INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

South Asian Cyber Espionage Group Linked to Middle East Hack

| 2026-04-09 10:45 MEDIUM LOW STATE-SPONSORED & ESPIONAGE
Executive Summary
AI-generated
In April 2026, a spear-phishing campaign targeting civil society figures in Middle Eastern countries, including three high-profile journalists in Egypt and Lebanon, was detected by digital rights organization Access Now. The attackers, likely affiliated with the known South Asian cyber espionage group Bitter (also known as T-APT-17 or APT-C-08), had been active since at least 2013, targeting government, energy, and engineering organizations in Pakistan, China, Bangladesh, Saudi Arabia, and the United Arab Emirates. Three high-profile journalists in Egypt and Lebanon were targeted by spear-phishing campaigns carried out from 2023 to 2024, with attackers impersonating legitimate people and services using fake accounts and profiles to deliver Android spyware strains posing as messaging apps. The campaign was ultimately unsuccessful in compromising the targets' Apple and Google accounts, but highlights the ongoing threat of cyber espionage operations targeting civil society figures in the region.
Technical Mitigations AI-generated
• Network Intrusion Prevention (ATT&CK mitigation for Phishing): Network intrusion prevention systems and systems designed to scan and remove malicious email attachments or links can be used to block activity. • Restrict Web-Based Content (ATT&CK mitigation for Phishing): Determine if certain websites or attachment types (ex: .scr, .exe, .pif, .cpl, etc.) that can be used for phishing are necessary for business operations and consider bloc • User Training (ATT&CK mitigation for Impersonation): Train users to be aware of impersonation tricks and how to counter them, for example confirming incoming requests through an independent platform like a phone call or in- • Threat Intelligence Program (ATT&CK mitigation for Impersonation): Threat intelligence helps defenders and users be aware of and defend against common lures and active campaigns that have been used for impersonation.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Operation TracedOperation Traced
Target & Sectors
GCC GCC SOUTH_ASIA SOUTH_ASIA AFRICA AFRICA NORTH_AMERICA NORTH_AMERICA mediamedia
Incident Timeline
‎August 2024
Threat actors affiliated with a South Asian cyber espionage group used phishing and malware tactics to target Apple users via fake iCloud pages, Android users through a ToTok app update hosted on deceptive domains, in an operation that compromised civil society figures.
infrastructure Android
‎May 2025
Researchers captured a complete credential exfiltration, including the username, password and 2FA codes, from an Android device targeted in May 2025.
infrastructure Android
‎August 2025
Threat actors using Bitter (T-APT-17 and APT-C-08), a South Asian cyber espionage group, launched spear-phishing campaigns against prominent critics of the Egyptian government in August 2025.
infrastructure Android
‎March 2026
A South Asian cyber espionage group used Android spyware to target a Lebanese journalist's Apple account in March 2026.
infrastructure Android
Tactical Metrics
Metrics
infrastructure
‎Android
Affected Product
Intelligence Sources
Infosecurity-Magazine 2026-04-09
Infosecurity-Magazine 2026-04-09