Middle East faced wave of cybersecurity threats since start of pandemic

1 / 2
The region has always been a hotbed for such attacks due to geopolitical factors. (File/Shutterstock)
2 / 2
Fatemah Alharbi, Cybersecurity researcher and consultant. (Supplied)
Short Url
Updated 24 October 2021
Follow

Middle East faced wave of cybersecurity threats since start of pandemic

  • The researchers issued 49 threat intelligence reports due to investigations associated with cyberattacks on the UAE
  • In the VMWare report, a survey of 252 Saudis showed 84 percent of them said that cyberattacks had increased due to working from home

RIYADH: Since the start of the pandemic, a wave of advanced threat campaigns targeting the Middle East have been discovered by Kaspersky, a global cybersecurity firm.

An APT is an attack campaign in which intruders establish an illicit, long-term presence on a network to mine highly sensitive data. The targets, which are carefully chosen and researched, typically include large enterprises or government networks.

The region has always been a hotbed for such attacks due to geopolitical factors.

Kaspersky researchers, keeping a close eye on the region for APTs, worked on 68 investigative reports related to 29 cyber gangs actively targeting the Middle East since the start of the pandemic.

The researchers issued 49 threat intelligence reports due to investigations associated with cyberattacks on the UAE, which endured the highest number of reports for all Middle Eastern countries.

The second highest was Saudi Arabia with 39 reports, followed by Egypt with 30. Kuwait and Oman had 21 each, while Jordan had 20. Iraq, Qatar and Bahrain had fewer than 20 reports each.

APT attacks primarily targeted government agencies, followed by diplomatic institutions, the education sector, and telecommunication institutions. Other targeted sectors included finance, IT, healthcare, legal, military, and defense.

Some of the APT groups investigated were Oilrig, WIRTE, Lazarus, and Sofacy.

Fatemah Alharbi, a cybersecurity expert and assistant professor at Taibah University, told Arab News: “PowerShell-based malware are utilized by advanced cyberattacks targeting critical infrastructures in Saudi Arabia.”

She said these cybercriminals were sending phishing emails that contained malicious Microsoft Office files impersonating legitimate entities.

To pass the firewall and the email protection techniques, she explained, these rigged files were protected by passwords and compressed as zip files.

“This approach facilitates the mission of these cybercriminals to take full control of the file system and to compromise every single file there. This means they would be able to control the operating system, applications, and data. Assuming the attack is detected, an in-depth analysis and investigation on the file system is highly recommended as a quick response to recover the system and stop the attack.”

Referring to a report by Bitdefender, a cybersecurity technology company, Alharbi said: “Researchers shed light on a well-known APT cyber espionage campaign that targets mainly critical infrastructures in Saudi Arabia.This threat group is called Chafer APT (also known as APT39 or Remix Kitten). The report shows that these cybercriminals rely on social engineering to compromise victims in Saudi Arabia.

“Technically, the attack tricked victims to run a remote administration tool located in the downloads folder, similar to the RAT components used against Turkey and Kuwait back in 2014 and 2018, respectively.”

Despite these threats, Alharbi said the Kingdom’s cybersecurity resources had proven their ability to face such dangers.

“Saudi Arabia is ranked No.1 in the MENA region and Asia and No.2 globally according to the Global Cybersecurity Index issued by the UN’s specialized agency in information and communications technology, the International Telecommunication Union in 2021.”

This indexing evaluates countries periodically based on five main axes: Legal, technical, regulatory, capacity-building, and cooperation. The Kingdom scored advanced points in all of these axes, she said.

Amin Hasbini, head of the global research and analysis team for the Middle East, Turkey, and Africa at Kaspersky, said: “Our cybersecurity experts have always been at the forefront of detecting and reporting the latest APT threats. Our reports are the product of their visibility into the cybersecurity landscape and promptly identify what poses a threat.

“We use these insights to, of course, alert the concerned organizations on time and provide them with the protection as well as intelligence needed against both known and unknown threats. As companies move towards digitization, especially due to the pandemic, it is more important now than ever before to know about the threats that are constantly evolving.”

According to a recent report from Kaspersky and VMWare, working remotely during the pandemic made Saudi employees vulnerable to cyberattacks.

In the VMWare report, a survey of 252 Saudis showed 84 percent of them said that cyberattacks had increased due to working from home.

Alharbi talked about methods to protect users from social engineering threats. “Recently, we see a rise in the number of cyberattacks that are based on social engineering. According to a recent report by PurpleSec, 98 percent of cyberattacks rely on social engineering. Cyber criminals prefer to use social engineering techniques that can expose a victim’s natural inclination to trust easily compared to implementing malwares or any other tools to hack systems.

“For that, organizations must strengthen and diversify their cybersecurity awareness tactics, such as publishing cybersecurity awareness content, in-class training, videos, simulations and tests,” she said.


Hamas military arm releases new video of Israeli hostage in Gaza

Updated 27 min 43 sec ago
Follow

Hamas military arm releases new video of Israeli hostage in Gaza

  • The family of hostage soldier Edan Alexander, 20, declined to comment but permitted the 3-1/2 minute video to be published
  • The video shows a pale-looking Alexander sitting in a dark space against a wall

JERUSALEM: Palestinian militant group Hamas published a video of an Israeli-American hostage on Saturday, in which he pleads for US President-elect Donald Trump to secure his release from captivity.
The family of hostage soldier Edan Alexander, 20, declined to comment but permitted the 3-1/2 minute video to be published. Alexander was abducted to Gaza during the Oct. 7, 2023 attack by Hamas on southern Israel.
The video shows a pale-looking Alexander sitting in a dark space against a wall, identifying himself, addressing his family, Israeli Prime Minister Benjamin Netanyahu and Trump. It is unclear whether his statement was scripted by his captors.
Netanyahu said in a statement that the video was cruel psychological warfare and that he had told Alexander’s family in a phone call that Israel was working tirelessly to bring the hostages home.
Around half of the 101 foreign and Israeli hostages still held incommunicado in Gaza are believed to still be alive.
Hamas leaders were expected to arrive in Cairo on Saturday for ceasefire talks with Egyptian officials to explore ways to reach a deal that could secure the release of hostages in return for Palestinian prisoners.
The fresh bid comes after Washington said this week it was reviving efforts toward that goal.
The Hostages Families Forum urged the administrations of both outgoing US President Joe Biden and Trump — who takes office in January — to step up efforts in order to secure a hostage release.
“The hostages’ lives hang by a thread,” it said.


World Central Kitchen says pausing Gaza operations after Israeli strike

Updated 30 November 2024
Follow

World Central Kitchen says pausing Gaza operations after Israeli strike

  • WCK in a statement said it “had no knowledge that any individual in the vehicle had alleged ties to the October 7 Hamas attack“
  • “All three men worked for WCK and they were hit while driving in a WCK jeep in Khan Yunis,” Bassal said

GAZA: US charity World Central Kitchen said Saturday it was “pausing operations in Gaza at this time” after an Israeli air strike hit a vehicle carrying its workers.
The Israeli military confirmed that a Palestinian employee of WCK was killed in a strike, accusing the worker of being a “terrorist” who “infiltrated Israel and took part in the murderous October 7 massacre” last year.
WCK in a statement said it “had no knowledge that any individual in the vehicle had alleged ties to the October 7 Hamas attack,” and did not confirm any deaths.
Earlier Saturday, Gaza civil defense agency spokesman Mahmud Bassal told AFP that five people were killed, including “three employees of World Central Kitchen,” in the strike in the main southern city of Khan Yunis.


“All three men worked for WCK and they were hit while driving in a WCK jeep in Khan Yunis,” Bassal said, adding that the vehicle had been “marked with its logo clearly visible.”
WCK confirmed a strike had hit its workers, but added: “At this time, we are working with incomplete information and are urgently seeking more details.”
The Israeli army statement said representatives from the unit responsible for overseeing humanitarian needs in Gaza had “demanded senior officials from the international community and the WCK administration to clarify the issue and order an urgent examination regarding the hiring of workers who took part in the October 7 massacre.”
It also said its strike in Khan Yunis had hit “a civilian unmarked vehicle and its movement on the route was not coordinated for transporting of aid.”
In April, an Israeli strike killed seven WCK staff — an Australian, three Britons, a North American, a Palestinian and a Pole.
Israel said it had been targeting a “Hamas gunman” in that strike, but the military admitted a series of “grave mistakes” and violations of its own rules of engagement.
The UN said last week that 333 aid workers had been killed since the start of the war in October of last year, 243 of them employees of the UN agency for Palestinian refugees, UNRWA.
Palestinian militants’ October 7, 2023 attack on southern Israel resulted in the deaths of 1,207 people, most of them civilians, according to an AFP tally of Israeli official figures.
Israel’s retaliatory military offensive has killed 44,382 people in Gaza, according to figures from the territory’s health ministry which the United Nations considers reliable.


Israel hits Hezbollah targets in Lebanon days into fragile truce

Updated 19 min 42 sec ago
Follow

Israel hits Hezbollah targets in Lebanon days into fragile truce

  • The army said it had also struck “military infrastructure” on the Syria-Lebanon border, where it accused Hezbollah of smuggling weapons in violation of the truce
  • Lebanon’s state-run National News Agency (NNA) reported “continued violations of the ceasefire” by Israel

JERUSALEM: The Israeli military carried out air strikes in Lebanon Saturday against Hezbollah activities that it said “posed a threat,” days into a fragile ceasefire between it and the Iran-backed group.
The army said it had also struck “military infrastructure” on the Syria-Lebanon border, where it accused Hezbollah of smuggling weapons in violation of the truce.
In a speech this week announcing his government was ready to accept a ceasefire after more than a year of hostilities with Hezbollah, Prime Minister Benjamin Netanyahu had warned that Israel would maintain “full military freedom of action” in the event of any breach.
In a statement on Saturday, the military listed four separate strikes in Lebanon on facilities, weapons and vehicles belonging to Hezbollah, saying it had acted “against activities in Lebanon that posed a threat to the State of Israel, violating the ceasefire understandings.”
Lebanon’s health ministry said that an Israeli “strike on a car in Majdal Zoun wounded three people including a seven-year-old child.”
Lebanon’s state-run National News Agency (NNA) reported “continued violations of the ceasefire” by Israel, including an incident in which an Israeli tank “crushed a number of cars and surrounded some families” who were later evacuated by the International Committee of the Red Cross.
Separately, Israel’s military said it had launched a “strike on military infrastructure sites adjacent to border crossings between Syria and Lebanon that were actively used by Hezbollah to smuggle weapons,” adding that the alleged smuggling took place after the ceasefire took effect.
The ceasefire deal, which was intended to end more than a year of cross-border exchanges of fire and two months of all-out war, went into effect early on Wednesday.
As part of the terms of the agreement, the Lebanese army and UN peacekeepers will deploy in southern Lebanon as the Israeli army withdraws over a period of 60 days.
Hezbollah is also meant to withdraw its forces north of the Litani river, approximately 30 kilometers (20 miles) from the border, and dismantle its military infrastructure in southern Lebanon.
On Friday, the group’s chief Naim Qassem vowed to cooperate with the Lebanese army “to implement the commitments of the agreement.”
NNA reported that army chief Joseph Aoun met US Major General Jasper Jeffers to discuss “the general situation and coordination mechanisms between concerned parties in the south.”
The US military’s Central Command said Jeffers arrived in Beirut this week “to serve as co-chair for the implementation and monitoring mechanism of the cessation of hostilities.”
According to Lebanon’s health ministry, at least 3,961 people have been killed in the country since October 2023 as a result of the Israel-Hezbollah conflict, most of them in recent weeks.
On the Israeli side, the hostilities have killed at least 82 soldiers and 47 civilians, authorities say.
Israel stepped up its campaign in south Lebanon in late September after nearly a year of cross-border exchanges begun by Hezbollah in support of its ally Hamas following the Palestinian group’s October 7, 2023 attack on southern Israel.


West faces ‘reckoning’ over Middle East radicalization: UK spy chief

Updated 30 November 2024
Follow

West faces ‘reckoning’ over Middle East radicalization: UK spy chief

  • MI6 head Richard Moore cites ‘terrible loss of innocent life’
  • ‘In 37 years in the intelligence profession, I’ve never seen the world in a more dangerous state’

LONDON: The West has “yet to have a full reckoning with the radicalizing impact of the fighting, the terrible loss of innocent life in the Middle East and the horrors of Oct. 7,” the head of Britain’s foreign intelligence service MI6 has warned.

Richard Moore made the comments in a speech delivered to the British Embassy in Paris, and was joined by his French counterpart Nicolas Lerner.

Moore said: “In 37 years in the intelligence profession, I’ve never seen the world in a more dangerous state. And the impact on Europe, our shared European home, could hardly be more serious.”

Daesh is expanding its reach and staging deadly attacks in Iran and Russia despite suffering significant territorial setbacks, he added, warning that “the menace of terrorism has not gone away.”

In October last year, Ken McCallum, the head of Britain’s domestic intelligence service MI5, said his agency was monitoring for increased terror risks in the UK due to the Gaza war. More than 40,000 Palestinians have been killed in Gaza in over a year of fighting.

In Lebanon, a 60-day truce agreed this week between Hezbollah and Israel brought an end to a conflict that has killed thousands of Lebanese civilians.


Israel military strikes kill 32 Palestinians in Gaza, medics say

Updated 30 November 2024
Follow

Israel military strikes kill 32 Palestinians in Gaza, medics say

  • Among the 32 killed, at least seven died in an Israeli strike on a house in central Gaza City

The Israeli military said it killed a Palestinian it accused of involvement in Hamas’ October 7 attack on Israel in a vehicle strike in Gaza, and is investigating claims that the individual was an employee of aid group World Central Kitchen.
At least 32 Palestinians were killed in Israeli military strikes across Gaza overnight and into Saturday, with most casualties reported in northern areas, medics told Reuters.
Later on Saturday medics said seven people were killed when an Israeli air strike targeted a vehicle near a gathering of Palestinians receiving aid in the southern area of Khan Younis south of the enclave.
According to residents and a Hamas source, the vehicle targeted near a crowd receiving flour belonged to security personnel responsible for overseeing the delivery of aid shipments into Gaza.
Among the 32 killed, at least seven died in an Israeli strike on a house in central Gaza City, according to a statement from the Gaza Civil Defense and the official Palestinian news agency WAFA early on Saturday.
The Gaza Civil Defense also reported that one of its officers was killed in attacks in northern Gaza’s Jabalia, bringing the total number of civil defense workers killed since October 7, 2023, to 88.
Earlier on Saturday, WAFA reported that three employees of the World Central Kitchen, a US-based, non-governmental humanitarian agency, were killed when a civilian vehicle was targeted in Khan Younis, southern Gaza.
The World Central Kitchen has not yet commented on the incident.