Ransomware activity targeting the Middle East surged to its highest level during the 17-month period assessed by CloudSEK, jumping from 17 threat intelligence feeds in April 2025 to 357 in June 2026 — more than a 20-fold increase.
The sharp ransomware escalation is part of a wider shift in the region’s cyber threat landscape, where financially motivated cybercrime is increasingly operating alongside politically driven hacktivism, state-linked espionage, destructive attacks and rapid exploitation of critical vulnerabilities.
CloudSEK’s new Middle East Cyber Threat Landscape 2025–2026 analyses threat activity across ransomware, hacktivism, dark web sources, adversary intelligence, malware and vulnerability intelligence between April 2025 and August 31, 2026. The report recorded its highest overall monthly volume in March 2026, with 2,245 threat intelligence feeds, while Israel was the most targeted country overall with 7,112 feeds.
The findings point to what CloudSEK describes as an increasingly “structurally complex” threat environment, in which organisations must defend simultaneously against high-volume disruptive attacks, financially motivated ransomware and quieter, longer-dwell espionage operations.
Key findings from the report
- Ransomware rose more than 20X: Monthly ransomware feeds increased from 17 in April 2025 to a peak of 357 in June 2026. The June spike was also nearly 10 times the previous month.
- Israel was the most targeted country overall, recording 7,112 threat intelligence feeds. Turkey ranked second overall, while Iran, the UAE, Saudi Arabia and Egypt were also heavily targeted.
- Turkey faced the highest ransomware targeting in the region, driven partly by attacks against industrial, manufacturing and logistics organisations.
- Hacktivism remained the largest threat category by volume, with Israel accounting for 37.8% of regional hacktivist activity.
- Government and financial services were the most targeted sectors overall, while ransomware disproportionately affected facility management, industrial, infrastructure, property management and manufacturing organisations.
- AI is beginning to appear in offensive threat operations. CloudSEK documented MuddyWater using Google’s Gemini model for PowerShell code obfuscation and found evidence of AI-assisted malware development by IRGC-linked Nimbus Manticore/UNC1549.
- Unpatched internet-facing infrastructure remains a major entry point. Fortinet, Ivanti, React, Kubernetes and other widely deployed technologies featured prominently among vulnerabilities relevant to attacks against organisations operating in the region.
Ransomware shifts the regional threat equation
One of the report’s most significant findings is the divergence between hacktivism and ransomware.
Hacktivist activity dominated much of 2025 and surged during periods of geopolitical escalation, particularly in June 2025, October 2025 and March 2026. From April 2026 onwards, however, hacktivist volumes declined sharply.
Ransomware moved in the opposite direction. Its slower but sustained rise culminated in the June 2026 spike, at precisely the period when hacktivist activity was falling most sharply. CloudSEK’s analysis suggests that politically motivated hacktivists and financially motivated ransomware operators largely operate according to different cycles rather than competing for the same attack windows.
Nova emerged as the most prolific ransomware operator identified in the regional dataset, while groups including The Gentlemen, Qilin, LockBit5 and DragonForce also appeared in campaigns affecting Middle Eastern organisations. The report highlights The Gentlemen as an emerging ransomware operator that exploited the Fortinet authentication-bypass vulnerability CVE-2024-55591, alongside VPN credential brute-forcing and the use of Rclone for data theft.
Asset-heavy industries are becoming particularly attractive because disruption can translate directly into operational and financial pressure. Facility management, industrial operations, property management, infrastructure and manufacturing were among the most targeted ransomware sectors.
Geopolitics continues to reshape cyber operations
Hacktivism remained the single largest threat category by volume across the reporting period. Israel was overwhelmingly its primary target, accounting for 37.8% of regional hacktivist activity, followed by Iran. Groups tracked during the period included SKYNET, HeziRash, DieNet, Keymous, OpIsrael, DARKSTORM, NoName057(16) and Handala.
The report also documents a shift in the geographic scope of some actors. Handala, historically focused heavily on Israeli organisations, was recorded targeting UAE critical infrastructure in April 2026, indicating that cyber operations associated with regional geopolitical tensions were extending beyond their traditional target sets.
At the same time, the region continued to face sophisticated espionage activity involving Iranian-linked actors including MuddyWater, Charming Kitten/APT35, APT42, Nimbus Manticore and OilRig, alongside other state-linked and advanced operators.
AI moves into the offensive cyber toolkit
An emerging development identified by CloudSEK is the use of generative AI to support offensive cyber operations.
The report documents MuddyWater using Google’s Gemini AI model to obfuscate PowerShell code, potentially making static analysis of malicious payloads more difficult. It also identifies evidence of AI-assisted malware development by Nimbus Manticore/UNC1549, which CloudSEK says could help accelerate tooling adaptation and operational tempo.
Nimbus Manticore also expanded operations across aviation, defence, telecommunications, software development and government targets, employing phishing, trojanised software installers, SEO poisoning and its MiniFast and MiniJunk malware tooling.
This signals a shift from AI being primarily discussed as a future offensive capability to its emerging use within the workflows of active threat actors.
UAE and Saudi Arabia face growing ransomware and espionage pressure
The UAE recorded 2,588 overall activity indicators and faced activity ranging from ransomware and dark-web exposure to state-linked campaigns.
CloudSEK documented MuddyWater campaigns targeting UAE maritime and industrial organisations, including region-specific phishing lures and a multi-stage Remcos RAT delivery chain. The actor also evolved its tooling toward the Rust-based RustyWater implant, reflecting continued investment in detection evasion.
Saudi Arabia, meanwhile, recorded 1,880 overall activity indicators and saw sustained interest from ransomware operators and underground cybercriminal markets. The Gentlemen targeted Saudi organisations during the reporting period, while Nimbus Manticore identified Saudi Arabia among the regions affected by its expanded operations.
CloudSEK currently assesses organisations in UAE and Saudi critical infrastructure as among the highest-risk groups in the region, alongside Israeli government, defence and healthcare organisations and Turkish industrial and manufacturing companies.
Dark web markets are monetising enterprise access
The report also points to sustained underground demand for credentials, corporate data and access to Middle Eastern enterprise systems.
Financial services and government organisations featured prominently in dark-web activity, alongside e-commerce, banking, investment, retail, education and telecommunications targets. CloudSEK observed significant credential theft, initial-access broker listings and leaked corporate information linked to Gulf organisations.
One campaign involving threat actor xpl0itrs, linked to TeamPCP, involved the sale of unauthorised access to Salesforce Experience Cloud environments belonging to government and financial-services targets. Prices ranged from $2,000 to $40,000 per victim. CloudSEK notes that the activity exploited misconfigured Guest User permissions rather than a previously unknown zero-day.
Critical vulnerabilities continue to provide attackers a path inside
Network-edge infrastructure — particularly VPNs, firewalls and SSL gateways — remained one of the most important initial-access vectors during the reporting period.
CloudSEK highlights actively exploited vulnerabilities affecting Fortinet FortiOS/FortiProxy, Ivanti Connect Secure and Microsoft Windows, while critical vulnerabilities in React Server Components, Kubernetes ingress-nginx, Erlang/OTP and Apache Parquet expanded the potential attack surface for cloud-first and digitally transforming organisations.
The nine major vulnerabilities assessed in the report had an average CVSS score of 9.2, placing all of them within Critical or High severity bands.
CloudSEK recommends organisations urgently patch exposed network-edge and web infrastructure, harden Salesforce and API permissions, strengthen phishing-resistant authentication, segment operational technology networks, maintain immutable offline backups, and test DDoS and incident-response capabilities.
Lower hacktivist noise should not be mistaken for lower cyber risk
Despite a decline in hacktivism after March 2026, CloudSEK warns organisations against interpreting reduced public-facing cyber disruption as an improvement in the overall threat environment.
Ransomware continued at elevated levels while state-linked actors evolved their tooling and techniques. CloudSEK consequently assesses the Middle East’s immediate post-reporting cyber threat environment as ELEVATED-HIGH.
For More Information, Read The Full Report
Related
This entry was posted on September 16, 2026 at 8:29 am and is filed under Commentary with tags CloudSEK. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
Middle East ransomware activity surges over 20X as hacktivism, state-linked espionage and AI-assisted threats converge: CloudSEK
Ransomware activity targeting the Middle East surged to its highest level during the 17-month period assessed by CloudSEK, jumping from 17 threat intelligence feeds in April 2025 to 357 in June 2026 — more than a 20-fold increase.
The sharp ransomware escalation is part of a wider shift in the region’s cyber threat landscape, where financially motivated cybercrime is increasingly operating alongside politically driven hacktivism, state-linked espionage, destructive attacks and rapid exploitation of critical vulnerabilities.
CloudSEK’s new Middle East Cyber Threat Landscape 2025–2026 analyses threat activity across ransomware, hacktivism, dark web sources, adversary intelligence, malware and vulnerability intelligence between April 2025 and August 31, 2026. The report recorded its highest overall monthly volume in March 2026, with 2,245 threat intelligence feeds, while Israel was the most targeted country overall with 7,112 feeds.
The findings point to what CloudSEK describes as an increasingly “structurally complex” threat environment, in which organisations must defend simultaneously against high-volume disruptive attacks, financially motivated ransomware and quieter, longer-dwell espionage operations.
Key findings from the report
Ransomware shifts the regional threat equation
One of the report’s most significant findings is the divergence between hacktivism and ransomware.
Hacktivist activity dominated much of 2025 and surged during periods of geopolitical escalation, particularly in June 2025, October 2025 and March 2026. From April 2026 onwards, however, hacktivist volumes declined sharply.
Ransomware moved in the opposite direction. Its slower but sustained rise culminated in the June 2026 spike, at precisely the period when hacktivist activity was falling most sharply. CloudSEK’s analysis suggests that politically motivated hacktivists and financially motivated ransomware operators largely operate according to different cycles rather than competing for the same attack windows.
Nova emerged as the most prolific ransomware operator identified in the regional dataset, while groups including The Gentlemen, Qilin, LockBit5 and DragonForce also appeared in campaigns affecting Middle Eastern organisations. The report highlights The Gentlemen as an emerging ransomware operator that exploited the Fortinet authentication-bypass vulnerability CVE-2024-55591, alongside VPN credential brute-forcing and the use of Rclone for data theft.
Asset-heavy industries are becoming particularly attractive because disruption can translate directly into operational and financial pressure. Facility management, industrial operations, property management, infrastructure and manufacturing were among the most targeted ransomware sectors.
Geopolitics continues to reshape cyber operations
Hacktivism remained the single largest threat category by volume across the reporting period. Israel was overwhelmingly its primary target, accounting for 37.8% of regional hacktivist activity, followed by Iran. Groups tracked during the period included SKYNET, HeziRash, DieNet, Keymous, OpIsrael, DARKSTORM, NoName057(16) and Handala.
The report also documents a shift in the geographic scope of some actors. Handala, historically focused heavily on Israeli organisations, was recorded targeting UAE critical infrastructure in April 2026, indicating that cyber operations associated with regional geopolitical tensions were extending beyond their traditional target sets.
At the same time, the region continued to face sophisticated espionage activity involving Iranian-linked actors including MuddyWater, Charming Kitten/APT35, APT42, Nimbus Manticore and OilRig, alongside other state-linked and advanced operators.
AI moves into the offensive cyber toolkit
An emerging development identified by CloudSEK is the use of generative AI to support offensive cyber operations.
The report documents MuddyWater using Google’s Gemini AI model to obfuscate PowerShell code, potentially making static analysis of malicious payloads more difficult. It also identifies evidence of AI-assisted malware development by Nimbus Manticore/UNC1549, which CloudSEK says could help accelerate tooling adaptation and operational tempo.
Nimbus Manticore also expanded operations across aviation, defence, telecommunications, software development and government targets, employing phishing, trojanised software installers, SEO poisoning and its MiniFast and MiniJunk malware tooling.
This signals a shift from AI being primarily discussed as a future offensive capability to its emerging use within the workflows of active threat actors.
UAE and Saudi Arabia face growing ransomware and espionage pressure
The UAE recorded 2,588 overall activity indicators and faced activity ranging from ransomware and dark-web exposure to state-linked campaigns.
CloudSEK documented MuddyWater campaigns targeting UAE maritime and industrial organisations, including region-specific phishing lures and a multi-stage Remcos RAT delivery chain. The actor also evolved its tooling toward the Rust-based RustyWater implant, reflecting continued investment in detection evasion.
Saudi Arabia, meanwhile, recorded 1,880 overall activity indicators and saw sustained interest from ransomware operators and underground cybercriminal markets. The Gentlemen targeted Saudi organisations during the reporting period, while Nimbus Manticore identified Saudi Arabia among the regions affected by its expanded operations.
CloudSEK currently assesses organisations in UAE and Saudi critical infrastructure as among the highest-risk groups in the region, alongside Israeli government, defence and healthcare organisations and Turkish industrial and manufacturing companies.
Dark web markets are monetising enterprise access
The report also points to sustained underground demand for credentials, corporate data and access to Middle Eastern enterprise systems.
Financial services and government organisations featured prominently in dark-web activity, alongside e-commerce, banking, investment, retail, education and telecommunications targets. CloudSEK observed significant credential theft, initial-access broker listings and leaked corporate information linked to Gulf organisations.
One campaign involving threat actor xpl0itrs, linked to TeamPCP, involved the sale of unauthorised access to Salesforce Experience Cloud environments belonging to government and financial-services targets. Prices ranged from $2,000 to $40,000 per victim. CloudSEK notes that the activity exploited misconfigured Guest User permissions rather than a previously unknown zero-day.
Critical vulnerabilities continue to provide attackers a path inside
Network-edge infrastructure — particularly VPNs, firewalls and SSL gateways — remained one of the most important initial-access vectors during the reporting period.
CloudSEK highlights actively exploited vulnerabilities affecting Fortinet FortiOS/FortiProxy, Ivanti Connect Secure and Microsoft Windows, while critical vulnerabilities in React Server Components, Kubernetes ingress-nginx, Erlang/OTP and Apache Parquet expanded the potential attack surface for cloud-first and digitally transforming organisations.
The nine major vulnerabilities assessed in the report had an average CVSS score of 9.2, placing all of them within Critical or High severity bands.
CloudSEK recommends organisations urgently patch exposed network-edge and web infrastructure, harden Salesforce and API permissions, strengthen phishing-resistant authentication, segment operational technology networks, maintain immutable offline backups, and test DDoS and incident-response capabilities.
Lower hacktivist noise should not be mistaken for lower cyber risk
Despite a decline in hacktivism after March 2026, CloudSEK warns organisations against interpreting reduced public-facing cyber disruption as an improvement in the overall threat environment.
Ransomware continued at elevated levels while state-linked actors evolved their tooling and techniques. CloudSEK consequently assesses the Middle East’s immediate post-reporting cyber threat environment as ELEVATED-HIGH.
For More Information, Read The Full Report
Share this:
Like this:
Related
This entry was posted on September 16, 2026 at 8:29 am and is filed under Commentary with tags CloudSEK. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.