Hacktivist Groups Expand Attacks Beyond Russia to Middle East and Central Asia

Hacktivist Groups Expand Attacks Beyond Russia to Middle East and Central Asia

First seen 9 Jun 2026, 11:55 UTC SecurelistTechnadusecurelist.com 81% similarity 59.0

Article Content

Browse articles
ThreatCluster

Hacktivist groups 4BID, Hakerskii Kit, and C.A.S. have broadened their attack geography, targeting organizations in Kazakhstan, the UAE, Syria, and Egypt, moving beyond their previous focus on Russian and Belarusian entities. The investigation began after indicators of compromise were detected in a breached Russian organization, leading researchers to uncover interconnected actors. Attackers primarily exploited the ProxyShell vulnerability in Microsoft Exchange to gain initial access, deploying the fd.aspx web shell for remote control and reconnaissance. The campaigns also utilized new ransomware samples, including ClearWater, and a previously undocumented backdoor named BlackSalt. Despite the new targets, most compromised systems still belong to Russian and Belarusian organizations. This shift in focus appears to be motivated by a claim from a 4BID member that attacking Russia is no longer profitable.

Key Points: • Hacktivist groups 4BID, Hakerskii Kit, and C.A.S. are targeting organizations in Kazakhstan, UAE, Syria, and Egypt. • Initial access is commonly gained through the ProxyShell vulnerability in Microsoft Exchange. • New malware includes the ClearWater ransomware and a backdoor named BlackSalt.

ThreatCluster AI

Timeline

2023-10-02
Public exploit for CVE-2023-44976 released
A proof-of-concept exploit appeared on GitHub, lowering the barrier for opportunistic attackers.
GitHub
2026-06-08
Securelist reports expanded attack geography
Hacktivist groups broadened their targets to include Kazakhstan, UAE, Syria, and Egypt, moving beyond Russia.
Securelist
2026-06-09
Technadu covers hacktivist activity
Technadu reports on the findings from Securelist regarding the expanded activities of 4BID and others.
Technadu
Date unknown
Initial access via ProxyShell vulnerability
Attackers exploited the ProxyShell vulnerability in Microsoft Exchange to gain access to compromised systems.
Securelist
Date unknown
Deployment of fd.aspx web shell
The fd.aspx web shell was deployed for remote control and reconnaissance after initial access was achieved.
Technadu

Community

Browse all →