected to Conti (e.g., Royal), Clop, and Play ransomware operations.

Medium-Risk Infrastructure: The Reconnaissance and Anonymity Layer

The majority of the list (996 IPs) fell into the medium-risk tier. These addresses do not match major trusted providers (Google, AWS, Cloudflare, Microsoft, Akamai) and are not clearly private/internal. They represent the supporting infrastructure that attackers use before escalating to high-risk ranges.

Key Medium-Risk Patterns

1. Proxy, VPN, and Anonymity Networks

Significant portions appear in ranges such as 185.x, 46.x, 91.x, and select 147.x (beyond the high-risk hits). These are frequently rotated and used to obscure attacker origins. Tactics include anonymized scanning, credential stuffing, and acting as stepping stones before pivoting into more aggressive infrastructure.

2. Scattered Residential and Small ISP Ranges

Numerous IPs with patterns such as .142, .108, .64, and .251 endings across various ASNs. These often represent dynamic residential connections or small hosting providers. They support low-volume reconnaissance and probing that is difficult to distinguish from legitimate traffic on its own.

3. Edge and Unknown Hosting

Public IPs that fall outside major cloud and CDN blocks. These are commonly used for short-lived relays, malware drop points, or testing environments before operators commit resources to higher-tier abusive hosting.

Representative Examples:

• Reserved or unusual patterns (e.g., 0.0.0.5, 0.0.6.2)

• Multiple .142 and .108 endings across different providers

• Broader blocks in the 102.x–112.x ranges with mixed proxy and residential characteristics

The Attack Ladder: How Medium Feeds High

Attackers rarely jump straight to high-signal infrastructure. The medium-risk layer serves critical early- and mid-stage functions:

• Reconnaissance & Discovery: Residential and small ISP ranges allow broad, low-and-slow probing without triggering heavy defenses.

• Anonymity & OPSEC: Proxy and VPN ranges obscure the true origin before operators move to more powerful C2.

• Stepping Stones & Testing: Medium infrastructure is used to validate targets or establish initial footholds before escalating to resilient ranges like 45.148.10 or Recyber for brute-force and persistent C2.

Once a foothold is gained or targets are validated, operations shift to the high-risk layer — where actors like TeamPCP deploy advanced C2 frameworks and ransomware affiliates conduct aggressive access operations.

This layered approach explains why simply blocking high-risk ranges is insufficient; defenders must also understand and monitor the supporting medium infrastructure that precedes it.

Key Takeaways

• Risk is Tiered: High-risk IPs represent execution and persistence; medium-risk IPs represent reconnaissance, anonymity, and initial access preparation.

• TeamPCP Represents Modern Sophistication: Direct infrastructure overlap with observed high-risk ranges highlights the convergence of supply chain attacks and traditional ransomware pipelines.

• Infrastructure Reuse is Common: The same abusive hosting providers and proxy networks are rotated across multiple campaigns and actor groups.

• Context Matters: Not every medium-risk IP is malicious, but patterns and correlation with high-risk activity significantly elevate concern.

Understanding these tiers and the tactics that connect them is essential for effective threat hunting and protective intelligence. At Quantitative Security, we create these reports by cross-referencing publicly available data and recent released threat reports, combined with OSINT and discoverable actionable intelligence gathered through rigorous analysis and custom tooling.

This approach enables organizations to move beyond reactive measures toward proactive understanding of attacker infrastructure and trade craft.

Previous
Previous

Mapping Legitimate Infrastructure and Dissecting Emerging Phishing & Malvertising

Next
Next

Comprehensive IP Threat Intelligence Analysis