< Back to all clusters
[TECHNOLOGY] · Egypt, Lebanon, Bahrain, United Arab Emirates, Saudi Arabia · 4 sources

Hack‑for‑Hire groups and ransomware gang adopt new infiltration tactics

Investigations have revealed a rise in commercially operated cyber‑espionage services that sell hacking capabilities to the highest bidder. These "hack‑for‑hire" outfits have targeted journalists, activists and government officials across the Middle East and North Africa – including Egypt, Lebanon, Bahrain, the United Arab Emirates and Saudi Arabia – as well as contacts in the United Kingdom and the United States. Attacks commonly involve sophisticated phishing to steal Apple‑ID credentials and download entire iCloud backups, or the deployment of Android malware such as ProSpy hidden inside popular messaging apps (Signal, WhatsApp, Zoom, ToTok, Botim) to gain full device control.

Separately, Google’s Threat Intelligence Group and the FBI have identified the criminal organization Silent Ransom Group, which has escalated ransomware operations by sending impostors posing as on‑site technical‑support staff. These actors physically enter victim offices, connect USB devices or install remote‑access tools to exfiltrate contracts, Social Security numbers and financial records. Rather than encrypting data, the gang threatens public disclosure unless a ransom is paid. Both reports warn that the outsourcing of cyber‑espionage tools and the use of covert physical infiltration substantially lower the cost and risk for perpetrators, making targeted surveillance and data theft more accessible and harder to attribute.