{"id":2915,"date":"2024-03-28T01:00:00","date_gmt":"2024-03-28T06:00:00","guid":{"rendered":"https:\/\/www.darkreading.com\/vulnerabilities-threats\/saudi-arabia-uae-top-list-of-apt-targeted-nations-in-middle-east"},"modified":"2024-03-28T01:00:00","modified_gmt":"2024-03-28T06:00:00","slug":"saudi-arabia-uae-top-list-of-apt-targeted-nations-in-the-middle-east","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/03\/28\/saudi-arabia-uae-top-list-of-apt-targeted-nations-in-the-middle-east\/","title":{"rendered":"Saudi Arabia, UAE Top List of APT-Targeted Nations in the Middle East"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/bltf80e1374e0ecd5e9\/654e39ee99734d0409840af2\/Middle_East_world_map_panther_Media_Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/saudi-arabia-uae-top-list-of-apt-targeted-nations-in-the-middle-east.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/saudi-arabia-uae-top-list-of-apt-targeted-nations-in-the-middle-east.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Sixteen advanced persistent threat (APT) groups targeted organizations in the Middle East over the past two years with cyberattacks focused on government agencies, manufacturing companies, and the energy industry.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The APT actors have mostly targeted organizations in Saudi Arabia, the United Arab Emirates, and Israel and include well-known groups such as Oilrig and Molerats, as well as lesser-known entities such as Bahamut and Hexane, according to an analysis published on March 27 by cybersecurity services firm Positive Technologies.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The groups aim to obtain information that puts their state sponsors at a political, economic, and military advantage, the researchers said. They documented 141 successful attacks that could be attributed to the groups.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Companies should pay attention to what tactics and techniques which APT groups attacking the region are using,&#8221; says Yana Avezova, a senior information security analyst at Positive Technologies. &#8220;Companies in the Middle East region can understand how these groups typically operate and prepare for certain steps accordingly.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The cybersecurity firm used its analysis to determine the most popular types of attacks used by the APT actors, including phishing for initial access, encrypting and camouflaging their malicious code, and communicating using common application-layer protocols, such as Internet Relay Chat (IRC) or DNS requests.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Of the 16 APT actors, six groups \u2014 including APT 35 and Moses Staff \u2014 were linked to Iran, three groups \u2014 such as Molerats \u2014 were linked to Hamas, and two groups were linked to China. The analysis only covered cyberattacks by groups considered both sophisticated and persistent, with Positive Technologies elevating some groups (such as Moses Staff) to APT status, rather than as a hactivist group.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;During the research, we came to the conclusion that some of the groups categorized as hacktivists by certain vendors are not actually hacktivist in nature,&#8221; <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.ptsecurity.com\/ww-en\/analytics\/apt-groups-in-the-middle-east\/?utm_source=pt-en&amp;utm_medium=article&amp;utm_campaign=positive-technologies-cyberattackers-targeting-telecommunications&amp;utm_content=news\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">the report stated<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, adding that &#8220;after a more in-depth analysis, we reached the conclusion that Moses Staff attacks are more sophisticated than hacktivist ones, and the group poses a greater threat than hacktivist groups typically do.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Top Initial Vectors: Phishing Attacks, Remote Exploitation\">Top Initial Vectors: Phishing Attacks, Remote Exploitation<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The analysis maps the various techniques used by each group to the MITRE AT&amp;CK Framework to determine the most common tactics used among the APT groups operating in the Middle East.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The most common tactics to gain initial access include phishing attacks \u2014 used by 11 APT groups \u2014 and exploiting vulnerabilities in public-facing applications, which was used by five groups. Three of the groups also use malware deployed to websites as part of a watering-hole attack targeting visitors in what is also known as a drive-by download attack.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Most APT groups initiate attacks on corporate systems with targeted phishing,&#8221; the report stated. &#8220;Most often, this involves email campaigns with malicious content. Besides email, some attackers \u2014 such as APT35, Bahamut, Dark Caracal, OilRig \u2014 use social networks and messengers for phishing attacks.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Once inside the network, all but one group gathered information on the environment, including the operating system and hardware, while most groups (81%) also enumerated the user accounts on the system and collected network configuration data (69%), according to the report.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">While &#8220;living off the land&#8221; has become a major concern among cybersecurity professionals, nearly all the attackers (94%) downloaded additional attack tools from external networks. Fourteen of the 16 APT groups used application-layer protocols \u2014 such as IRC or DNS \u2014 to facilitate the download, the report stated.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Focused on Long-Term Control\">Focused on Long-Term Control<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The APT groups are typically focused on long-term control of infrastructure, becoming active during a &#8220;geopolitically crucial moment,&#8221; Positive Technologies stated in the report. To prevent their success, companies should look out for their specific tactics, but also focus on hardening their information and operational technology.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The inventory and prioritization of assets, using event monitoring and incident response, and training employees to be more aware of cybersecurity issues are all critical steps for long-term security, says Positive Technologies&#8217; Avezova.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;In short, it is important to adhere to the key principles of result-driven cybersecurity,&#8221; she says, adding that &#8220;the first steps to take are to counter the most commonly used attack techniques.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Out of the 16 groups, the majority targeted organizations in six different Middle Eastern nations: 14 targeted Saudi Arabia; 12 the UAE; 10 Israel; nine Jordan; and eight each targeted Egypt and Kuwait.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">While government, manufacturing, and energy were the most commonly targeted sectors, mass media and the military-industrial complex are increasingly common victim targets, the company stated in the report.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">With the increasing targeting of critical industries, organizations should treat cybersecurity as a critical initiative, the report stated.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;[T]he primary goal [should be] eliminating the possibility of non-tolerable events \u2014 events that prevent an organization from achieving its operational or strategic goals or lead to significant disruption of its core business as a result of a cyberattack,&#8221; the company stated in the report. &#8220;These events are defined by the organization&#8217;s top management and lay the foundation for a cybersecurity strategy.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/saudi-arabia-uae-top-list-of-apt-targeted-nations-in-middle-east\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Sixteen advanced persistent threat (APT) groups targeted organizations in the<\/p>\n","protected":false},"author":12,"featured_media":2916,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-2915","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/saudi-arabia-uae-top-list-of-apt-targeted-nations-in-the-middle-east-scaled.jpg?fit=2560%2C1408&ssl=1",2560,1408,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/saudi-arabia-uae-top-list-of-apt-targeted-nations-in-the-middle-east-scaled.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/saudi-arabia-uae-top-list-of-apt-targeted-nations-in-the-middle-east-scaled.jpg?fit=300%2C165&ssl=1",300,165,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/saudi-arabia-uae-top-list-of-apt-targeted-nations-in-the-middle-east-scaled.jpg?fit=640%2C352&ssl=1",640,352,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/saudi-arabia-uae-top-list-of-apt-targeted-nations-in-the-middle-east-scaled.jpg?fit=640%2C352&ssl=1",640,352,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/saudi-arabia-uae-top-list-of-apt-targeted-nations-in-the-middle-east-scaled.jpg?fit=1536%2C845&ssl=1",1536,845,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/saudi-arabia-uae-top-list-of-apt-targeted-nations-in-the-middle-east-scaled.jpg?fit=2048%2C1126&ssl=1",2048,1126,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/saudi-arabia-uae-top-list-of-apt-targeted-nations-in-the-middle-east-scaled.jpg?fit=1024%2C563&ssl=1",1024,563,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/saudi-arabia-uae-top-list-of-apt-targeted-nations-in-the-middle-east-scaled.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/saudi-arabia-uae-top-list-of-apt-targeted-nations-in-the-middle-east-scaled.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/saudi-arabia-uae-top-list-of-apt-targeted-nations-in-the-middle-east-scaled.jpg?fit=2560%2C1408&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2915","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=2915"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2915\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/2916"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=2915"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=2915"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=2915"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}