A hack-for-hire group has been identified targeting journalists, activists, and government officials in the Middle East and North Africa. The campaign utilized phishing attacks to compromise iCloud backups and Signal accounts, alongside Android spyware capable of full device control, TechCrunch reports.Security researchers from Access Now and Lookout have detailed a sophisticated espionage campaign that began in 2023 and continued through 2025. The attacks targeted individuals in Egypt, Lebanon, Bahrain, and the United Arab Emirates, with potential reach into Saudi Arabia, the United Kingdom, and the United States. The group, linked to BITTER APT and possibly an offshoot of the Indian firm Appin, employed tactics such as phishing for Apple ID credentials to access iCloud backups and deploying Android spyware disguised as legitimate messaging apps like Signal and WhatsApp.For iPhone users, the aim was to gain access to iCloud backups, while Android users were targeted with ProSpy spyware. These methods are seen as a cheaper alternative to commercial spyware, offering plausible deniability to the clients.Source: TechCrunch
Data Security, Privacy, Threat Intelligence
Hack-for-hire group targets MENA journalists and officials

Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds



