Executive Summary
The Middle East Threat Landscape Report provides a comprehensive overview of the evolving cyber threat environment, highlighting key trends and emerging risks observed over the year of 2024. In a region shaped by the convergence of geopolitical tensions, rapid digitalization, and economic transformation. State-backed cyber espionage, financially motivated ransomware, and hybrid threat campaigns defined the middle east’s evolving threat landscape.
1. Nation-State Operations Intensify
State-sponsored actors, particularly from Iran, China, and North Korea, led widespread cyber espionage campaigns targeting government, defense, and energy sectors. Iranian groups such as OilRig and MuddyWater were especially prolific, using tailored malware and credential-based access to achieve long-term infiltration.
2. Ransomware Expands in Scope and Scale
Ransomware attacks surged, with groups like RansomHub and LockBit 3.0 exploiting vulnerabilities and compromised credentials to execute rapid, high-impact campaigns. Double and triple extortion tactics became standard, often disrupting critical services across technology, energy, and government sectors.
3. Dark Web Ecosystem Powers Threat Access
Initial Access Brokers and data leak markets thrived on the dark web, facilitating targeted intrusions. Compromised credentials, remote service exploits, and phishing kits tailored to regional entities were widely traded, reflecting the commoditization of cyber access in the Middle East.
The Middle East will continue to face sophisticated, multi-vector threats in 2025. Cybersecurity must be viewed as a strategic priority, on par with geopolitical and economic risk. Organizations should strengthen detection, invest in AI-enabled defenses, and engage in regional intelligence collaboration to stay ahead of evolving threats.
1. Introduction
The Middle East’s cybersecurity environment in 2024 was shaped by a unique intersection of geopolitical tension, economic ambition, and rapid digital transformation. This report is intended to inform senior cybersecurity leaders and the whole cyber security community about the evolving threat landscape across Middle Eastern countries. The focus is on Arab states and other regional nations (e.g. Gulf Cooperation Council members, Levant countries, and parts of North Africa), excluding Iran and Israel as countries under analysis. Iran and Israel are not covered as victim countries in this report; however, their cyber activities loom large over the region’s threat landscape, and inevitably so. By concentrating on the defined Middle East, we aim to highlight why this region has become central to global cyber conflicts and what that means for organizations operating here.

Figure 1. Highlighted Map of the Middle East Defined in this Report.
For this report, the Middle East refers specifically to the following countries: Saudi Arabia, United Arab Emirates, Qatar, Bahrain, Kuwait, Oman, Yemen, Jordan, Palestine, Lebanon, Syria, Iraq, and Egypt. Wherein, Iran and Israel have been excluded to maintain a balanced regional perspective and avoid skewing research outcomes due to their distinct geopolitical and cyber threat dynamics.
Geopolitical and Strategic Context: The Middle East remains a geopolitical hotspot, and this volatility increasingly extends into cyberspace. Ongoing conflicts and rivalries, from civil wars and insurgencies to the high-profile Israel–Palestine conflict, provide fertile ground for cyber operations by state actors and militant groups. Regional powers view cyber espionage as a key tool for intelligence and influence, while non-state actors and proxies engage in defacement, data leaks, and disruption to champion their causes. The strategic importance of the Middle East on the world stage, as the hub of global energy supplies, trade routes, and investment, makes it a magnet for major cyber powers. Both global adversaries and local nation-states conduct intrusions to steal sensitive data and to prepare for potential sabotage. For instance, Chinese state-sponsored groups have been involved in long-term spying on Middle Eastern governments as part of broader campaigns (e.g. Operation Diplomatic Specter targeted multiple ministries and embassies in the region since 2022). Likewise, Iranian Advanced Persistent Threat (APT) groups have persistently focused on their neighbors and Gulf rivals, seeking political, military, and economic intelligence. The result is a Middle Eastern cyber landscape heavily influenced by statecraft and geopolitics, where cyber operations are often entwined with real-world diplomatic agendas.
Digital Transformation and Economic Drivers: Parallel to these tensions, Middle Eastern nations are undergoing rapid digital growth and economic diversification. Ambitious national initiatives, such as Saudi Vision 2030, the UAE’s digital government strategy, and similar Vision 2030 programs in Qatar and Bahrain, are propelling government services, critical infrastructure, and businesses into the digital age. Investment in smart cities, fintech, cloud computing, and AI is soaring as the region seeks to reduce reliance on oil and embrace a knowledge economy. For example, Saudi Arabia launched the CyberIC program to boost national cyber defenses and foster local cybersecurity startups, and the UAE has dedicated record budgets to upgrade government cyber protection standards. These advancements underscore the strategic interest of the region to cyber actors: as the Middle East modernizes its infrastructure and accumulates valuable digital assets, it becomes an even more attractive target. The same oil & gas facilities, financial centers, and airlines that drive prosperity are also high-value prey for cybercriminals and espionage groups. Indeed, 2024 saw attackers exploiting newly digitized systems and zero-day vulnerabilities to disrupt oil, gas, and telecommunications operations. The combination of wealth and digital expansion means Middle Eastern organizations face not only traditional cyber threats but also sophisticated attacks aiming to derail economic progress. Protecting critical infrastructure and supply chains has thus become a national security priority in these countries, as evidenced by new regulations and regional cybersecurity frameworks.
Scope of Report: Within this context, the report examines key cyber threat trends observed in 2024 affecting Middle Eastern nations. It covers state-sponsored threat activity, major cybercrime operations (like ransomware and data theft), exploitation of vulnerabilities, and the role of the dark web in regional threats. The goal is to provide a holistic view of how espionage, cybercrime, and hacktivism have intersected in the Middle East, and to distill insights that organizations can use to bolster their defenses. We also consider how the Middle East’s cyber threat landscape is distinct, influenced by regional conflicts and alliances, and why international stakeholders are increasingly concerned with cyber stability in this region. By understanding these dynamics, cybersecurity leaders can better anticipate adversaries’ goals (e.g. espionage versus financial gain), assess the risks to their sector, and prioritize security investments accordingly. In the sections that follow, we detail the threat landscape of 2024, draw connections to geopolitical and economic factors, and finally look ahead to what 2025 may hold for Middle Eastern cyber resilience.
2. Threat Landscape in the Middle East
The Middle East in 2024 emerged as one of the world’s most active cyber battlegrounds, where regional geopolitical instability and economic transformation merged to create a perfect storm of cyber threats. A narrative of constant espionage, financially driven breaches, and ideologically motivated attacks played out across nations from the Gulf to the Levant. Several broad patterns characterized the threat landscape:
1. Espionage and Statecraft in Cyberspace:
Geopolitical rivalries heavily shaped the threat landscape, as nation-state hackers ramped up espionage and disruptive activities. Iran, in particular, leveraged cyber operations as an extension of its regional ambitions. Throughout 2024, Iranian state-sponsored groups continued extensive campaigns of espionage against Middle Eastern governments, militaries, and critical industries. These APTs deployed phishing and malware to infiltrate targets ranging from Gulf state ministries to energy companies. Beyond Iran, other global powers also operated in the region: Chinese cyber-espionage campaigns quietly targeted Middle Eastern diplomatic and economic institutions as part of broader Asia/Africa operations. Meanwhile, Russia and Western intelligence services are believed to monitor the region’s conflicts via cyber means, though with less public reporting. The outcome is that Middle Eastern networks have been persistently probed and penetrated by sophisticated APTs looking for high-value data. In some cases, these state actors went beyond spying, engaging in sabotage or information operations.
2. Ransomware and Cybercrime Epidemic:
Alongside espionage, the Middle East was hit by a wave of financially motivated cybercrime, mirroring global trends but with some regional wrinkles. Ransomware gangs significantly expanded their focus on Middle Eastern victims in 2024. Criminal groups from Eastern Europe and elsewhere view the region’s enterprises, many flush with oil revenue or undergoing digital growth, as lucrative targets willing to pay to avoid business disruption. Data from incident disclosures shows a steady drumbeat of attacks on businesses and government agencies across Saudi Arabia, the UAE, Qatar, Egypt, and beyond.
Notably, the LockBit and RansomHub collective were responsible for a large share of incidents. These groups executed so-called “big game hunting” attacks: intrusions into large organizations where they could extort hefty ransoms. Middle Eastern technology, energy, and public sectors were hit most frequently, but other industries were not spared. The tactics followed the global playbook, often starting with an Initial Access Broker (IAB) selling access to regional corporate networks. Moreover, reports of such access listings are found on criminal forums, with the UAE being the top country for advertised access. Once inside, ransomware affiliates would escalate privileges, steal sensitive files, then encrypt systems to disrupt operations, demanding payment for decryption keys and silence. The impact on regional organizations was severe: ransomware attacks caused multi-day outages in government services, loss of citizen data, and financial losses in the tens of millions of dollars.
It’s also worth noting that financial Trojans and data theft malware were widespread in the Middle East, not just ransomware. Banking trojans, credential stealers, and cryptocurrency mining malware have proliferated as more business and consumer activity moves online. Regional banks reported an uptick in sophisticated fraud attempts and breaches, prompting many to harden their cyber defenses.
3. Blurring Lines – “Hybrid” Threat Campaigns:
A clear theme in the Middle East’s 2024 threat landscape was the erosion of boundaries between different types of threat actors. We observed a continuum of malicious activity that ranged from pure espionage to pure cybercrime, with many incidents falling somewhere in between. This was exemplified by operations where the objectives were both political and financial. One reason for this convergence is that some nation-state actors have embraced criminal techniques either to mask their involvement or to generate revenue.
Iran provides a case study: in addition to classic espionage, certain Iranian-linked groups engaged in ransomware operations. A joint advisory by U.S. agencies in 2024 revealed that Iran-based actors were cooperating with criminal ransomware gangs (like BlackCat/ALPHV), essentially moonlighting as initial access brokers and extortion consultants, even as they concurrently stole data likely to feed Iranian intelligence. This dual-purpose activity blurs the line between state and criminal actions.
Similarly, hacktivist crews turning to crime has been noted as a trend: groups that started with ideological hacking may shift to profit-driven attacks either to fund their cause or out of personal gain. For example, a Middle Eastern hacktivist group could deface an adversary’s website one week, then deploy ransomware against a private company the next.
Another form of hybrid threat is the coordination (direct or indirect) between state units and nominally independent criminal gangs. There are suspicions that some ransomware attacks on Gulf critical companies had political backing or ulterior motives beyond money, essentially using criminals as a proxy to weaken a rival nation’s economy. On the flip side, organized crime groups sometimes unwittingly serve geopolitical interests (for instance, by selling stolen data to a nation’s security service). The Middle East, with its intense conflicts and high financial stakes, saw several such convergent threats in 2024. This makes defending against threats more complicated: a breach might involve multiple actors with different motivations working in tandem. An APT could steal data quietly while a criminal encrypts systems noisily, all in one incident. From the defender’s perspective, it underscores the need for a comprehensive security posture that guards against espionage (protecting sensitive IP and state secrets) and ransomware (protecting availability and finances) at the same time.
In summary, the 2024 threat landscape in the Middle East was defined by a meld of espionage, cybercrime, and activism. Geopolitical instability and high-value targets created a magnet for APTs, while economic growth and digitalization attracted e-crime. These forces did not operate in isolation, they often intertwined, resulting in complex attacks that challenged conventional security strategies. The Middle East has truly become a microcosm of the global cyber threat environment, concentrated and intensified by the region’s strategic significance.
3. Major Regional Threat Actors and APT Groups
The 2024 cyber threat landscape in the Middle East was shaped by a diverse array of Advanced Persistent Threat (APT) groups with global ties. State-aligned threat actors from Iran, China, Russia, North Korea, and regional groups all actively targeted Middle Eastern governments, critical industries, and infrastructures. Their operations were largely espionage-driven; aiming to steal sensitive information, with select campaigns pursuing financial gain or destructive effects.

Figure 2. Geographic Spread of APT Campaigns in the Middle East (2024).
As depicted in Figure 2, the map presents the relative intensity of APT-based cyber activity across the Middle East throughout the year. Darker shades indicate higher volumes of state-sponsored cyber campaigns. Saudi Arabia, the United Arab Emirates (UAE), and Egypt emerged as the primary targets, facing extensive cyber espionage and strategic intrusions. Meanwhile, Bahrain, Qatar, Kuwait, Oman, Iraq, Jordan, Lebanon, and Palestine experienced moderate levels of cyber threat activity. In contrast, Syria and Yemen observed notably lower APT engagement. This geographic visualization sheds light on the concentrated nature of cyber threats, particularly in economically strategic and politically influential states.

Figure 3. Top Observed APT Groups in the Middle East (2024).
From another angle, Figure 3 above highlights the distribution and relative prominence of APT groups active in the Middle East during the year. OilRig (11.4%), MuddyWater (10.0%), and Magic Hound (9.3%) emerged as the most prolific actors, collectively accounting for approximately 31% of observed APT activities in the region. Notably, these three groups, all originating from Iran, underscore the significant role it plays in shaping the cyber espionage landscape across the Middle East. Other groups such as Lazarus Group (North Korea) and APT33 (Peach Sandstorm, Iran) were also active, reflecting the threat ecosystem where geopolitical interests strongly influence targeting strategies and operational intensity.
3.1 The Three Elephants in the Room
Among the wide array of threat actors active in the Middle East, three state-sponsored groups were behind the majority of the campaigns conducted across the region. To be specific, three Iranian-linked APT groups: OilRig, MuddyWater, and Magic Hound (APT35) stood out as especially prolific “elephants in the room” shaping the APT landscape. These groups were not only responsible for a significant share of observed campaigns, but also demonstrated expansive reach, persistent tactics, and strategic alignment with Iran’s regional interests.

1. APT Group: OilRig
| Names & Aliases | OilRig, APT34, Helix Kitten, Earth Simnavaz, UNC1860, TA452, Hazel Sandstorm, Cobalt Gypsy. |
| Country of Origin | Iran. |
| Threat Actor Type | Nation-State Sponsored. |
| Linked Organization | Ministry of Intelligence and Security (MOIS). |
| Objectives | Espionage, Sabotage, and Information Theft. |
| Targeted Countries | Egypt, Iraq, Jordan, Kuwait, Lebanon, Oman, Qatar, Saudi Arabia, and UAE. |
| Targeted Sectors | Aviation, Chemical, Defense, Education, Energy, Financial, Government, High-Tech, IT, Hospitality, Oil and gas, Telecommunications. |
In 2024, OilRig carried out a series of targeted espionage campaigns across the Arab Middle East, with notable activity observed in Iraq, the Gulf, and the Levant. A key operation compromised Iraqi government infrastructure using newly identified backdoors dubbed Veaty and Spearal, which exploited Microsoft Exchange servers for credential harvesting, established passive backdoors on IIS servers, and communicated via hijacked internal email accounts and DNS tunneling.
Parallel campaigns across the Gulf focused on oil, telecom, and financial entities, leveraging credential theft via Exchange-based implants and custom password filter malware. OilRig also exploited vulnerabilities such as CVE-2024-30088 to escalate privileges while maintaining persistence through PowerShell-based toolkits.
Phishing remained a consistent entry point, often delivering payloads through macro-laced Office documents or corrupted job offers. Notably, attackers shifted infrastructure and adapted implants from older tools like Karkoff and SideTwist, preserving stealth and operational continuity.
The group’s operations in 2024 demonstrated a sustained ability to adapt its malware, infrastructure, and delivery techniques. Attacks were often timed around politically sensitive periods, and lateral movement into neighboring states suggests a regional espionage strategy leveraging one breach to reach others.
2. APT Group: MuddyWater
| Names & Aliases | MuddyWater, Seedworm, TEMP.Zagros, Static Kitten, TA450, Boggy Serpens, Yellow Nix, Mercury, ITG17. |
| Country of Origin | Iran. |
| Threat Actor Type | Nation-State Sponsored. |
| Linked Organization | Ministry of Intelligence and Security (MOIS). |
| Objectives | Intelligence Gathering, Espionage, Information Theft. |
| Targeted Countries | Bahrain, Egypt, Iraq, Jordan, Kuwait, Lebanon, Oman, Qatar, Saudi Arabia, and UAE. |
| Targeted Sectors | Aviation, Defense, Education, Energy, Financial, Food and Agriculture, Gaming, Government, Healthcare, High-Tech, IT, Media, NGOs, Oil and gas, Shipping and Logistics, Telecommunications, Transportation. |
Throughout the year, MuddyWater significantly escalated its cyber campaigns across the Middle East, leveraging refined phishing tactics, novel malware, and sophisticated command-and-control (C2) infrastructure. Early in the year, extensive spear-phishing operations targeted entities in Saudi Arabia, UAE, Jordan, Lebanon, and Iraq, utilizing compromised email accounts to deliver legitimate Remote Monitoring and Management (RMM) tools, Atera and ScreenConnect.
By mid-2024, following heightened scrutiny on RMM misuse, MuddyWater swiftly adapted by introducing custom-built implants such as the BugSleep (MuddyRot) backdoor, embedded in PDF attachments disguised as legitimate documents linked from trusted file-sharing services like Egnyte. This tactical evolution reduced their digital footprint and enhanced evasion capabilities, demonstrating sophisticated operational agility in response to defensive measures.
The group also deployed an upgraded C2 framework, DarkBeatC2, characterized by stealthy PowerShell-based communication, spoofed domains, and integration of open-source reconnaissance platforms like reNgine. The adoption of diverse tools and continuous infrastructure shifts enabled effective campaign management at scale across various sectors, including governmental organizations, media, aviation, and telecommunications.
3. APT Group: MagicHound
| Names & Aliases | APT35, CharmingKitten, Cobalt Illusion, TEMP.Beanie, TA453, CharmingCypress, Mint Sandstorm, Yellow Garuda, Phosphorus. |
| Country of Origin | Iran. |
| Threat Actor Type | Nation-State Sponsored. |
| Linked Organization | Islamic Revolutionary Guard Corps Intelligence Organization (IRGC-IO). |
| Objectives | Espionage, Intelligence collection. |
| Targeted Countries | Egypt, Iraq, Jordan, Kuwait, Saudi Arabia, Syria, UAE, Yemen, and Palestine. |
| Targeted Sectors | Defense, Education, Energy, Financial, Government, Healthcare, IT, Manufacturing, NGOs, Oil and gas, Technology, Telecommunications, and organizations that are either based or have business interests in Saudi Arabia. |
MagicHound (APT35) conducted campaigns across the Arab Middle East which employed fake job offers, spoofed journalist personas, and social engineering tailored to geopolitical tensions to compromise individuals in defense, academia, and policymaking. One notable campaign impersonated recruiters from known companies, delivering ZIP files that deployed custom implants via .lnk shortcuts. These attacks installed SnailResin and SlugResin backdoors while mimicking North Korean tactics to obfuscate attribution.
Alongside these, phishing waves targeting Middle Eastern researchers and diplomats used trusted sender impersonation and topical lures; such as Gaza-related discourse or regional policy to distribute weaponized documents. Victims were led to download remote templates or archives that initiated multi-stage infections, culminating in the deployment of MediaPl and MischiefTut implants. These provided covert access, data exfiltration capabilities, and persistent control through LOLBins and PowerShell.
Toolset evolution continued with the discovery of BellaCpp, a C++ rewrite of the previously exposed BellaCiao malware. This updated variant featured encrypted configurations, modular payload support, and improved stealth for long-term espionage.
Observed targeting clustered around Saudi Arabia, UAE, Iraq, Lebanon, and Palestine, indicating an effort to monitor defense strategy, research communities, and regional diplomatic developments. These campaigns relied on deception, malware innovation, and personal profiling to quietly infiltrate sensitive environments.
3.2. Iran-Linked APT Groups
Prevalence and Objectives: Along with OilRig, MuddyWater, and APT35 (Magic Hound), Iranian state-sponsored actors remained highly active across the Middle East in 2024, conducting extensive espionage campaigns through deeply integrated groups such as APT33 (Peach Sandstorm), Fox Kitten, and Tortoiseshell. These actors targeted government ministries, diplomatic entities, defense and aerospace industries, energy sectors, and critical infrastructure. Their operations often utilized credential theft, exploitation of compromised VPN and RDP services, and custom-developed malware to quietly maintain persistent access and facilitate prolonged intelligence collection.
Notable Campaigns: APT33 (Peach Sandstorm) significantly expanded its espionage operations, particularly within Gulf countries such as the UAE. The group’s campaigns employed password-spray techniques for initial access and introduced a sophisticated, multi-stage backdoor called “Tickler,” leveraging fraudulent cloud services, including malicious Azure instances, to maintain discreet communication channels.
Fox Kitten notably pivoted towards financially motivated cybercrime by collaborating with ransomware affiliates such as ALPHV (BlackCat), RansomHouse, and NoEscape. The group provided these ransomware operators initial access to governmental, educational, financial, healthcare, and defense networks in the UAE, exploiting vulnerable network entry points and deploying persistent backdoors and web shells.
Tortoiseshell focused specifically on espionage targeting aerospace and defense sectors within Gulf nations, employing spear-phishing lures disguised as job offers. Their operations involved deploying specialized malware loaders and remote access tools (RATs) to stealthily gather sensitive defense-related data, aligning closely with Iran’s strategic objectives.
Evolving Tactics: A significant trend observed in 2024 was Iran’s blending of espionage operations with financially driven cybercrime activities. The Fox Kitten campaign exemplifies this shift, directly enabling ransomware operations by securing initial network access in exchange for financial incentives from ransomware affiliates. This convergence of state-sponsored espionage and cybercrime tactics underscores Iran’s strategic interest in monetizing cyber capabilities, complicating attribution, and amplifying the disruptive potential of its cyber operations across the Middle East. Overall, Iranian APTs in 2024 demonstrated both breadth, reaching almost every Middle Eastern country, and depth, with a mix of intelligence-gathering and disruptive capabilities.
3.3. Chinese APT Groups
Prevalence and Objectives: Several Chinese state-backed groups expanded their focus to the Middle East in 2024, driven by strategic espionage objectives. APT41 (Earth Baku) was especially notable – traditionally active in Asia, this group broadened its operations into the Gulf region. In a campaign dubbed Earth Baku, the APT41 crew targeted the United Arab Emirates and Qatar across multiple sectors including government, telecom, media, healthcare, education, and technology. Intelligence reports revealed that Earth Baku used sophisticated malware loaders (e.g. StealthVector/StealthReacher) to deploy modular implants, aiming to exfiltrate data while maintaining long-term stealths. This campaign exemplified China’s interest in Middle Eastern geopolitical and economic intelligence, from infrastructure projects to diplomatic communications.
Beyond APT41, other China-linked actors identified in the region included newly observed clusters (reported under code-names like SneakyChef and Diplomatic Specter) targeting Middle Eastern ministries of foreign affairs and politicians in 2024. These groups often masquerade as legitimate software providers or use watering-hole tactics. Their motivation is typically pure espionage: stealing diplomatic cables, trade secrets, and strategic plans. Notably, Chinese operations in the Middle East have focused on countries hosting critical infrastructure projects or strategic ports (aligning with China’s economic interests). For example, Operation Diplomatic Specter targeted foreign ministries and embassies across the region (attributed to an unknown Chinese cluster), and another campaign spoofed a software tool to infiltrate Middle Eastern government networks (attributed to an actor originating within the Middle East but possibly linked to Chinese malware tooling). These incursions reflect China’s growing cyber footprint in the Middle East’s political and economic sphere.
Tactics: Chinese APTs are known for their technical sophistication and supply-chain tactics. In 2024, they leveraged stolen credentials and exploited public-facing applications for initial accesss. Once inside, they deploy custom backdoors and stealthy data exfiltration tools. For instance, Earth Baku was observed using a benign-looking VPN service (Tailscale) in victim networks for covert communications. The emphasis is on stealth and persistence, Chinese malware often remains hidden for months, quietly siphoning information. The broad sectoral spread of targets (from telecommunications and technology to healthcare and government) suggests an intelligence-gathering mandate aiming to support China’s foreign policy and commercial interests in the Middle East.
3.4. Russian APT Groups
Prevalence and Objectives: Russia’s state-sponsored hacking groups continued to operate globally in 2024, with some activity touching the Middle East, largely as an extension of Moscow’s geopolitical campaigns. APT28 (Fancy Bear) and APT29 (Cozy Bear), the GRU and SVR-linked units respectively, primarily concentrated on NATO/Eastern Europe due to the war in Ukraine, but they did target Middle Eastern networks opportunistically. For example, an FBI cybersecurity advisory noted that APT28 compromised networking devices (such as routers and VPN appliances) in countries like Jordan and the UAE as part of its broader campaign to collect intelligence on governments and critical sectors. These operations targeted a wide range of industries, from Aerospace & Defense and Energy to Education and Government, indicating that Russian actors sought any valuable intelligence related to Middle Eastern states’ positions on international issues. Such access could allow Russia to monitor regional diplomacy or military cooperation with Western allies.
OilAlpha, a lesser-known actor initially thought to operate from Yemen, may also have Russian ties or support Russia-aligned interests. In 2024, it targeted humanitarian and media organizations in Saudi Arabia and Yemen, likely to gather intelligence on conflicts and relief operations. Overall, Russian APT motives in the region center on classic espionage: tracking Middle Eastern governments’ stances, military procurements, and energy markets, especially in the context of global sanctions and alliances.
Tactics: Russian actors favor infrastructure compromise and phishing. APT28, for instance, deploys network device malware to harvest credentials or eavesdrop on communications (often leaving few traces on endpoint computers). APT29 excels at spear-phishing high-value individuals (diplomats, defense officials) with tailored lures to deliver trojans and steal emails. In 2024, no major destructive cyber-attacks in the Middle East were definitively attributed to Russian APTs, their known destructive operations (e.g. energy grid attacks) remained focused on Ukraine. However, the risk of spillover exists: Russian hackers have shown capability to deploy wiper malware or temporarily disrupt critical systems, and Middle Eastern networks could be indirectly affected (for example, if they are used as staging grounds or if a conflict escalates in cyberspace).
3.5. North Korea and Other Regional Actors
North Korea’s Lazarus Group: The Lazarus Group (linked to North Korea’s Reconnaissance General Bureau) stood out as a major actor targeting the Middle East in 2024. Lazarus is unique in that it pursues both espionage and financial gain. In the past year, it conducted a stealthy campaign (Operation Phantom Circuit) breaching telecom and IT providers across Oman, the UAE, Saudi Arabia, Qatar, Bahrain, and Egypt to secretly monitor communications and siphon data; likely in support of North Korean intelligence needs. Simultaneously, Lazarus cells continued their global cryptocurrency theft operations, some of which extended into the Middle East’s burgeoning crypto sector. Multiple cybersecurity firms reported Lazarus targeting crypto exchanges and fintech startups worldwide, including in the Gulf, using elaborate social engineering (for instance, posing as recruiters on LinkedIn) and deploying custom malware to steal digital currencies.
Lazarus’ dual mission is reflected in its methods: it uses advanced malware toolkits (e.g. the AppleJeus family of crypto-stealing malware and stealthy rootkits) for financial heists, and more conventional espionage malware for spying. In 2024, security research highlighted Lazarus’s increasing sophistication, such as embedding malicious code in open-source software packages to infect target organizations undetected. The group’s activities in the Middle East have strategic implications; by compromising telecom networks and defense contractors, Lazarus can exfiltrate military and diplomatic intel, while its theft of funds (cryptocurrency or even traditional ransomware extortion) indirectly finances North Korea’s regime. The presence of North Korean hackers in Middle Eastern networks elevates the cybersecurity risk for regional financial institutions and any organization holding valuable IP or data.
Regional and Ideologically Motivated Groups: In addition to the big state players, 2024 saw cyber activity from groups rooted in Middle East conflicts and regional politics. The WIRTE Group, believed to be a Gaza/Hamas-affiliated team, expanded beyond espionage into disruptive attacks. Intelligence sources reported that WIRTE (sometimes dubbed a “Hamas cyber unit”) carried out two distinct campaigns during 2024, including attempts to deploy wiper malware on government networks in the Palestinian territories and neighboring Arab countries. WIRTE’s targeting spanned Palestinian Authority institutions as well as Egypt, Jordan, Iraq, and Saudi Arabia, reflecting an intent to surveil regional governments and possibly retaliate against those seen as adversarial. Its motivations blend espionage with hacktivism or sabotage aligned to the Israel–Palestine conflict.
Another example is OilAlpha, a threat actor identified in Yemen. OilAlpha emerged mid-2024 targeting humanitarian organizations, media outlets, and government agencies in Yemen and Saudi Arabia. This group’s origin is not definitively confirmed, some evidence suggests a Yemen-based actor (potentially linked to the Houthi movement) with Iran-aligned interests. The objectives of OilAlpha were espionage and information operations: by infiltrating NGOs and media, the group can gather intelligence on humanitarian activities and influence narratives around the Yemen conflict.
Finally, SideWinder, an Indian subcontinent APT known for targeting Pakistan and neighboring states, also appeared in Middle Eastern cyber incidents. There has been documented SideWinder attacks on government and military entities in Saudi Arabia, the UAE, and Egypt, indicating that regional rivalries (India-Pakistan) sometimes spill into Middle Eastern cyberspace when, for instance, Pakistani interests or allies in the Gulf are targeted. SideWinder’s tactics include sending trojanized documents relevant to Middle Eastern geopolitics to infect victims (for example, fake briefing papers on defense cooperation).
Other Unattributed Threats: At least a handful of sophisticated attacks in the region during 2024 remain unattributed to known APT groups. These “unknown” threat actors were observed using bespoke malware and infrastructure. For instance, one campaign used a fake software update tool to target multiple Middle Eastern governments (discovered by Trend Micro), and another dubbed “DuneQuixote” by researchers involved espionage against a Middle Eastern government in early 2024. Some of these may eventually be linked to established APTs (early hints suggest Chinese origins in some cases), while others could represent new actors emerging from the region’s evolving cyber landscape.
3.6. Strategic Implications for Regional Cybersecurity
The 2024 APT threat landscape underlines that the Middle East is an active battleground for state-sponsored cyber operations. Espionage is the dominant theme, with adversaries focusing on governmental, diplomatic, and economic intelligence. Virtually every Middle Eastern government, especially the more geopolitically connected (GCC states, Egypt, etc.), has been subject to intrusions. For regional CISOs and decision-makers, this means that sensitive communications and data are persistently at risk, requiring robust encryption, network monitoring, and threat intelligence sharing at the national level.
Another key implication is the targeting of critical infrastructure. Energy companies (oil & gas), telecommunications providers, and transportation hubs in the Middle East have been singled out by multiple APTs (Iranian, Chinese, and others). Compromise of these sectors not only threatens economic stability but could also have safety implications (e.g., disruption of oil supply or power grids). Nations in the region must prioritize cyber defense in these industries, enforcing strong authentication, regular vulnerability patching (many Iranian breaches began with unpatched VPN servers), and closer public-private collaboration on security. The fact that groups like APT41 attacked healthcare and education networks as well suggests that no sector is off-limits. Even universities and hospitals (which often have less mature security) can be indirect avenues to steal research or personal data.
The blurring of criminal and state-sponsored activity, exemplified by Iran’s partnership with ransomware gangs, is a worrying trend. Middle Eastern organizations might find themselves victims of ransomware not just for profit but as a byproduct of state-affiliated hackers pursuing dual goals. This calls for a dual approach to resilience: traditional cybercrime defenses (backup strategies, incident response for ransomware) combined with counter-espionage measures. It also raises policy questions: e.g., should governments treat ransomware attacks as potential state-sponsored incidents if evidence links to groups like Fox Kitten?
Finally, the multiplicity of threat actor origins (Iran, China, Russia, North Korea, India/Pakistan, plus local actors) operating in the Middle East means that regional cybersecurity is entwined with international politics. Intelligence sharing and diplomatic cooperation will be crucial. Gulf states and allies might consider joint cyber defense initiatives, since the same threat groups are hitting many countries in parallel. Attribution of attacks can be sensitive in diplomacy, but quietly sharing indicators of compromise and tactics among trusted partners can greatly enhance collective defense.
In summary, 2024 demonstrated that Middle Eastern nations are not just passive targets but integral to the operational theatres of the world’s most active APT groups. Building cyber resilience; through strengthened defense postures, user awareness of phishing, zero-trust network architectures, and regional threat intelligence exchange, is now a strategic imperative for the Middle East. Decision-makers should approach cybersecurity as a foundation of national security and economic stability, investing in the capacity to detect, respond to, and recover from state-sponsored attacks. The coming years will likely bring continued APT attention to the region; however, a coordinated and well-informed cybersecurity community can mitigate these risks and protect the region’s digital future.
4. A Year of Ransomware
Ransomware remains a critical threat to organizations across the Middle East, driven by both opportunistic cybercriminals and more advanced, well-funded adversaries. In 2024, 39 ransomware families were observed, targeting diverse sectors such as technology, construction, healthcare, government, and energy. In addition to the operational disruption (e.g., production halts, service outages) and financial losses (costs of downtime, ransom payments), ransomware attacks can severely damage brand reputation and public trust.
- Regional Complexity: Geopolitical tensions and high-value critical infrastructure make Middle Eastern organizations prime targets.
- Rapid Weaponization: Ransomware-as-a-Service (RaaS) models lower the barrier for would-be attackers, creating a dynamic threat environment.
This section provides a data-driven overview of ransomware activity in 2024 and profiles the top five ransomware families. Emphasis is placed on their technical capabilities, typical targets, and extortion methods. By understanding these families’ behaviors and evolution, stakeholders can develop strategies for effective threat mitigation.
4.1. Ransomware by the Numbers
Throughout 2024, 116 confirmed ransomware incidents were recorded in the Middle East, with each attack displaying unique characteristics in terms of infiltration, lateral movement, encryption, and extortion. However, consistent trends emerged:
- Double/Triple Extortion Models
Many groups exfiltrate data before encryption, threatening to publish stolen information if victims refuse to pay. Some families (e.g., LockBit 3.0) add DDoS or direct client outreach as further pressure tactics.
- Diverse Target Sectors
Critical industries (construction, energy, healthcare) and government agencies remain frequent targets due to the potentially severe disruption and high ransom yield.
- Rapidly Evolving Tactics
Several families (notably FunkSec) adopt AI-assisted development to refine malware quickly, while others like RansomHub and Qilin rebrand or share code across multiple variants.
Monthly Incidents
As shown in Figure 4, the monthly incidence of ransomware fluctuated over the year, with a noticeable dip in June–July followed by a sharp rise from October to December. These spikes often correlate with seasonal factors, holiday staffing gaps, or high-value campaigns launched by emerging RaaS affiliates.

Figure 4. Ransomware Incidents Observed in 2024 (By Month).
Note: Timelines for some reported incidents are estimated due to limited visibility into internal network compromises; actual attack timelines may differ if disclosure was delayed. The statistics presented are based on the most up-to-date intelligence as of January 2025.
Top Ransomware Families
Of the 39 ransomware families observed, five dominated the threat landscape, collectively accounting for nearly half (46%) of all incidents:
- RansomHub (16%)
- LockBit 3.0 (10%)
- Qilin (Agenda) (7%)
- FunkSec (7%)
- Stormous (6%)
Smaller or newly emerging families; including ElDorado, DragonRansomware, DarkVault, Sarcoma, Killsec, and others, comprised the remaining share (see Figure 5).

Figure 5. Top Observed Ransomware Families in the Middle East (2024).
Geographic Distribution
While ransomware is a global issue, certain countries in the region experienced disproportionately high volumes of incidents. Figure 6 shows that the UAE leads by a wide margin, exceeding 50 recorded attacks, followed by Saudi Arabia and Egypt, with smaller tallies in other Gulf and Levant states. These disparities may reflect variations in infrastructure maturity, reporting transparency, or attacker perception of victim “payout” potential.

Figure 6. Ransomware Incidents Observed in 2024 (By Country).
Targeted Sectors
Ransomware groups commonly target industries with limited downtime tolerance or high-value data, such as technology, construction, healthcare, energy, and government. As displayed in Figure 7, these critical sectors remain prime objectives for extortion-driven campaigns; likely due to the potential scale of disruption and willingness to pay for quick restoration.

Figure 7. Ransomware Incidents Observed in 2024 (By Targeted Sector).
4.2. Top Five Ransomware Families
1. RansomHub
RansomHub is a ransomware-as-a-service (RaaS) operation that burst onto the scene in early 2024, quickly making waves with its generous 90% revenue share for affiliates and a cunning approach to infiltration and encryption. Advertised by the threat actor “koley” on the Ramp Forum, RansomHub’s emergence was no accident; it incorporates rebranded or purchased code from older strains like Knight and has close ties to other notorious groups, including ALPHV (BlackCat).
| Attribute | Details |
|---|---|
| Emergence | First emerged in February 2024 as a RaaS, promoted by the threat actor “koley” on the Ramp Forum. |
| Country of Origin | [Unknown]. |
| Motivation | Financial gain (high-value targets, large ransoms). |
| Technical Details | Written in Golang and C++, targets Windows, Linux, and ESXi environments. |
| Notable Characteristics | – Affiliate group: ALPHV (BlackCat). – Shares code overlaps and configuration keys with Knight ransomware (likely rebranded purchase). – “README_.txt” ransom note warns victims against seeking law enforcement. – Offers a 90% revenue share to affiliates, fueling rapid adoption. |
| Typical Targets | Construction firms, IT services, healthcare facilities, and large enterprises. |
| Extortion Method | Double extortion: data theft + file encryption, posted on the “RansomHub Blog” if ransom is not paid. |
| Common TTPs | – Exploits Zerologon (CVE-2020-1472) for domain admin privileges. – Uses tools like Splashtop Atera for lateral movement. – Affiliates can reboot endpoints in safe mode prior to encryption (bypassing security tools). |
| Key Insight | Rapidly rose in prominence due to lucrative affiliate payouts and rebranded code from older ransomware families. |
2. LockBit 3.0
LockBit 3.0, also referred to as “LockBit Black“, is a ransomware-as-a-service (RaaS) variant that traces its lineage back to the LockBit Gang, active since 2019. Over multiple evolutions (LockBit 1.0, 2.0, and 3.0), this group has launched simultaneous extortion blogs and consistently refined its techniques. Despite Operation Cronos in February 2024, a multinational law enforcement operation seizing 34 LockBit servers, LockBit 3.0 remains active, leveraging a mix of advanced encryption (AES + RSA), multi-OS support (Windows, Linux, ESXi, macOS), and double-extortion to pressure victims into payments.
| Attribute | Details |
|---|---|
| Emergence | Evolved from LockBit 1.0 (2019) to LockBit 3.0 in June 2022, each version releasing an updated extortion blog simultaneously. |
| Country of Origin | Russia. |
| Motivation | Financial gain, with ransom amounts ranging from $85,000 to over $1 million. |
| Technical Details | – Targets Windows, Linux, ESXi, macOS. – Uses AES + RSA for encryption. – Integrates tactics from other strains (e.g., BlackMatter). |
| Notable Characteristics | – Operation Cronos partially disrupted infrastructure in Feb 2024. – Law enforcement-developed decryptors available for some victims. – Introduced new payment options (BTC, Monero, Zcash) and “pay to extend,” “pay to destroy,” or “buy stolen data” models. |
| Typical Targets | Government, public education, municipal services, energy sector, and large enterprises. |
| Extortion Method | Primarily double extortion (encryption + data theft), occasionally triple extortion (DDoS threats). |
| TTPs | – Initial Access: Phishing, drive-by compromise, exploiting known CVEs (Log4j, Zerologon). – Lateral Movement: SMB, PsExec, Cobalt Strike. – Impact: Data encryption, file exfiltration, and ransom notes forcing high-pressure payment. |
| Key Insight | Despite law enforcement efforts, LockBit 3.0’s multi-platform approach and constant feature updates allow it to remain highly effective, especially where vulnerabilities and weak credentials persist. |
3. Qilin (Agenda)
Qilin (formerly known as “Agenda“) is a ransomware-as-a-service (RaaS) threat group that first surfaced in July 2022, rebranding in October 2022. Samples of the ransomware are written in both Go (Golang) and Rust, showing code similarities with BlackBasta, BlackMatter, and REvil (Sodinokibi). The group is known for double extortion, demanding payment for decryption while threatening to publish stolen data. Despite claiming to exclude certain CIS countries, Qilin’s RaaS model has facilitated attacks across multiple regions and industries.
| Attribute | Details |
|---|---|
| Emergence | Active since July 2022; rebranded from “Agenda” to “Qilin” in October 2022. |
| Country of Origin | Russia. |
| Motivation | Financial gain, with ransoms ranging from $50k to $800k, scaling up to $50 million in extreme cases (e.g., healthcare providers). |
| Technical Details | – Go & Rust codebase. – Targets Windows, Linux, ESXi. – Features advanced encryption modes (skip-step, percent, fast) and intermittent encryption to evade detection. |
| Notable Characteristics | – Two-tier RaaS payout: affiliates earn 80% if ransom ≤ $3M, 85% if > $3M <br/> – Has a Telegram channel (inactive since June 2024) <br/> – Claims to forbid attacks on CIS countries. |
| Typical Targets | Law, healthcare, finance, manufacturing, and IT services. |
| Extortion Method | Double extortion (encrypt + threaten data leaks) with a Tor-based extortion blog (“Qilin”). |
| TTPs | – Initial Access: Phishing (spearphishing attachments/links), RDP brute force. – Lateral Movement: PsExec, SSH, PowerShell scripts. – Impact: Encrypts critical systems, demands crypto payment, threatens data leaks. |
| Key Insight | Qilin’s adaptability (written in Go & Rust) and flexible encryption approach allow affiliates to tune attacks, representing a formidable threat to any region lacking robust defenses. |
4. FunkSec
FunkSec emerged in late 2024, claiming over 85 global victims in December alone and extending its reach into the UAE, Egypt, Qatar, Jordan, and Lebanon. Although it brands itself as a Ransomware-as-a-Service (RaaS) venture, FunkSec blurs lines with hacktivism by reusing data from older campaigns. Its core developers appear to rely on AI-assisted (Rust-based) tool generation, issuing low ransom demands (as little as $10,000) and running a Tor-based leak site to gain maximum visibility. Despite doubts about its true victim count and the authenticity of many leaks, the group’s evolving tactics still pose a tangible risk across various Middle Eastern industries.
| Attribute | Details |
|---|---|
| Emergence | Surfaced late 2024; quickly claimed over 85 global victims in December alone. |
| Country of Origin | Algeria for core developer(s), per location slips in screenshots and Rust binaries, though no official group origin is stated. |
| Motivation | Financial gain with possible hacktivist undertones; aims for recognition/visibility by inflating claims of data leaks. |
| Technical Details | – AI-assisted malware development enabling rapid iteration. – Rust-based encryptor (“.funksec”) with frequent updates. – Evidence of code duplication and repeated calls (suggesting less-experienced authors). |
| Notable Characteristics | – Low ransom demands ($10k+). – Many leaked datasets appear recycled or “fake” from prior hacktivist campaigns. – Maintains a data leak site (DLS) featuring breach announcements and a custom DDoS tool. |
| Typical Targets | Healthcare, finance, manufacturing, government, and IT. |
| Extortion Method | Double extortion (data theft + encryption), selling stolen data cheaply on their data leak site. |
| TTPs | – Initial Access: Possibly phishing, direct infiltration with stolen credentials, brute force. – Execution: Rust-based binaries with heavy code repetition. – Impact: File encryption, data leak threats on a Tor-based site. |
| Key Insight | FunkSec’s “AI-driven” approach and low-skill coding style produce high-volume, low-sophistication attacks, but the group’s marketing and repeated updates keep it visible on ME threat radars. |

Figure 8. FunkSec data leak site.
In addition to the ransomware, the FunkSec group offers additional tools, most of them commonly associated with hacktivist activity (see Figure 9). The availability of these ancillary tools further reflects the group’s blurred lines between pure cybercrime and hacktivist-style exploits.

Figure 9. Additional offerings by FunkSec.

Figure 10. FunkSec ransomware note.
5. Stormous
Stormous is a financially motivated threat group behind the StormouS.X/GhostLocker ransomware-as-a-service (RaaS) program, first unveiled in February 2024. This affiliate program is tied to a broader hacktivist-cybercriminal collective known as “The Five Families”, which includes actors like GhostSec, Blackforums, SiegedSec, and ThreatSec. Recent findings indicate that GhostLocker; originally introduced in October 2023 by GhostSec, has evolved into a new RaaS franchise attracting other groups, including Stormous. While GhostSec purportedly retired from direct cybercrime in May 2024, Stormous continued to expand GhostLocker operations, influencing attack activity across the Middle East, including the UAE and other regional targets.
| Attribute | Details |
|---|---|
| Emergence | StormousX (July 2022), GhostLocker 2.0 (late 2023), GhostLocker 3.0 (July 2024). StormouS.X/GhostLocker RaaS launched in February 2024. |
| Country of Origin | [Uknown]; Stormous forbids data leaks from Russian or “neighboring” entities, but no stated origin for the group itself. |
| Motivation | Financial gain via RaaS extortion; also some hacktivist-like elements through alliances with GhostSec. |
| Technical Details | – GhostLocker primarily targets Windows systems (x86/x64). – Ransomware includes features like disabling Task Manager, bypassing UAC, fast encryption, and comprehensive affiliate dashboards. |
| Notable Characteristics | – Adoption of the new GhostLocker RaaS (Figure 11 below). – Part of “The Five Families” collective (hacktivist-cybercrime convergence). |
| Typical Targets | Healthcare, manufacturing, finance, government, construction, education, and IT. |
| Extortion Method | Double extortion: After encrypting data, threatens to publish stolen files on StormouS.X Blog or name-and-shame via Telegram channels. |
| TTPs | – Initial Access: RDP exploits, phishing, supply chain compromises. – Execution: Python-based GhostLocker code (obfuscated, compiled with Nuitka), disabling critical Windows processes. – Impact: Rapid encryption (AES), data leaks, ransom negotiation demands. |
| Key Insight | Stormous merges hacktivist-style branding with commercial RaaS tactics, capturing a broad affiliate base and threatening Middle Eastern organizations across multiple sectors. |

Figure 11. Stormous announcing their adoption of GhostLocker.
5. Regional Malware Trends
The threat landscape was heavily shaped by the widespread use of stealers, Remote Access Trojans (RATs), and loaders, both globally and across the Middle East. These malware families have become the cornerstone of many modern cybercriminal campaigns; each serving distinct functions within an attack chain.
Global Perspective
Globally, stealers led the malware activity charts, with over 51,000 detections, highlighting a continued focus on harvesting credentials, financial data, and personal information. This was followed by loaders (28,754 detections), which play a crucial role in facilitating malware deployment by fetching and executing payloads post-infection. RATs remained a persistent threat, with 24,430 detections, enabling adversaries to silently gain control of compromised systems for espionage, lateral movement, or data exfiltration.
Regional Focus: The Middle East
The Middle East closely mirrored global trends but revealed unique insights into attacker behavior and targeted malware preferences. In this context, Cipher has identified the top 20 malware targeting the region in 2024, based on observed detections and internal telemetry data. These 20 malware families collectively accounted for 102,534 detections, categorized by malware type and family, offering a detailed view into the regional threat landscape.
Lumma Stealer emerged as the most detected malware in the region, with a share of 14.29%, underscoring its popularity among cybercriminals focused on credential harvesting and financial data theft. Lumma’s dominance highlights the regional prioritization of data monetization.
Following Lumma, AsyncRAT and Agent Tesla stood out with high detection volumes, both offering remote control, surveillance, and data exfiltration capabilities. These tools are often used in espionage operations and commodity attacks alike.
The continued presence of legacy threats such as njRAT and Emotet signals the region’s ongoing struggle with malware propagated through phishing and spam campaigns, revealing gaps in email security hygiene and user awareness.
What sets the Middle East apart is the broad diversity of malware families seen in the region. Noteworthy are newer threats like Stealc and XWorm, which represent a shift toward stealthy, modular malware strains. The appearance of Cobalt Strike, a post-exploitation framework increasingly abused by both APT actors and cybercriminals, highlights the blending of advanced and commodity threat techniques.
Figure 12 below highlights the top 10 identified threats in the Middle East, with the complete classification and further details available in Appendix A.

Figure 12. Top 10 Malware Types in the Region (by Detection Volume).

Figure 13. Malware Family Distribution Across the Top 20 Detected Malware in 2024.
6. Top Exploited Vulnerabilities
2024 witnessed numerous critical vulnerabilities that have been actively exploited. To which, affecting critical infrastructure, security tools, and widely used enterprise software. Exploiting these flaws, attackers can gain unauthorized access to systems, execute arbitrary code, steal sensitive data, or disrupt operations.
The following table highlights critical vulnerabilities reported in 2024, their associated vendors, and the impacted products. These vulnerabilities are all categorized as “Critical” based on their severity and the potential impact they have on affected systems.
Table 1. Top Exploited Critical CVEs and Their Impact (2024).
| CVE ID | Affected Vendor/Products | Impact |
|---|---|---|
| CVE-2024-3400 | Palo Alto Networks / PAN-OS | Remote code execution |
| CVE-2024-4040 | CrushFTP | Remote code execution, unauthorized access |
| CVE-2024-9463 | Palo Alto Networks / Expedition | Remote code execution, allowing system compromise. |
| CVE-2024-9680 | Mozilla / Firefox | Remote code execution via malicious websites. |
| CVE-2024-47575 | Fortinet / FortiManager | Remote code execution with elevated privileges. |
| CVE-2024-40711 | Veeam / Backup & Replication | Remote code execution by unauthenticated attackers. |
| CVE-2024-7593 | Ivanti / Virtual Traffic Manager | Remote, unauthenticated exploitation. |
| CVE-2024-3272 | D-Link / Multiple NAS Devices | Remote code execution, and potential exposure of sensitive DNS information |
| CVE-2024-3273 | D-Link / Multiple NAS Devices | Remote code execution, and potential exposure of sensitive DNS information |
| CVE-2024-37079 & CVE-2024-37080 | VMware / vCenter | Remote code execution |
| CVE-2024-29849 | Veeam / Backup Enterprise Manager | Authentication bypass vulnerability |
| CVE-2024-21410 | Microsoft / Exchange Server | Potential server compromise, data theft. |
| CVE-2024-21762 | Fortinet / FortiOS | Complete compromise of Fortinet devices. |
| CVE-2024-4671 | Google / Chromium | Allow attackers to bypass browser security |
| CVE-2024-0012 | Palo Alto Networks / PAN-OS | Remote code execution, compromising devices. |
| CVE-2024-9465 | Palo Alto Networks / Expedition | Remote code execution, enabling system control. |
| CVE-2024-28987 | Solar Winds / Web Help Desk (WHD) | Unauthorized access to internal functionality and data. |
| CVE-2024-8963 | Ivanti / Cloud Services Appliance | Unauthorized access to restricted functionality. |
| CVE-2024-21887 | Ivanti / Connect Secure/ Policy Secure | Increased attacker capabilities within Ivanti products. |
The chart below shows the distribution of critical CVEs across various vendors. We observe that Palo Alto Networks has 4 critical vulnerabilities, Ivanti has 3, D-Link, Fortinet, Veeam, and VMware have 2 each, while CrushFTP, Google, Microsoft, Mozilla, and SolarWinds have 1 each.

Figure 14. Distribution of Critical CVEs by Vendor (2024).
7. Dark Web Insights
The dark web landscape saw through notable shifts in market structure, threat actor behavior, and attack infrastructure. This section outlines key global trends before zooming into specific threat actor behaviors, tools, and discussions relevant to the region.
7.1. Key Global Dark Web Trends
- Market Fragmentation and Trust Erosion: The takedowns of infamous dark web markets such as Nemesis Market, Genesis Market, BreachForums, and others triggered fragmentation. Actors moved to invite-only forums, Tox-based communications, and Telegram. Over 80% of new marketplaces failed within nine months, reflecting rising distrust.
- Proliferation of Initial Access Brokers (IABs): IABs became more targeted and professional, advertising network access by sector, geography, and company size. Listings often supported ransomware operations, with prices ranging from $250 to $3,000.
- Credential Theft and Stealer Log Markets: Logs from stealers like RedLine, Raccoon, and Lumma dominated underground trade. Bundled with account checkers, these logs enabled efficient takeovers and were often sorted by country and platform.
- Migration to Encrypted Messaging Platforms: Cybercriminals increasingly favored Telegram and Discord, with over 60,000 crime-related Telegram channels tracked globally. These platforms reduce visibility and complicate monitoring efforts.
- Pay-to-Unlock Leak Models: Ransomware operators and data brokers offered partial breach samples for free, while full datasets were sold privately, turning leaks into high-value commodities.
- Adoption of AI Tools: Generative AI was used for phishing kits, scam automation, and deepfakes. While still maturing, these tools lowered the entry barrier and increased operational scale for cybercriminals.
7.2. Dark Web Threat Activity in the Middle East
The Middle East experienced a surge in dark web-driven threats, influenced by global trends but tailored to local conditions. High digital adoption, financial growth, and regional tensions made countries like Saudi Arabia, the UAE, and Egypt key targets for majority of dark web incidents.
- Exposure of Regional Credentials and Data
Over 1.8 million credentials tied to Middle Eastern entities were found on dark web markets and Telegram in 2024. These included access to enterprise VPNs, government portals, and telecom platforms; largely harvested via stealer malware.
Based on our telemetry data and intelligence sources, Cipher reported over 1000 credential leaks to clients across various industries. This exposure heightens the risks of unauthorized access, data breaches, financial loss, and reputational damage, while also expanding the attack surface, eroding customer trust, and potentially causing compliance violations and operational disruptions.
- Targeted Brand Impersonation and Phishing
There was a threefold increase in spoofed domains using Middle East-specific Top-Level Domains (TLDs). Phishing kits mimicking Qatari and Omani banks circulated on Telegram, often sold with hosting support and built-in evasion.
| Regional Focus: Saudi Arabia |
|---|
| The financial impacts of these phishing campaigns in Saudi Arabia alone were staggering, with estimated losses ranging from $70 to $100 million in 2024. This surge in phishing activity is directly tied to the growing digitization of the region’s financial services sector, which has made it a prime target for cybercriminals. The most affected industries include: • Financial Services: Banks and financial institutions were the primary targets, with cybercriminals leveraging fraudulent websites and phishing kits to steal sensitive customer data. • E-Commerce and Service Portals: Digital payment systems and online service platforms were also heavily targeted, reflecting the broader trend of cybercriminals exploiting online infrastructures. |
- Initial Access Listings Involving Middle Eastern Entities
Initial access to organizations based in the Middle East was a prominent commodity on dark web forums and marketplaces. Over 120 listings were observed in 2024 advertising unauthorized access to companies in the region. Listings often included system specifications, domain names, and user privileges, highlighting the depth of reconnaissance performed by access brokers. Many listings provide access via RDP, VPNs, or remote desktop tools like Citrix, ScreenConnect, AnyDesk, and RDWeb. Attackers also target internal resources through e-commerce platforms (Magento, WordPress), databases (MySQL, phpMyAdmin), POS systems, and web consoles (cPanel), using these entry points to escalate their attacks.

Figure 15. Distribution of Dark Web IAB Posts by Industry.

Figure 16. Dark web forum post offering initial access to a UAE-based organization.

Figure 17. A discussion thread on dark web forums advertising access to a system based in Egypt.
- Mentions of Regional Targets on Underground Forums
Arabic-language phishing kits, malware panels, and breach discussions increased on region-focused forums. This shift reflects growing localization in attack tooling and an effort to better exploit regional infrastructure.
- Hacktivism and Geopolitically Driven Threats
Hacktivist activity continued to pose a significant threat across the Middle East, driven by ongoing regional conflicts, political instability, and deep-rooted ideological divisions. While many of these campaigns were symbolic, they had a tangible impact on public confidence, government authority, and the availability of digital services. The rise in such operations was further intensified by escalating geopolitical tensions, particularly the Israel-Palestine conflict, and the growing sophistication of threat actors in the region.
| Regional Focus: UAE |
|---|
| The threat actor SN_BlackMeta has shown a recurring interest in targeting the UAE, particularly its financial and digital infrastructure. One notable record-breaking six-day attack occurred in July 2024, when the group launched a six-day DDoS campaign against a UAE-based financial institution. The attack peaked at 14.7 million requests per second, with sustained waves lasting up to 20 hours. The campaign severely impacted online services, reducing legitimate web traffic to just 0.002% at its lowest. “SN_BlackMeta” publicly claimed responsibility via their Telegram channel, where they often announce operations in advance and post follow-up statistics or images to amplify their messaging. This incident reflects the group’s shift toward prolonged, high-impact operations, leveraging DDoS-for-hire services like InfraShutdown, and underscores the growing hacktivist threat landscape in the region. Motivation: The group cited support for Palestinian causes, aiming to disrupt infrastructure tied to nations they view as adversaries. |

Figure 18. Threat actor announcing the start of coordinated attacks on multiple UAE institutions, including the target of the six-day DDoS campaign.



Figures 19, 20 and 21. Examples of attack announcements and updates for different countries.
8. Tactics, Techniques, and Procedures (TTPs) in Focus
This section examines the prominent TTPs observed in the Middle East during 2024 across two categories of threat actors: APT groups, and ransomware variants. For each actor type, we highlight the most abused techniques, emerging trends, and unique adaptations.
8.1. APT Groups: Stealthy Infiltration and Sustained Access
Advanced Persistent Threat groups in the region largely favored techniques that enable quiet infiltration and long-term persistence. APT initial access often relies on spearphishing with malicious attachments [T1566.001]. Attackers send targeted emails with weaponized documents or files, counting on victims to open them and trigger malware execution. These lures frequently employ social engineering and file masquerading [T1036], for example, an executable file disguised as a PDF or Word document
Once inside, APT groups tend to live off the land using legitimate tools and credentials. One of the most prevalent techniques is abuse of Valid Accounts [T1078] for lateral movement and persistence. By stealing or acquiring credentials (often through info-stealer malware dumps on the dark web), APT actors can log in as valid users and quietly access additional systems. This allows them to bypass many security controls by appearing as normal network traffic. In 2024, multiple Middle Eastern APT campaigns leveraged stolen admin credentials to expand access within victim networks, highlighting credential theft as a cornerstone of APT operations. APT groups also heavily utilized scripting and command-line interpreters [T1059] such as PowerShell and Windows Command Shell to execute payloads and administer systems. This tactic lets them run malicious code through trusted utilities, often with obfuscated scripts to avoid detection. For persistence, APT attackers favored techniques like Boot or Logon Autostart Execution [T1547], e.g. adding registry Run keys or scheduled tasks to ensure their malware or backdoor launches on reboot. They commonly created hidden scheduled tasks [T1053] or Windows services [T1543] under innocuous names for privilege escalation and recurring execution. These built-in OS mechanisms give APT malware a foothold that survives reboots and maintenance.
Notably, APTs in the region showed relatively lower reliance on heavy anti-VM sandbox evasion techniques, instead, many APT malware are hand-crafted for target environments and use other stealth measures. APT groups did adapt by targeting cloud and SaaS environments more in 2024, using techniques like stealing session tokens and abusing cloud accounts, but their core TTPs remained spearphishing, credential access, and stealthy persistence. Overall, Middle East APTs continued to refine tried-and-true techniques to quietly gather data over long durations.
8.2. Ransomware Variants: Aggressive Exploitation and Impact
Ransomware groups demonstrated a brute-force and fast-moving approach, emphasizing techniques that maximize access and damage in the shortest time. Many of these attacks began with exploiting exposed services or credentials to break in. Unlike APTs, ransomware crews often gained initial access via weakly secured external remote services [T1133] like RDP/VPN or via known vulnerabilities in public-facing applications [T1190]. In fact, multiple high-profile regional ransomware incidents stemmed from unpatched internet-facing systems being exploited (with T1190 scoring among the top initial access techniques). Some groups still used phishing, but overall the trend skewed toward direct intrusion through vulnerabilities or purchased credentials. Once inside, valid accounts [T1078] usage became dominant, attackers would leverage stolen domain admin credentials to rapidly spread across servers. This aligns with the broader ransomware affiliate model where initial access brokers supply credentials to ransomware gangs, enabling quick takeovers.
After gaining a foothold, ransomware operators aggressively perform discovery and credential dumping. They use utilities like Mimikatz for OS Credential Dumping [T1003] to extract admin and domain passwords, facilitating full control over the environment. Many groups also executed built-in commands or scripts [T1059] to map the network, identify critical systems, and prepare their payload deployment. Notably, system and network discovery techniques, such as System Information Discovery [T1082], scored very high, reflecting that ransomware attackers thoroughly enumerate victim environments to locate file shares, backups, and other high-value targets.
When ready to strike, ransomware attacks deploy a suite of impact techniques in quick succession. A hallmark is the encryption of files – Data Encrypted for Impact [T1486] – which was the single most common technique across ransomware cases, as expected. However, supporting techniques are equally important: nearly all observed ransomware incidents included steps to disable or impede defenses before encryption. For example, adversaries would systematically stop services [T1489] on victim machines, often targeting security software, databases, or backup services, to make data accessible for encryption and prevent interference. In Middle Eastern ransomware attacks, service stoppage extended to critical infrastructure like Exchange and SQL services, and even hypervisors; some ransomware strains issue commands to shut down or pause all virtual machines on ESXi hosts prior to encrypting the virtual disks. Similarly, attackers employed Inhibit System Recovery [T1490] by deleting or disabling backups and shadow copies, ensuring that victims cannot easily recover their data. These aggressive actions magnify the damage: by the time ransomware payloads start encrypting, the organization’s protective measures (antivirus, backups, etc.) are already neutralized.
Another notable trend is the abundant use of anti-analysis and evasion techniques in ransomware campaigns. Nearly all active ransomware variants featured some form of virtual machine or sandbox detection [T1497] and anti-debugging tricks to evade security tools. For instance, many payloads check for VMware or VirtualBox artifacts and will terminate or delay execution if found, to avoid running in researcher environments. Ransomware operators also leveraged obfuscation and packing [T1027] to make their binaries harder to detect by antivirus, and in some cases used masquerading (naming their binaries after system processes). But since the endgame of ransomware is loud (encryption and ransom notes), evasion is mainly to reach that stage without being stopped. It’s worth noting that data exfiltration has become a standard part of ransomware operations (the double-extortion tactic). Many groups were observed stealing data; Exfiltration Over C2 Channel [T1041], before encryption, using built-in network channels or external transfer to leak sites. At least 19 ransomware gangs were active in the Middle East in the first half of 2024, most of which practiced data theft to pressure victims. This represents an overlap with APT motivations (data collection), though ransomware actors monetize the data rather than spy.
| Defensive Spotlight – Ransomware TTPs |
|---|
| To defend against these aggressive tactics, organizations should prioritize preventative controls and fast detection. Ensure all internet-facing systems are up to date on patches and enforce multi-factor authentication on remote access (mitigating T1190 and T1133 paths). Deploy robust monitoring for sudden stops of critical services (an EDR can alert if, say, a backup or antivirus service is unexpectedly killed; a red flag for T1489) and for mass deletion of shadow copies (T1490). Network segmentation and admin account hygiene can limit how far ransomware spreads with any stolen credentials (T1078). Most critically, maintain offline backups and tested incident response plans. If an intrusion is detected at the discovery or credential harvesting stage, swift isolation of affected hosts can prevent the transition to the encryption phase. Given the speed of ransomware attacks, having automated containment (such as disabling an account or network access when suspect behavior is detected) can make the difference in thwarting the attackers’ endgame. |
8.3. Top Initial Access Techniques
Table 2. Key Initial Access Techniques Observed in the Middle East (2024).
| Initial Access | ||
| Rank | Technique (MITRE ATT&CK ID) | Observed Examples |
| 1 | T1190 – Exploit Public-Facing Application | Unpatched internet-facing systems (web servers, VPN appliances, etc.) are prime targets. Iranian-linked actors were observed scanning and exploiting vulnerable devices (Citrix Netscaler, F5 BIG-IP, Palo Alto PAN-OS, etc.) via known CVEs to gain entry. |
| 2 | T1078 – Valid Accounts | For example, Rhysida ransomware affiliates rent compromised RDP/VPN accounts from initial-access brokers, and Iranian threat actors have escalated brute-force and credential-theft campaigns in the region. |
| 3 | T1133 – External Remote Services | Attackers frequently target exposed remote-access services. Compromised RDP or VPN logins are a common entry point; accounts are often sold by underground brokers or obtained via credential attacks. |
| 4 | T1566 – Phishing | For example, Lazarus Group’s “DreamJob” campaign used fake job offers to deploy trojanized tools, and regional ransomware operators similarly use benign-looking emails to drop malware. |
9. Recommendations and Mitigation Strategies
1. Patch & Vulnerability Management
- Regularly update software to address vulnerabilities and ensure systems are secure.
- Address known exploits (e.g., Zerologon, Log4j) promptly.
- Continuously scan public-facing systems (RDP, VPN, Veeam backups) and maintain an updated patch schedule.
2. Access Control & Network Segmentation
- Enforce multi-factor authentication (MFA) on all remote admin portals (RDP, VPN).
- Implement strict access controls, ensuring users only have access to the resources they need for their role (principle of least privilege).
- Segment critical servers (domain controllers, ICS/OT) to limit lateral movement and lock down remote management tools (Splashtop, Atera).
3. Email & Phishing Defenses
- Deploy advanced email filtering and frequent staff training, since many strains (e.g., FunkSec, Qilin) use phishing for initial access.
- Monitor for suspicious macros/attachments or links leading to malicious installers.
4. Endpoint Security & Hardening
- Use EDR/XDR to detect attempts at safe-mode encryption (RansomHub), AI-generated Rust binaries (FunkSec), or other advanced evasion.
- Disable unneeded services (e.g., open RDP ports) and track legitimate remote-access deployments.
5. Backups & Incident Response
- Regularly back up critical data and ensure backups are stored offline or in a secure cloud environment
- Keep offline backups, regularly tested for restoration.
- Develop ransomware-specific IR playbooks, accounting for multi-OS coverage (Windows, Linux, ESXi) and double extortion scenarios.
6. Threat Intelligence & Information Sharing
- Follow “name-and-shame” blogs, leak sites, Telegram channels, and other intelligence-sharing platforms to monitor and detect activities relevant to your organization.
- Share IoCs (file hashes, IPs, TTPs) with regional CERTs or industry ISACs for rapid community protection.
7. Zero Trust & Advanced Defenses
- Implement Zero Trust principles to limit attacker movement.
- Monitor for abnormal processes (UAC bypasses, mass file renaming) or suspicious code repeats, especially given AI-driven threats (e.g. FunkSec).
8. Data Encryption
- Encrypt sensitive data both in transit and at rest to protect it from unauthorized access during exfiltration attempts.
9. User Training
- Educate users to identify phishing attempts and avoid clicking on suspicious links or attachments.
10. Future Outlook: What is Ahead?
Looking ahead, 2025 is poised to bring continued escalation and evolution in the Middle Eastern cyber threat landscape. The converging trends of 2024; state-sponsored aggression, rampant ransomware, critical infrastructure risks, and hybrid threat actors, will likely persist and, in some cases, intensify. Cybersecurity stakeholders in the region should prepare for the following thematic developments in the coming year:
- Persistent State Activity and Escalation
Far from abating, nation-state cyber operations targeting the Middle East are expected to continue at a high tempo. State-sponsored APT groups (from Iran and other interested powers) will persist in conducting espionage against governments, defense sectors, and industries to fulfill strategic intelligence needs. If geopolitical tensions remain high or new conflicts emerge, we anticipate more aggressive or destructive cyber tactics could be employed. For instance, Iranian cyber units may expand their focus to include more disruptive attacks on regional adversaries’ infrastructure if provoked, especially critical sectors like energy, finance, or transport that could yield leverage in a confrontation. Other state actors such as China are likely to maintain or increase their quiet cyber-espionage in the Middle East, especially as China deepens economic ties and relations. The ongoing instability in certain states (Yemen, Syria, Iraq) may also invite cyber espionage from multiple sides (regional powers and global powers) vying for influence. In essence, Middle Eastern networks will remain a chessboard for state-linked hackers in 2025. Organizations should expect sustained phishing, credential theft, and malware implant activity from APTs, and they should be vigilant for any signs of more overt sabotage as geopolitical flashpoints flare. Joint intelligence reports by agencies such as NSA and CISA have warned that Iranian actors specifically will keep targeting accounts and devices with known vulnerabilities, a trend we foresee continuing, meaning rigorous patch management and network monitoring will be as critical as ever.
- Ransomware “Professionalization” and Evolution:
The ransomware threat in will evolve further in 2025, likely becoming more sophisticated and potentially more targeted. The region’s notoriety in cybercrime circles rose in 2024 due to several big payouts and successful breaches, which could attract new ransomware groups to try their luck. We expect the major ransomware-as-a-service cartels to continue targeting Middle Eastern victims, but they may refine their tactics. The emergence of ransomware strains tailored to compromise or encrypt OT systems would be a dangerous game-changer. Additionally, multi-stage extortion is likely to increase: beyond encrypting data and threatening leaks, attackers might engage in harassment extortion (contacting customers of the victim or using stolen data to pressure stakeholders), techniques already seen globally and expected to grow. Another expected trend is the continued blurring between financially motivated and state-linked actors. Initial Access Brokers will also proliferate, selling ready-made footholds into Middle East orgs on the dark web, which means even smaller criminal groups can purchase access and deploy ransomware without sophisticated skills. Defenders should brace for creative extortion tactics and ensure incident response plans consider scenarios like critical infrastructure ransomware and triple extortion schemes.
- AI-Driven Threats and Opportunities:
2025 will likely be a year where artificial intelligence (AI) plays a dual role in cybersecurity, as both a tool for attackers and a defensive asset for organizations. Threat actors are already experimenting with generative AI to enhance their attacks, and this is expected to accelerate. According to recent threat intelligence, adversaries worldwide are “weaponising AI-generated deception”, such as highly convincing phishing lures and deepfake content, to trick victims. In the Middle East, we anticipate phishing and social engineering campaigns will become more sophisticated through AI. For example, attackers could use AI to automatically craft phishing emails in flawless Arabic or English, personalized to the target, making detection harder. Voice phishing (vishing) using AI-generated speech (impersonating a CEO’s voice, for instance) rose dramatically in late 2024, CrowdStrike reported a 442% jump in AI-fueled vishing attacks globally between H1 2024 and H2 2024. AI can also help attackers with vulnerability discovery and exploit development. Notably, Iran-nexus actors have been exploring generative AI to find new security gaps and even to patch their own systems faster, aligning with Irann’s AI initiatives. This suggests a potential AI arms race: attackers use AI to find cracks and automate attacks, while defenders deploy AI for anomaly detection and rapid response. Indeed, governments in the region are recognizing AI’s defensive potential. By 2027, as much as 95% of countries are predicted to experience major cyberattacks leveraging generative AI, highlighting that Middle Eastern nations must prepare now. We expect organizations in 2025 to increasingly integrate AI in their security operations (for threat hunting, user behavior analytics, etc.) to counter fast-moving AI-powered threats.
- Hybrid Threats and Dual-Purpose Operations Continue:
The blending of espionage and cybercrime that we saw in 2024 will likely continue into 2025. Dual-purpose operations, where the same actors engage in both state-aligned spying and personal/corporate financially motivated crime, will persist and possibly expand. Economic pressures or sanctions on certain nations might drive their state hackers to carry out more cryptocurrency thefts or ransomware attacks to generate revenue (North Korea’s model is instructive here, though outside the region, but Iran or its proxies could follow suit more boldly if needed). Similarly, hacktivist groups could morph: those motivated by regional causes might adopt ransomware to support fundraising, or conversely, criminal groups might cloak their attacks in political rhetoric to evade crackdowns. The continued turmoil in regions like the Levant could produce new groups that have a patriotic or sectarian facade but essentially operate as cyber mercenaries. This complicates attribution and response, a trend likely to continue. On the defensive side, we expect greater collaboration among nations and industries to counter these complex threats. Intelligence-sharing alliances may be strengthened: for example, GCC countries and allies might form joint cyber task forces to quickly disseminate indicators of compromise from state-sponsored attacks or to coordinate takedowns of criminal infrastructure. The recognition that threats are interconnected is growing; as one forecast noted, hacker groups could form international alliances to carry out large-scale attacks, sharing botnets and exploits to be more destructive. We should assume threat actors are already doing this, so defenders must do the same, coordinate and pool resources on a regional level. 2025 might see the establishment of more formal Middle East cyber cooperation frameworks, possibly under the auspices of organizations like the GCC or Arab League, focusing on joint exercises and training (efforts which have begun in 2024).
11. Conclusion
The events of 2024 confirmed that the Middle East remains a focal point for global cyber operations, with advanced persistent threats, ransomware groups, and ideologically motivated actors targeting the region with increasing sophistication and scale. Cyber threats are no longer episodic; they are sustained, evolving, and strategically aligned with the geopolitical dynamics of the region.
State-sponsored actors led aggressive espionage campaigns against government, energy, defense, and technology sectors. Ransomware groups demonstrated growing technical agility and broader sectoral reach, capitalizing on double extortion and affiliate-driven operations. Meanwhile, dark web markets and hacktivist networks amplified both commercial and geopolitical risks, especially in high-profile economies such as the UAE and Saudi Arabia.
This convergence of state interests, financial motives, and ideological drivers has created a complex and persistent threat environment. Organizations must now view cybersecurity as a strategic function, one that demands executive oversight, cross-border cooperation, and continuous investment.
Moving forward, the emphasis should be on building regional cyber resilience, integrating threat intelligence into national security strategy, and enhancing visibility across critical sectors. While the threat landscape will continue to evolve, a coordinated, intelligence-led approach will be key to mitigating risk, protecting national interests, and securing the region’s digital future.
Appendix B: Top 20 Malware Identified in the Region
| Rank | Malware Name | Family Type | Detections | Primary Objective |
| 1 | Lumma | Stealer | 14,657 | Steals sensitive credentials, banking data, and personal information, causing financial and privacy damage. |
| 2 | AsyncRAT | RAT | 9,016 | Grants attackers full control of infected systems, facilitating espionage, data theft, and further malware installation. |
| 3 | Agent Tesla | Trojan | 8,548 | Steals sensitive information (credentials, emails) through keylogging, potentially leading to financial loss or identity theft. |
| 4 | XWorm | RAT | 8,198 | Provides remote access to systems, enabling attackers to manipulate data, install malware, and steal information. |
| 5 | Remcos | Trojan | 8,025 | Offers remote control and data theft capabilities, often used for espionage or executing malicious tasks. |
| 6 | Stealc | Stealer | 7,980 | Targets sensitive user data, including login credentials, for financial fraud or identity theft. |
| 7 | RedLine | Stealer | 7,142 | Specializes in stealing banking details, cryptocurrency wallets, and other sensitive personal data. |
| 8 | Amadey | Infostealer | 6,264 | Steals sensitive data (user credentials, system info), potentially enabling further exploitation or fraud. |
| 9 | Emotet | Trojan | 4,483 | Often used in large-scale attacks, it spreads malware, steals data, and is involved in ransomware delivery. |
| 10 | DCRat | RAT | 3,593 | Provides remote access, enabling data theft, surveillance, and system manipulation by attackers. |
| 11 | njRAT | Trojan | 3,502 | Enables remote access and can be used for spying, stealing data, and deploying further malicious software. |
| 12 | MetaStealer | Stealer | 2,768 | Steals sensitive information, including login credentials, to facilitate fraud or unauthorized access. |
| 13 | GuLoader | Downloader | 2,621 | Downloads other malicious software, often a precursor to more dangerous infections like ransomware or trojans. |
| 14 | Formbook | Spyware | 2,620 | Tracks user activity, collects personal data (credentials, browsing habits), and can lead to identity theft. |
| 15 | Cobalt Strike | Penetration Software | 2,531 | Used for advanced cyberattacks, including data exfiltration, system exploitation, and lateral movement within networks. |
| 16 | Quasar RAT | Trojan | 2,526 | Facilitates remote access for cybercriminals to control systems, steal data, or install further malicious software. |
| 17 | Balada Injector | Backdoor | 2,403 | Installs malware and opens backdoors for further malicious activities, leading to potential data loss or system compromise. |
| 18 | Blank Grabber | Stealer | 2,025 | Primarily steals images, videos, and sensitive documents, often used in blackmail or extortion campaigns. |
| 19 | Vidar | Trojan | 2,006 | Focuses on stealing financial data, login credentials, and personal information, which can lead to fraud and identity theft. |
| 20 | CryptBot | Infostealer | 1,626 | Steals sensitive data, with a focus on cryptocurrency wallets and banking information, which can lead to financial theft. |
