INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
South Asian Cyber Espionage Group Linked to Middle East Hack
| 2026-04-09 10:45 MEDIUM LOW STATE-SPONSORED & ESPIONAGE
Executive Summary
AI-generated
In April 2026, a spear-phishing campaign targeting civil society figures in Middle Eastern countries, including three high-profile journalists in Egypt and Lebanon, was detected by digital rights organization Access Now. The attackers, likely affiliated with the known South Asian cyber espionage group Bitter (also known as T-APT-17 or APT-C-08), had been active since at least 2013, targeting government, energy, and engineering organizations in Pakistan, China, Bangladesh, Saudi Arabia, and the United Arab Emirates. Three high-profile journalists in Egypt and Lebanon were targeted by spear-phishing campaigns carried out from 2023 to 2024, with attackers impersonating legitimate people and services using fake accounts and profiles to deliver Android spyware strains posing as messaging apps. The campaign was ultimately unsuccessful in compromising the targets' Apple and Google accounts, but highlights the ongoing threat of cyber espionage operations targeting civil society figures in the region.
Technical Mitigations AI-generated
• Network Intrusion Prevention (ATT&CK mitigation for Phishing): Network intrusion prevention systems and systems designed to scan and remove malicious email attachments or links can be used to block activity.
• Restrict Web-Based Content (ATT&CK mitigation for Phishing): Determine if certain websites or attachment types (ex: .scr, .exe, .pif, .cpl, etc.) that can be used for phishing are necessary for business operations and consider bloc
• User Training (ATT&CK mitigation for Impersonation): Train users to be aware of impersonation tricks and how to counter them, for example confirming incoming requests through an independent platform like a phone call or in-
• Threat Intelligence Program (ATT&CK mitigation for Impersonation): Threat intelligence helps defenders and users be aware of and defend against common lures and active campaigns that have been used for impersonation.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Operation TracedOperation Traced
Target & Sectors
GCC
GCC
SOUTH_ASIA
SOUTH_ASIA
AFRICA
AFRICA
NORTH_AMERICA
NORTH_AMERICA
mediamedia
Incident Timeline
August 2024
Threat actors affiliated with a South Asian cyber espionage group used phishing and malware tactics to target Apple users via fake iCloud pages, Android users through a ToTok app update hosted on deceptive domains, in an operation that compromised civil society figures.
Click on any entity below to view its context and source!
infrastructure
Android
Apple users are lured with fake iCloud or E2EE app phishing pages, while Android users are directed to download ProSpy malware, such as through a fake ToTok app update hosted on deceptive domains like totok-pro[.]ai-ae[.]io.
While ProSpy and Dracarys were developed years apart, the structural and behavioral parallels, combined with Bitter’s history of targeting Android devices and using PHP-based C2 infrastructure, strengthened the attribution.
May 2025
Researchers captured a complete credential exfiltration, including the username, password and 2FA codes, from an Android device targeted in May 2025.
Click on any entity below to view its context and source!
infrastructure
Android
Analysis of ProSpy Spyware
Lookout researchers also shared details about the ProSpy Android malware used in the campaigns, of which they acquired 11 samples, the earliest found in August 2024.
August 2025
Threat actors using Bitter (T-APT-17 and APT-C-08), a South Asian cyber espionage group, launched spear-phishing campaigns against prominent critics of the Egyptian government in August 2025.
Click on any entity below to view its context and source!
infrastructure
Android
Upon investigating the campaigns, Access Now discovered Android malware tied to the phishing infrastructure.
Researchers from ESET shared
a report
in October 2025 about two
Android spyware
strains posing as messaging apps and targeted users in the United Arab Emirates (UAE).
March 2026
A South Asian cyber espionage group used Android spyware to target a Lebanese journalist's Apple account in March 2026.
Click on any entity below to view its context and source!
infrastructure
Android
This Android spyware could have allowed the attackers to access and extract victims’ files, personal contacts, text messages and geolocation, enable device microphones and cameras as well as instal further malicious apps on the target’s device.
Tactical Metrics
Metrics
infrastructure
Android
Affected Product
Click for context!
Researchers from ESET shared
a report
in October 2025 about two
Android spyware
strains posing as messaging apps and targeted users in the United Arab Emirates (UAE).
Upon investigating the campaigns, Access Now discovered Android malware tied to the phishing infrastructure.
Apple users are lured with fake iCloud or E2EE app phishing pages, while Android users are directed to download ProSpy malware, such as through a fake ToTok app update hosted on deceptive domains like totok-pro[.]ai-ae[.]io.
This Android spyware could have allowed the attackers to access and extract victims’ files, personal contacts, text messages and geolocation, enable device microphones and cameras as well as instal further malicious apps on the target’s device.
Analysis of ProSpy Spyware
Lookout researchers also shared details about the ProSpy Android malware used in the campaigns, of which they acquired 11 samples, the earliest found in August 2024.
While ProSpy and Dracarys were developed years apart, the structural and behavioral parallels, combined with Bitter’s history of targeting Android devices and using PHP-based C2 infrastructure, strengthened the attribution.
Intelligence Sources
Infosecurity-Magazine
2026-04-09
Middle East Hack-for-Hire Operation Traced to South Asian Cyber Espionage Group
Infosecurity-Magazine
Infosecurity-Magazine
2026-04-09
Middle East Hack-for-Hire Operation Traced to South Asian Cyber Espionage Group
Infosecurity-Magazine
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-05T11:47
Comprehensive Tactical Telemetry
Highly Correlated Entities
27x
organisation
Identified Entity
ESET
entity
12x
timeline
Temporal Reference
October 2025
date
11x
target region
Target Country
Pakistan
country
5x
tactic
Cyber Operation Type
Phishing
tactic
3x
industry
Targeted Sector
Government
sector
3x
target region
Target Region
MIDDLE_EAST
region
2x
source region
Origin Country
Egypt
country
2x
source region
Origin Region
AFRICA
region
Contextual Telemetry
Context Block
5 METRICS
infrastructure
Affected Product
Android
software
attribution
Attributing Entity
Access Now and SMEX
authority
campaign
Campaign
Operation Traced
operation
tactic
MITRE ATT&CK Technique
T1566 - Phishing
technique
general metric
Samples
11
samples
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.