Skip to content
Hacktivist Groups Expand Attacks Beyond Russia to Middle East and Central Asia

Hacktivist Groups Expand Attacks Beyond Russia to Middle East and Central Asia

First seen 9 Jun 2026, 11:55 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 10, 2026 at 11:29 UTC

Hacktivist groups 4BID, Hakerskii Kit, and C.A.S. have broadened their attack geography, targeting organizations in Kazakhstan, the UAE, Syria, and Egypt, moving beyond their previous focus on Russian and Belarusian entities. The investigation began after indicators of compromise were detected in a breached Russian organization, leading researchers to uncover interconnected actors. Attackers primarily exploited the ProxyShell vulnerability in Microsoft Exchange to gain initial access, deploying the fd.aspx web shell for remote control and reconnaissance. The campaigns also utilized new ransomware samples, including ClearWater, and a previously undocumented backdoor named BlackSalt. Despite the new targets, most compromised systems still belong to Russian and Belarusian organizations. This shift in focus appears to be motivated by a claim from a 4BID member that attacking Russia is no longer profitable.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 92d ago How this analysis works

Timeline

2023-10-02
Public exploit for CVE-2023-44976 released
A proof-of-concept exploit appeared on GitHub, lowering the barrier for opportunistic attackers.
GitHub
2026-06-08
Securelist reports expanded attack geography
Hacktivist groups broadened their targets to include Kazakhstan, UAE, Syria, and Egypt, moving beyond Russia.
Securelist
2026-06-09
Technadu covers hacktivist activity
Technadu reports on the findings from Securelist regarding the expanded activities of 4BID and others.
Technadu
Date unknown
Initial access via ProxyShell vulnerability
Attackers exploited the ProxyShell vulnerability in Microsoft Exchange to gain access to compromised systems.
Securelist
Date unknown
Deployment of fd.aspx web shell
The fd.aspx web shell was deployed for remote control and reconnaissance after initial access was achieved.
Technadu

More articles in this cluster (3)

Following this threat?

Track Babuk, Blackout Locker and Eriell Group in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed