Cybersecuritynews Coordinated Cyber Espionage Targets Libyan Oil Sector
Article Content
- •A cyber espionage campaign targeted Libyan critical infrastructure from November 2025 to February 2026.
- •AsyncRAT was used in the attacks, indicating potential state-sponsored involvement.
- •The affected sectors include oil, telecommunications, and government institutions.
Between November 2025 and February 2026, a coordinated cyber espionage campaign targeted a Libyan oil refinery, a telecommunications organization, and a state institution. The attacks utilized AsyncRAT, a publicly available remote access Trojan known for its use by state-sponsored threat groups. This campaign specifically aimed at Libya's critical infrastructure, raising alarms about the security of the oil sector, which produced approximately 1.37 million barrels of oil per day in 2025. The scope of the attacks indicates a significant threat to national security and economic stability. As of March 23, 2026, the situation remains under investigation, with no confirmed attribution of the attackers.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track AsyncRAT in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Surge in Exploited CVEs and Malware Activity in H1 2026 In the first half of 2026, Insikt Group reported 215 actively exploited CVEs, marking a 34% increase from the previous year. Notably, AsyncRAT emerged as the leading malware, with nearly 60,000 unique hashes. The report highlighted a significant rise in NFC-based Android attacks, which surged by 188%. Threat actors…
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…