Threat intelligence
- Suspected origin
- [Gaza]
- First seen
- 2011-01-01 00:00:00
- Motivation
- Information theft and espionage
- Targeted sectors
- Critical infrastructure, Defense, Education, Government, Media, Transportation
- TLP
- WHITE
(Kaspersky) The Global Research and Analysis Team (GReAT) at Kaspersky Lab has uncovered new targeted attacks in the Middle East. Native Arabic-speaking cybercriminals have built advanced methods and tools to deliver, hide and operate malware that they have also developed themselves. This malware was originally discovered during an investigation of one of the attacks in the Middle East.
Political activities and news are being actively used by the cybercriminals to entice victims into opening files and attachments. Content has been created with professionalism, with well-designed visuals and interesting, familiar details for the victims, as if the information were long awaited.
The victims of the attacks to date have been carefully chosen; they are active and influential in their respective cultures, but also attractive to the cybercriminals as a source of intelligence and a target for extortion.
The attackers have been operating for more than two years now, running different campaigns, targeting different types of victims and different types of devices (including Windows- and Android-based). We suspect that at least 30 people distributed across different countries are operating the campaigns.
Recorded Future found possible overlap with Cyber fighters of Izz Ad-Din Al Qassam, Fraternal Jackal.
Also known as
APT-C-23Arid ViperATK 66Big Bang APTDesert FalconGrey KarkadannMantisNiobiumPinstripe LightningRenegade JackalScimitarTAG-63TAG-CT1Two-tailed Scorpion
Tooling and malware
Micropsia
Coverage 2
threat-intel
The DevMan ransomware-as-a-service (RaaS) operation has significantly upgraded its affiliate portal, transitioning from a chat-based system to a centralized platform for managing victims, payouts, and team operations. PRā¦

ransomware
The Gentlemen ransomware group, initially operating as the affiliate-focused Phantom Mantis, has evolved into an independent RaaS operation led by the cybercriminal LARVA-368 (aka hastalamuerte). The group, responsibleā¦
