logo

12,000+ Systems Scanned Ahead Of Middle East Critical Infrastructure Attacks

ID: b78173e4-5076-599f-a63c-c7aaf0552ac5

STIX ID: report--b78173e4-5076-599f-a63c-c7aaf0552ac5

Feed Name: Cyber Press

Threat Score
90/100

Date Published: 2026-04-15

Date Updated: 2026-04-15

Author: Varshini

...
...

Oasis Security uncovered a coordinated reconnaissance-to-exfiltration campaign active since February that scanned >12,000 internet-exposed systems, exploited five newly disclosed RCE vulnerabilities across web, mail, workflow automation, RMM, and AI platforms, and used a modular multi-protocol C2 (linked to ArenaC2/MuddyWater tradecraft) to harvest credentials and exfiltrate ~200 files (passport and payroll records) from an Egyptian aviation enterprise, with primary targeting of aviation, energy/infrastructure, and government entities in the Middle East.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.