Technadu Hacktivist Groups Expand Attacks Beyond Russia to Middle East and Central Asia
Article Content
- •Hacktivist groups 4BID, Hakerskii Kit, and C.A.S. are targeting organizations in Kazakhstan, UAE, Syria, and Egypt.
- •Initial access is commonly gained through the ProxyShell vulnerability in Microsoft Exchange.
- •New malware includes the ClearWater ransomware and a backdoor named BlackSalt.
Hacktivist groups 4BID, Hakerskii Kit, and C.A.S. have broadened their attack geography, targeting organizations in Kazakhstan, the UAE, Syria, and Egypt, moving beyond their previous focus on Russian and Belarusian entities. The investigation began after indicators of compromise were detected in a breached Russian organization, leading researchers to uncover interconnected actors. Attackers primarily exploited the ProxyShell vulnerability in Microsoft Exchange to gain initial access, deploying the fd.aspx web shell for remote control and reconnaissance. The campaigns also utilized new ransomware samples, including ClearWater, and a previously undocumented backdoor named BlackSalt. Despite the new targets, most compromised systems still belong to Russian and Belarusian organizations. This shift in focus appears to be motivated by a claim from a 4BID member that attacking Russia is no longer profitable.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Babuk, Blackout Locker and Eriell Group in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Toy Ghouls Use HiveMQ and Element for New Windows Backdoors The financially motivated group Toy Ghouls has introduced two new Windows backdoors named mqtt-bird-agent and matrix-bird-agent, utilizing HiveMQ and Element messenger for command-and-control communications. This marks a shift from their previous reliance on public tools and ransomware builders. The backdoors are…
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…