PULSE NAME
Hack-for-Hire Campaign Targets Journalists Across MENA Region
WHITE Bitter AlienVault 2026-04-09 Modified: 2026-04-09
16
IOCs
MEDIUM VOLUME
A hack-for-hire operation with suspected links to the Bitter threat actor targeted journalists, activists, and government officials across the Middle East and North Africa between 2023 and 2025. The campaign employed sophisticated spear-phishing attacks via LinkedIn, Apple Messages, WhatsApp, and email to compromise Apple and Google accounts. Victims included Egyptian journalists Mostafa Al-A'sar and Ahmed Eltantawy, along with a Lebanese journalist whose Apple Account was fully compromised. Attackers used OAuth consent phishing and fake login pages to harvest credentials and 2FA codes. Infrastructure overlaps with Android spyware campaigns distributing ProSpy, ToSpy, and Dracarys malware. The operation represents an unusual expansion of Bitter's targeting scope into civil society, suggesting either hack-for-hire services or direct nation-state involvement in regional surveillance efforts focused on monitoring communications and harvesting personal data.
MITRE ATT&CK & Malware Families
MALWARE FAMILIES
ProSpy ToSpy Dracarys
Indicators of Compromise (16)
All CVE domain hostname
TYPEINDICATORDESCRIPTIONCREATED
CVE CVE-2025-55182 2026-04-09
CVE CVE-2026-34040 2026-04-09
CVE CVE-2026-35616 2026-04-09
CVE CVE-2026-5281 2026-04-09
domain com-ae.net 2026-04-09
domain en-account.info 2026-04-09
domain youtubepremiumapp.com 2026-04-09
hostname android.com-ae.net 2026-04-09
hostname encryption-plug-in-signal.com-ae.net 2026-04-09
hostname facetime.com-en.io 2026-04-09
hostname id-apple.com-en.io 2026-04-09
hostname join-facetime.com-ae.net 2026-04-09
hostname secure-signal.com-en.io 2026-04-09
hostname signin-apple.com-en-uk.co 2026-04-09
hostname telegram.com-en.io 2026-04-09
hostname verify-apple.com-ae.net 2026-04-09