Year in Research: Threat Landscape Within Middle East

Executive Summary

1. Nation-State Operations Intensify

2. Ransomware Expands in Scope and Scale

3. Dark Web Ecosystem Powers Threat Access

1. Introduction

2. Threat Landscape in the Middle East

1. Espionage and Statecraft in Cyberspace:

2. Ransomware and Cybercrime Epidemic:

3. Blurring Lines – “Hybrid” Threat Campaigns:

3. Major Regional Threat Actors and APT Groups

3.1 The Three Elephants in the Room

1. APT Group: OilRig
Names & AliasesOilRig, APT34, Helix Kitten, Earth Simnavaz, UNC1860, TA452, Hazel Sandstorm, Cobalt Gypsy.
Country of OriginIran.
Threat Actor TypeNation-State Sponsored.
Linked OrganizationMinistry of Intelligence and Security (MOIS).
ObjectivesEspionage, Sabotage, and Information Theft.
Targeted CountriesEgypt, Iraq, Jordan, Kuwait, Lebanon, Oman, Qatar, Saudi Arabia, and UAE.
Targeted SectorsAviation, Chemical, Defense, Education, Energy, Financial, Government, High-Tech, IT, Hospitality, Oil and gas, Telecommunications.

2. APT Group: MuddyWater

Names & AliasesMuddyWater, Seedworm, TEMP.Zagros, Static Kitten, TA450, Boggy Serpens, Yellow Nix, Mercury, ITG17.
Country of OriginIran.
Threat Actor TypeNation-State Sponsored.
Linked OrganizationMinistry of Intelligence and Security (MOIS).
ObjectivesIntelligence Gathering, Espionage, Information Theft.
Targeted CountriesBahrain, Egypt, Iraq, Jordan, Kuwait, Lebanon, Oman, Qatar, Saudi Arabia, and UAE.
Targeted SectorsAviation, Defense, Education, Energy, Financial, Food and Agriculture, Gaming, Government, Healthcare, High-Tech, IT, Media, NGOs, Oil and gas, Shipping and Logistics, Telecommunications, Transportation.

3. APT Group: MagicHound

Names & AliasesAPT35, CharmingKitten, Cobalt Illusion, TEMP.Beanie, TA453, CharmingCypress, Mint Sandstorm, Yellow Garuda, Phosphorus.
Country of OriginIran.
Threat Actor TypeNation-State Sponsored.
Linked OrganizationIslamic Revolutionary Guard Corps Intelligence Organization (IRGC-IO).
ObjectivesEspionage, Intelligence collection.
Targeted CountriesEgypt, Iraq, Jordan, Kuwait, Saudi Arabia, Syria, UAE, Yemen, and Palestine.
Targeted SectorsDefense, Education, Energy, Financial, Government, Healthcare, IT, Manufacturing, NGOs, Oil and gas, Technology, Telecommunications, and organizations that are either based or have business interests in Saudi Arabia.

3.2. Iran-Linked APT Groups

3.3. Chinese APT Groups

3.4. Russian APT Groups

3.5. North Korea and Other Regional Actors

3.6. Strategic Implications for Regional Cybersecurity

4. A Year of Ransomware

4.1. Ransomware by the Numbers

Top Ransomware Families

Geographic Distribution

Targeted Sectors

4.2. Top Five Ransomware Families

1. RansomHub

AttributeDetails
EmergenceFirst emerged in February 2024 as a RaaS, promoted by the threat actor “koley” on the Ramp Forum.
Country of Origin[Unknown].
MotivationFinancial gain (high-value targets, large ransoms).
Technical DetailsWritten in Golang and C++, targets Windows, Linux, and ESXi environments.
Notable Characteristics– Affiliate group: ALPHV (BlackCat). – Shares code overlaps and configuration keys with Knight ransomware (likely rebranded purchase). – “README_.txt” ransom note warns victims against seeking law enforcement. – Offers a 90% revenue share to affiliates, fueling rapid adoption.
Typical TargetsConstruction firms, IT services, healthcare facilities, and large enterprises.
Extortion MethodDouble extortion: data theft + file encryption, posted on the “RansomHub Blog” if ransom is not paid.
Common TTPs– Exploits Zerologon (CVE-2020-1472) for domain admin privileges. – Uses tools like Splashtop Atera for lateral movement. – Affiliates can reboot endpoints in safe mode prior to encryption (bypassing security tools).
Key InsightRapidly rose in prominence due to lucrative affiliate payouts and rebranded code from older ransomware families.


2. LockBit 3.0

AttributeDetails
EmergenceEvolved from LockBit 1.0 (2019) to LockBit 3.0 in June 2022, each version releasing an updated extortion blog simultaneously.
Country of OriginRussia.
MotivationFinancial gain, with ransom amounts ranging from $85,000 to over $1 million.
Technical Details– Targets Windows, Linux, ESXi, macOS. – Uses AES + RSA for encryption. – Integrates tactics from other strains (e.g., BlackMatter).
Notable CharacteristicsOperation Cronos partially disrupted infrastructure in Feb 2024. – Law enforcement-developed decryptors available for some victims. – Introduced new payment options (BTC, Monero, Zcash) and “pay to extend,” “pay to destroy,” or “buy stolen data” models.
Typical TargetsGovernment, public education, municipal services, energy sector, and large enterprises.
Extortion MethodPrimarily double extortion (encryption + data theft), occasionally triple extortion (DDoS threats).
TTPsInitial Access: Phishing, drive-by compromise, exploiting known CVEs (Log4j, Zerologon). – Lateral Movement: SMB, PsExec, Cobalt Strike. – Impact: Data encryption, file exfiltration, and ransom notes forcing high-pressure payment.
Key InsightDespite law enforcement efforts, LockBit 3.0’s multi-platform approach and constant feature updates allow it to remain highly effective, especially where vulnerabilities and weak credentials persist.


3. Qilin (Agenda)

AttributeDetails
EmergenceActive since July 2022; rebranded from “Agenda” to “Qilin” in October 2022.
Country of OriginRussia.
MotivationFinancial gain, with ransoms ranging from $50k to $800k, scaling up to $50 million in extreme cases (e.g., healthcare providers).
Technical Details– Go & Rust codebase. – Targets Windows, Linux, ESXi. – Features advanced encryption modes (skip-step, percent, fast) and intermittent encryption to evade detection.
Notable CharacteristicsTwo-tier RaaS payout: affiliates earn 80% if ransom ≤ $3M, 85% if > $3M <br/> – Has a Telegram channel (inactive since June 2024) <br/> – Claims to forbid attacks on CIS countries.
Typical TargetsLaw, healthcare, finance, manufacturing, and IT services.
Extortion MethodDouble extortion (encrypt + threaten data leaks) with a Tor-based extortion blog (“Qilin”).
TTPsInitial Access: Phishing (spearphishing attachments/links), RDP brute force. – Lateral Movement: PsExec, SSH, PowerShell scripts. – Impact: Encrypts critical systems, demands crypto payment, threatens data leaks.
Key InsightQilin’s adaptability (written in Go & Rust) and flexible encryption approach allow affiliates to tune attacks, representing a formidable threat to any region lacking robust defenses.

4. FunkSec

AttributeDetails
EmergenceSurfaced late 2024; quickly claimed over 85 global victims in December alone.
Country of OriginAlgeria for core developer(s), per location slips in screenshots and Rust binaries, though no official group origin is stated.
MotivationFinancial gain with possible hacktivist undertones; aims for recognition/visibility by inflating claims of data leaks.
Technical DetailsAI-assisted malware development enabling rapid iteration. – Rust-based encryptor (“.funksec”) with frequent updates. – Evidence of code duplication and repeated calls (suggesting less-experienced authors).
Notable CharacteristicsLow ransom demands ($10k+). – Many leaked datasets appear recycled or “fake” from prior hacktivist campaigns. – Maintains a data leak site (DLS) featuring breach announcements and a custom DDoS tool.
Typical TargetsHealthcare, finance, manufacturing, government, and IT.
Extortion MethodDouble extortion (data theft + encryption), selling stolen data cheaply on their data leak site.
TTPsInitial Access: Possibly phishing, direct infiltration with stolen credentials, brute force. – Execution: Rust-based binaries with heavy code repetition. – Impact: File encryption, data leak threats on a Tor-based site.
Key InsightFunkSec’s “AI-driven” approach and low-skill coding style produce high-volume, low-sophistication attacks, but the group’s marketing and repeated updates keep it visible on ME threat radars.

5. Stormous

AttributeDetails
EmergenceStormousX (July 2022), GhostLocker 2.0 (late 2023), GhostLocker 3.0 (July 2024). StormouS.X/GhostLocker RaaS launched in February 2024.
Country of Origin[Uknown]; Stormous forbids data leaks from Russian or “neighboring” entities, but no stated origin for the group itself.
MotivationFinancial gain via RaaS extortion; also some hacktivist-like elements through alliances with GhostSec.
Technical DetailsGhostLocker primarily targets Windows systems (x86/x64). – Ransomware includes features like disabling Task Manager, bypassing UAC, fast encryption, and comprehensive affiliate dashboards.
Notable Characteristics– Adoption of the new GhostLocker RaaS (Figure 11 below). – Part of “The Five Families” collective (hacktivist-cybercrime convergence).
Typical TargetsHealthcare, manufacturing, finance, government, construction, education, and IT.
Extortion MethodDouble extortion: After encrypting data, threatens to publish stolen files on StormouS.X Blog or name-and-shame via Telegram channels.
TTPsInitial Access: RDP exploits, phishing, supply chain compromises. – Execution: Python-based GhostLocker code (obfuscated, compiled with Nuitka), disabling critical Windows processes. – Impact: Rapid encryption (AES), data leaks, ransom negotiation demands.
Key InsightStormous merges hacktivist-style branding with commercial RaaS tactics, capturing a broad affiliate base and threatening Middle Eastern organizations across multiple sectors.

Global Perspective

Regional Focus: The Middle East

6. Top Exploited Vulnerabilities

CVE ID
Affected Vendor/Products
Impact
CVE-2024-3400Palo Alto Networks / PAN-OSRemote code execution
CVE-2024-4040CrushFTPRemote code execution, unauthorized access
CVE-2024-9463Palo Alto Networks / ExpeditionRemote code execution, allowing system compromise.
CVE-2024-9680Mozilla / FirefoxRemote code execution via malicious websites.
CVE-2024-47575Fortinet / FortiManagerRemote code execution with elevated privileges.
CVE-2024-40711Veeam / Backup & ReplicationRemote code execution by unauthenticated attackers.
CVE-2024-7593Ivanti / Virtual Traffic ManagerRemote, unauthenticated exploitation.
CVE-2024-3272D-Link / Multiple NAS DevicesRemote code execution, and potential exposure of sensitive DNS information
CVE-2024-3273D-Link / Multiple NAS DevicesRemote code execution, and potential exposure of sensitive DNS information
CVE-2024-37079 & CVE-2024-37080VMware / vCenterRemote code execution
CVE-2024-29849Veeam / Backup Enterprise ManagerAuthentication bypass vulnerability
CVE-2024-21410Microsoft / Exchange ServerPotential server compromise, data theft.
CVE-2024-21762Fortinet / FortiOSComplete compromise of Fortinet devices.
CVE-2024-4671Google / ChromiumAllow attackers to bypass browser security
CVE-2024-0012Palo Alto Networks / PAN-OSRemote code execution, compromising devices.
CVE-2024-9465Palo Alto Networks / ExpeditionRemote code execution, enabling system control.
CVE-2024-28987Solar Winds / Web Help Desk (WHD)Unauthorized access to internal functionality and data.
CVE-2024-8963Ivanti / Cloud Services ApplianceUnauthorized access to restricted functionality.
CVE-2024-21887Ivanti / Connect Secure/ Policy SecureIncreased attacker capabilities within Ivanti products.

7. Dark Web Insights

7.2. Dark Web Threat Activity in the Middle East

8. Tactics, Techniques, and Procedures (TTPs) in Focus

8.1. APT Groups: Stealthy Infiltration and Sustained Access

8.2. Ransomware Variants: Aggressive Exploitation and Impact

8.3. Top Initial Access Techniques

Initial Access
RankTechnique (MITRE ATT&CK ID)Observed Examples
1T1190 – Exploit Public-Facing ApplicationUnpatched internet-facing systems (web servers, VPN appliances, etc.) are prime targets. Iranian-linked actors were observed scanning and exploiting vulnerable devices (Citrix Netscaler, F5 BIG-IP, Palo Alto PAN-OS, etc.) via known CVEs to gain entry​.
2T1078 – Valid AccountsFor example, Rhysida ransomware affiliates rent compromised RDP/VPN accounts from initial-access brokers​, and Iranian threat actors have escalated brute-force and credential-theft campaigns in the region​.
3T1133 – External Remote ServicesAttackers frequently target exposed remote-access services. Compromised RDP or VPN logins are a common entry point; accounts are often sold by underground brokers or obtained via credential attacks​.
4T1566 – PhishingFor example, Lazarus Group’s “DreamJob” campaign used fake job offers to deploy trojanized tools​, and regional ransomware operators similarly use benign-looking emails to drop malware​.

9. Recommendations and Mitigation Strategies

10. Future Outlook: What is Ahead?

  • Persistent State Activity and Escalation
  • Ransomware “Professionalization” and Evolution:
  • AI-Driven Threats and Opportunities:
  • Hybrid Threats and Dual-Purpose Operations Continue:

11. Conclusion

Appendix B: Top 20 Malware Identified in the Region

RankMalware NameFamily TypeDetectionsPrimary Objective
1LummaStealer14,657Steals sensitive credentials, banking data, and personal information, causing financial and privacy damage.
2AsyncRATRAT9,016Grants attackers full control of infected systems, facilitating espionage, data theft, and further malware installation.
3Agent TeslaTrojan8,548Steals sensitive information (credentials, emails) through keylogging, potentially leading to financial loss or identity theft.
4XWormRAT8,198Provides remote access to systems, enabling attackers to manipulate data, install malware, and steal information.
5RemcosTrojan8,025Offers remote control and data theft capabilities, often used for espionage or executing malicious tasks.
6StealcStealer7,980Targets sensitive user data, including login credentials, for financial fraud or identity theft.
7RedLineStealer7,142Specializes in stealing banking details, cryptocurrency wallets, and other sensitive personal data.
8AmadeyInfostealer6,264Steals sensitive data (user credentials, system info), potentially enabling further exploitation or fraud.
9EmotetTrojan4,483Often used in large-scale attacks, it spreads malware, steals data, and is involved in ransomware delivery.
10DCRatRAT3,593Provides remote access, enabling data theft, surveillance, and system manipulation by attackers.
11njRATTrojan3,502Enables remote access and can be used for spying, stealing data, and deploying further malicious software.
12MetaStealerStealer2,768Steals sensitive information, including login credentials, to facilitate fraud or unauthorized access.
13GuLoaderDownloader2,621Downloads other malicious software, often a precursor to more dangerous infections like ransomware or trojans.
14FormbookSpyware2,620Tracks user activity, collects personal data (credentials, browsing habits), and can lead to identity theft.
15Cobalt StrikePenetration Software2,531Used for advanced cyberattacks, including data exfiltration, system exploitation, and lateral movement within networks.
16Quasar RATTrojan2,526Facilitates remote access for cybercriminals to control systems, steal data, or install further malicious software.
17Balada InjectorBackdoor2,403Installs malware and opens backdoors for further malicious activities, leading to potential data loss or system compromise.
18Blank GrabberStealer2,025Primarily steals images, videos, and sensitive documents, often used in blackmail or extortion campaigns.
19VidarTrojan2,006Focuses on stealing financial data, login credentials, and personal information, which can lead to fraud and identity theft.
20CryptBotInfostealer1,626Steals sensitive data, with a focus on cryptocurrency wallets and banking information, which can lead to financial theft.

Leave a Reply

Discover more from CForce Security Research

Subscribe now to keep reading and get access to the full archive.

Continue reading