{"id":77762,"date":"2025-06-18T11:31:16","date_gmt":"2025-06-18T08:31:16","guid":{"rendered":"https:\/\/gulftech-news.com\/en\/?p=77762"},"modified":"2025-06-18T11:31:17","modified_gmt":"2025-06-18T08:31:17","slug":"report-advanced-cyberattacks-hit-middle-east-critical-infrastructure-over-two-years","status":"publish","type":"post","link":"https:\/\/gulftech-news.com\/en\/2025\/06\/18\/report-advanced-cyberattacks-hit-middle-east-critical-infrastructure-over-two-years\/","title":{"rendered":"Report: Advanced Cyberattacks Hit Middle East Critical Infrastructure Over Two Years"},"content":{"rendered":"\n<p><em><strong>FortiGuard Labs Uncovers Advanced Espionage Campaign Targeting IT\/OT Systems<\/strong><\/em><\/p>\n\n\n\n<p><em><strong>\u00a073% of OT Firms Targeted as Cyberattacks Escalate Across Critical Sectors<\/strong><\/em><\/p>\n\n\n\n<p>TheFortiGuard Labs\u2019 Incident Response (FGIR) team recently investigated a long-term cyber intrusion targeting critical national infrastructure (CNI) in the Middle East.<\/p>\n\n\n\n<p>The intrusion, attributed to a state-sponsored threat actor, involved sustained espionage operations and suspected network prepositioning. Over the course of nearly two years, the threat actor deployed novel malware, bypassed network segmentation, and made repeated attempts to maintain access across segmented IT and OT environments.<\/p>\n\n\n\n<p><strong>Advanced Malware and Persistent Access<\/strong><\/p>\n\n\n\n<p>The multi-phase intrusion detailed by FGIR spanned from 2023 to early 2025. The attacker initially gained entry using compromised VPN credentials, then established footholds using multiple custom backdoors including HanifNet, HXLibrary, and NeoExpressRAT. They bypassed segmentation using proxy tools such as Ngrok, ReverseSocks5, and plink, and targeted virtualization infrastructure to deepen access.<\/p>\n\n\n\n<p>While no confirmed disruption to OT systems was observed, the report notes significant reconnaissance activity in restricted environments \u2014 emphasizing the need for heightened defense across converged IT\/OT networks.<\/p>\n\n\n\n<p>The operation unfolded across four stages: initial compromise, consolidation of access, adversary response to containment, and attempted re-entry via exploitation of third-party software and phishing attacks. Even after being removed from the network, the threat actor made repeated efforts to re-establish access \u2014 signalling a long-term strategic objective.<\/p>\n\n\n\n<p><strong>OT Security Faces Escalating Threats<\/strong><\/p>\n\n\n\n<p>According to Fortinet\u2019s <a href=\"https:\/\/www.fortinet.com\/uk\/resources\/reports\/state-of-ot-cybersecurity\">2024 State of Operational Technology and Cybersecurity Report<\/a>, 73% of OT organizations globally have now experienced cyber intrusions \u2014 up from 49% in 2023 \u2014 with targeted OT-only attacks also rising from 17% to 24%.<\/p>\n\n\n\n<p>This trend mirrors the patterns observed in the latest investigation, where state-linked actors deployed advanced malware, evaded detection, and used phishing and software exploitation to reestablish access after remediation efforts. For this reason, we are seeing responsibility for OT cybersecurity increasingly shifting to the CISO, CIO, and COO, with 60% of organizations reporting executive-level oversight.<\/p>\n\n\n\n<p><strong>Regional Threat Activity on the Rise<\/strong><\/p>\n\n\n\n<p>Fortinet\u2019s <a href=\"https:\/\/www.fortinet.com\/uk\/resources\/reports\/threat-landscape-report\">2025 Global Threat Landscape Report<\/a> also confirms that state-sponsored groups remain highly active, targeting government, technology, and education sectors. Interestingly, over 60% of hacktivist campaigns globally were linked to geopolitical causes. The Middle East also remains a high-risk region for cyber activity, with the EMEA region accounting for 26% of recorded global exploitation attempts.<\/p>\n\n\n\n<p><strong>Defensive Recommendations<\/strong><\/p>\n\n\n\n<p>To defend against such persistent and well-resourced adversaries, the FortiGuard team recommends that organizations prioritize the following defensive measures:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Enforcing multi-factor authentication (MFA) and regular credential rotation<\/li>\n\n\n\n<li>Deploying zero-trust architecture and network segmentation<\/li>\n\n\n\n<li>Implementing endpoint detection and response (EDR) and behavioural analytics<\/li>\n\n\n\n<li>Conducting regular penetration testing and incident response readiness exercises<\/li>\n<\/ul>\n\n\n\n<p>This investigation highlights the persistent and evolving nature of state-backed cyber threats targeting Middle Eastern CNIs, and a growing need for continuous monitoring, adaptive defense strategies, and coordinated threat intelligence to protect critical infrastructure in the face of sophisticated cyber threats.<\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>FortiGuard Labs Uncovers Advanced Espionage Campaign Targeting IT\/OT Systems \u00a073% of OT Firms Targeted as Cyberattacks Escalate Across Critical Sectors TheFortiGuard Labs\u2019 Incident Response (FGIR) team recently investigated a long-term cyber intrusion targeting critical national infrastructure (CNI) in the Middle East. The intrusion, attributed to a state-sponsored threat actor, involved sustained espionage operations and suspected &hellip;<\/p>\n","protected":false},"author":2,"featured_media":77763,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[2815,2814],"class_list":["post-77762","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-critical-infrastructure","tag-cyberattacks"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v24.1 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Report: Advanced Cyberattacks Hit Middle East Critical Infrastructure Over Two Years - Gulf Tech News<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/gulftech-news.com\/en\/2025\/06\/18\/report-advanced-cyberattacks-hit-middle-east-critical-infrastructure-over-two-years\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Report: Advanced Cyberattacks Hit Middle East Critical Infrastructure Over Two Years - Gulf Tech News\" \/>\n<meta property=\"og:description\" content=\"FortiGuard Labs Uncovers Advanced Espionage Campaign Targeting IT\/OT Systems \u00a073% of OT Firms Targeted as Cyberattacks Escalate Across Critical Sectors TheFortiGuard Labs\u2019 Incident Response (FGIR) team recently investigated a long-term cyber intrusion targeting critical national infrastructure (CNI) in the Middle East. The intrusion, attributed to a state-sponsored threat actor, involved sustained espionage operations and suspected &hellip;\" \/>\n<meta property=\"og:url\" content=\"https:\/\/gulftech-news.com\/en\/2025\/06\/18\/report-advanced-cyberattacks-hit-middle-east-critical-infrastructure-over-two-years\/\" \/>\n<meta property=\"og:site_name\" content=\"Gulf Tech News\" \/>\n<meta property=\"article:published_time\" content=\"2025-06-18T08:31:16+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-06-18T08:31:17+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/gulftech-news.com\/en\/wp-content\/uploads\/2025\/06\/2423112.jpg?v=1750235464\" \/>\n\t<meta property=\"og:image:width\" content=\"1000\" \/>\n\t<meta property=\"og:image:height\" content=\"557\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"bessan helmi\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"bessan helmi\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/gulftech-news.com\/en\/2025\/06\/18\/report-advanced-cyberattacks-hit-middle-east-critical-infrastructure-over-two-years\/\",\"url\":\"https:\/\/gulftech-news.com\/en\/2025\/06\/18\/report-advanced-cyberattacks-hit-middle-east-critical-infrastructure-over-two-years\/\",\"name\":\"Report: Advanced Cyberattacks Hit Middle East Critical Infrastructure Over Two Years - Gulf Tech News\",\"isPartOf\":{\"@id\":\"https:\/\/gulftech-news.com\/en\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/gulftech-news.com\/en\/2025\/06\/18\/report-advanced-cyberattacks-hit-middle-east-critical-infrastructure-over-two-years\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/gulftech-news.com\/en\/2025\/06\/18\/report-advanced-cyberattacks-hit-middle-east-critical-infrastructure-over-two-years\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/gulftech-news.com\/en\/wp-content\/uploads\/2025\/06\/2423112.jpg?v=1750235464\",\"datePublished\":\"2025-06-18T08:31:16+00:00\",\"dateModified\":\"2025-06-18T08:31:17+00:00\",\"author\":{\"@id\":\"https:\/\/gulftech-news.com\/en\/#\/schema\/person\/c033626e357b2f7e127eac0570ddc05c\"},\"breadcrumb\":{\"@id\":\"https:\/\/gulftech-news.com\/en\/2025\/06\/18\/report-advanced-cyberattacks-hit-middle-east-critical-infrastructure-over-two-years\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/gulftech-news.com\/en\/2025\/06\/18\/report-advanced-cyberattacks-hit-middle-east-critical-infrastructure-over-two-years\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/gulftech-news.com\/en\/2025\/06\/18\/report-advanced-cyberattacks-hit-middle-east-critical-infrastructure-over-two-years\/#primaryimage\",\"url\":\"https:\/\/gulftech-news.com\/en\/wp-content\/uploads\/2025\/06\/2423112.jpg?v=1750235464\",\"contentUrl\":\"https:\/\/gulftech-news.com\/en\/wp-content\/uploads\/2025\/06\/2423112.jpg?v=1750235464\",\"width\":1000,\"height\":557,\"caption\":\"Report: Advanced Cyberattacks Hit Middle East Critical Infrastructure Over Two Years\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/gulftech-news.com\/en\/2025\/06\/18\/report-advanced-cyberattacks-hit-middle-east-critical-infrastructure-over-two-years\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/gulftech-news.com\/en\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Report: Advanced Cyberattacks Hit Middle East Critical Infrastructure Over Two Years\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/gulftech-news.com\/en\/#website\",\"url\":\"https:\/\/gulftech-news.com\/en\/\",\"name\":\"Gulf Tech News\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/gulftech-news.com\/en\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/gulftech-news.com\/en\/#\/schema\/person\/c033626e357b2f7e127eac0570ddc05c\",\"name\":\"bessan helmi\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/gulftech-news.com\/en\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/bb1e09a6f094e0fa605073926f8ad9eb228a8b0aacd381fda782c562612428cf?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/bb1e09a6f094e0fa605073926f8ad9eb228a8b0aacd381fda782c562612428cf?s=96&d=mm&r=g\",\"caption\":\"bessan helmi\"},\"url\":\"https:\/\/gulftech-news.com\/en\/author\/bessan-helmi\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Report: Advanced Cyberattacks Hit Middle East Critical Infrastructure Over Two Years - Gulf Tech News","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/gulftech-news.com\/en\/2025\/06\/18\/report-advanced-cyberattacks-hit-middle-east-critical-infrastructure-over-two-years\/","og_locale":"en_US","og_type":"article","og_title":"Report: Advanced Cyberattacks Hit Middle East Critical Infrastructure Over Two Years - Gulf Tech News","og_description":"FortiGuard Labs Uncovers Advanced Espionage Campaign Targeting IT\/OT Systems \u00a073% of OT Firms Targeted as Cyberattacks Escalate Across Critical Sectors TheFortiGuard Labs\u2019 Incident Response (FGIR) team recently investigated a long-term cyber intrusion targeting critical national infrastructure (CNI) in the Middle East. The intrusion, attributed to a state-sponsored threat actor, involved sustained espionage operations and suspected &hellip;","og_url":"https:\/\/gulftech-news.com\/en\/2025\/06\/18\/report-advanced-cyberattacks-hit-middle-east-critical-infrastructure-over-two-years\/","og_site_name":"Gulf Tech News","article_published_time":"2025-06-18T08:31:16+00:00","article_modified_time":"2025-06-18T08:31:17+00:00","og_image":[{"width":1000,"height":557,"url":"https:\/\/gulftech-news.com\/en\/wp-content\/uploads\/2025\/06\/2423112.jpg?v=1750235464","type":"image\/jpeg"}],"author":"bessan helmi","twitter_card":"summary_large_image","twitter_misc":{"Written by":"bessan helmi","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/gulftech-news.com\/en\/2025\/06\/18\/report-advanced-cyberattacks-hit-middle-east-critical-infrastructure-over-two-years\/","url":"https:\/\/gulftech-news.com\/en\/2025\/06\/18\/report-advanced-cyberattacks-hit-middle-east-critical-infrastructure-over-two-years\/","name":"Report: Advanced Cyberattacks Hit Middle East Critical Infrastructure Over Two Years - Gulf Tech News","isPartOf":{"@id":"https:\/\/gulftech-news.com\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/gulftech-news.com\/en\/2025\/06\/18\/report-advanced-cyberattacks-hit-middle-east-critical-infrastructure-over-two-years\/#primaryimage"},"image":{"@id":"https:\/\/gulftech-news.com\/en\/2025\/06\/18\/report-advanced-cyberattacks-hit-middle-east-critical-infrastructure-over-two-years\/#primaryimage"},"thumbnailUrl":"https:\/\/gulftech-news.com\/en\/wp-content\/uploads\/2025\/06\/2423112.jpg?v=1750235464","datePublished":"2025-06-18T08:31:16+00:00","dateModified":"2025-06-18T08:31:17+00:00","author":{"@id":"https:\/\/gulftech-news.com\/en\/#\/schema\/person\/c033626e357b2f7e127eac0570ddc05c"},"breadcrumb":{"@id":"https:\/\/gulftech-news.com\/en\/2025\/06\/18\/report-advanced-cyberattacks-hit-middle-east-critical-infrastructure-over-two-years\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/gulftech-news.com\/en\/2025\/06\/18\/report-advanced-cyberattacks-hit-middle-east-critical-infrastructure-over-two-years\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/gulftech-news.com\/en\/2025\/06\/18\/report-advanced-cyberattacks-hit-middle-east-critical-infrastructure-over-two-years\/#primaryimage","url":"https:\/\/gulftech-news.com\/en\/wp-content\/uploads\/2025\/06\/2423112.jpg?v=1750235464","contentUrl":"https:\/\/gulftech-news.com\/en\/wp-content\/uploads\/2025\/06\/2423112.jpg?v=1750235464","width":1000,"height":557,"caption":"Report: Advanced Cyberattacks Hit Middle East Critical Infrastructure Over Two Years"},{"@type":"BreadcrumbList","@id":"https:\/\/gulftech-news.com\/en\/2025\/06\/18\/report-advanced-cyberattacks-hit-middle-east-critical-infrastructure-over-two-years\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/gulftech-news.com\/en\/"},{"@type":"ListItem","position":2,"name":"Report: Advanced Cyberattacks Hit Middle East Critical Infrastructure Over Two Years"}]},{"@type":"WebSite","@id":"https:\/\/gulftech-news.com\/en\/#website","url":"https:\/\/gulftech-news.com\/en\/","name":"Gulf Tech News","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/gulftech-news.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/gulftech-news.com\/en\/#\/schema\/person\/c033626e357b2f7e127eac0570ddc05c","name":"bessan helmi","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/gulftech-news.com\/en\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/bb1e09a6f094e0fa605073926f8ad9eb228a8b0aacd381fda782c562612428cf?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/bb1e09a6f094e0fa605073926f8ad9eb228a8b0aacd381fda782c562612428cf?s=96&d=mm&r=g","caption":"bessan helmi"},"url":"https:\/\/gulftech-news.com\/en\/author\/bessan-helmi\/"}]}},"_links":{"self":[{"href":"https:\/\/gulftech-news.com\/en\/wp-json\/wp\/v2\/posts\/77762","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/gulftech-news.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/gulftech-news.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/gulftech-news.com\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/gulftech-news.com\/en\/wp-json\/wp\/v2\/comments?post=77762"}],"version-history":[{"count":1,"href":"https:\/\/gulftech-news.com\/en\/wp-json\/wp\/v2\/posts\/77762\/revisions"}],"predecessor-version":[{"id":77764,"href":"https:\/\/gulftech-news.com\/en\/wp-json\/wp\/v2\/posts\/77762\/revisions\/77764"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/gulftech-news.com\/en\/wp-json\/wp\/v2\/media\/77763"}],"wp:attachment":[{"href":"https:\/\/gulftech-news.com\/en\/wp-json\/wp\/v2\/media?parent=77762"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/gulftech-news.com\/en\/wp-json\/wp\/v2\/categories?post=77762"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/gulftech-news.com\/en\/wp-json\/wp\/v2\/tags?post=77762"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}