Middle East Hack-for-Hire Operation Traced to South Asian Cyber Espionage Group
ID: a88cebd7-95b9-59ad-9f43-a2076a4ad636
STIX ID: report--a88cebd7-95b9-59ad-9f43-a2076a4ad636
Feed Name: Infosecurity Magazine (News)
Access Now and partner NGOs identified a spear-phishing campaign (2023–2025) targeting journalists and civil-society figures in the Middle East that delivered ProSpy Android spyware and used fake iCloud/E2EE phishing pages and staged APK hosting. Lookout and other researchers found malware samples, live staging servers, credential exfiltration (including captured usernames, passwords, and 2FA codes), and shared infrastructure/techniques linking the operation to the Bitter APT or a related South Asian hack-for-hire group; some attacks succeeded in taking over an Apple account while others were stopped by target vigilance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
