INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
UAE Faces Rising Complex Cyberattacks from Seven Seas Group
| 2026-10-07 16:42 CRITICAL LOW RANSOMWARE & EXTORTION CYBERATTACK (GENERAL)
Executive Summary
AI-generated
A series of ransom hacking incidents targeting organizations in the UAE occurred between October 5th and 7th, with Seven Seas Group being breached on October 5th. The SPIRALS hacking group claims to have breached both Seven Seas Group and the UAE Pro League on October 7th. According to samples shared by the threat actor, allegedly exfiltrated data from Seven Seas Group includes internal host information, employee-related documents, and SharePoint data. Organizations in the UAE are experiencing a surge in cyberattacks, with nearly 2,700 attacks per week over the past half-year, compared to about 2,300 global averages, according to Check Point Software Technologies. The most popular attack type is exploits for information-disclosure vulnerabilities, impacting 62% of affected organizations, and ransomware, botnets, and information-stealing malware are also prevalent in the region.
Technical Mitigations AI-generated
• Network Intrusion Prevention (ATT&CK mitigation for Phishing): Network intrusion prevention systems and systems designed to scan and remove malicious email attachments or links can be used to block activity.
• Restrict Web-Based Content (ATT&CK mitigation for Phishing): Determine if certain websites or attachment types (ex: .scr, .exe, .pif, .cpl, etc.) that can be used for phishing are necessary for business operations and consider bloc
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
INC RansomINC Ransom
Target & Sectors
GCC
GCC
NORTH_AMERICA
NORTH_AMERICA
telecommunicationstelecommunications
mediamedia
governmentgovernment
Incident Timeline
2026/10/07
The UAE - Seven Seas Group SPIRALS hacking group has escalated cyberattacks by shifting from simple, visible attacks like DDoS and website defacements to complex, targeted cyberattacks.
Click on any entity below to view its context and source!
organisation
UAE - UAE Pro League
UAE - UAE Pro League INC Ransom hacking gr....
threat_actor
INC Ransom
UAE - UAE Pro League INC Ransom hacking gr....
UAE - UAE Pro League
INC Ransom hacking group claims to have breached the UAE Pro League.
organisation
the UAE Pro League
UAE - UAE Pro League
INC Ransom hacking group claims to have breached the UAE Pro League.
organisation
SPIRALS
UAE - Seven Seas Group
SPIRALS hacking group claims to have breached Seven Seas Group.
organisation
Seven Seas Group
UAE - Seven Seas Group
SPIRALS hacking group claims to have breached Seven Seas Group.
organisation
Check Point
Organizations in the UAE and Saudi Arabia experienced nearly 2,700 attacks per week in the past half-year, compared with about 2,300 attacks per week for a typical organization across the globe, according to data provided by cybersecurity firm Check Point Software Technologies.
organisation
SharePoint
According to samples shared by the threat actor, the allegedly exfiltrated data includes internal host information, employee-related documents, and SharePoint data.
organisation
Positive Technologies
Meanwhile, Iran's media organizations and telecom infrastructure are typically popular targets of attack, says Darya Lavrova, lead analyst at Positive Technologies.
organisation
Different Nations
Different Nations, Different Mix of Attackers
While the conflict between US, Israel, and Iran
continues to drive many cyberattacks
, the proportion of DDoS attacks has "noticeably declined," Positive Technologies
stated in its report
.
organisation
DDoS
Different Nations, Different Mix of Attackers
While the conflict between US, Israel, and Iran
continues to drive many cyberattacks
, the proportion of DDoS attacks has "noticeably declined," Positive Technologies
stated in its report
.
organisation
Dream Group
"
Gross domestic product alone is not enough to explain the targeting of certain countries, says Shalev Hulio, CEO and co-founder of Dream Group, a Tel Aviv-based sovereign AI firm.
organisation
IoT
"
Both the public and private sectors should focus on reducing their attack surface areas and moving away from legacy systems and Internet of Things (IoT) devices, Lavrova says.
Intelligence Sources
Dark Reading
2026-09-23
Bluesky Hackmanac
2026-10-05
Cyber Alert !! UAE - Seven Seas Group SPIRALS hacking gro...
Bluesky Hackmanac
Bluesky Hackmanac
2026-10-07
Cyber Alert !! UAE - UAE Pro League INC Ransom hacking gr...
Bluesky Hackmanac
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-08T06:20
Comprehensive Tactical Telemetry
Highly Correlated Entities
11x
organisation
Identified Entity
UAE - UAE Pro League
entity
8x
attribution
Attributing Entity
Telegram
authority
8x
general metric
%
67
%
6x
target region
Target Country
United Arab Emirates
country
4x
tactic
Cyber Operation Type
Ddos
tactic
2x
industry
Targeted Sector
Media
sector
2x
tactic
MITRE ATT&CK Technique
T1592.002 - Software
technique
2x
general metric
Attacks
2,700
attacks
Contextual Telemetry
Context Block
3 METRICS
threat actor
APT Group
INC Ransom
actor
target region
Target Region
MIDDLE_EAST
region
timeline
Temporal Reference
2028
date
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.