Skip to content
AttackFeed by Joe Wagner | Cybersecurity News from Across the Internet

AttackFeed by Joe Wagner

Cybersecurity News from Across the Internet

  • Attack/News Feeds
  • Gov Alerts/ISAC Feeds
  • Vulnerability Alerts
  • Privacy/Governance Feeds
  • Fraud Feeds
  • iOS App
  • Android App
  • Home
  • Attack Feeds
  • Hack-for-hire spyware campaign targets journalists in Middle East, North Africa  – CyberScoop
AttackFeed by Joe Wagner | Hack-for-hire spyware campaign targets journalists in Middle East, North Africa  - CyberScoop

Hack-for-hire spyware campaign targets journalists in Middle East, North Africa  – CyberScoop

Posted on April 8, 2026 By Tim Starks
Attack Feeds

An apparent hack-for-hire campaign from a group with suspected Indian government connections targeted Middle Eastern and North African journalists and activists using spyware, three collaborating organizations said in reports published Wednesday.

The attacks shared infrastructure that pointed to the advanced persistent threat group known as Bitter, which most frequently targets government, military, diplomatic and critical infrastructure sectors across South Asia, according to conclusions from researchers at Access Now, Lookout and SMEX.

Each group took on a different piece of the puzzle:

  • Access Now got calls on its helpline that led it to examine a spearphishing campaign in 2023 and 2024. It contacted Lookout for technical support about the malware it encountered.
  • Lookout attributed the malware to Bitter, concluding it was a likely hack-for-hire campaign, using the Android ProSpy spyware.
  • SMEX dived into a spearphishing campaign targeting a prominent Lebanese journalist last year, collaborating with Access Now to discover shared infrastructure between the campaigns.

One of the victims, independent Egyptian journalist Mostafa Al-A’sar, said he contacted Access Now after receiving a suspicious link from someone he’d been talking to about a job position. He was skeptical because his phone had been targeted before, when he was arrested in Egypt in 2018.

The lesson for journalists and civil society groups is that cybersecurity “is not a luxury,” he said.

“I feel like I’m threatened,” Al-A’sar said, and even though he was living in exile, he feels like “they are still following me. I also felt worried about my family, about my friends, about my sources.”

The combined research found a wider campaign than just the original victims.

“Our joint findings expose an espionage campaign that has been operational since at least 2022 until present day primarily targeting civil society members and potentially government officials in the Middle East,” Lookout wrote. “The operation features a combination of targeted spearphishing delivered through fake social media accounts and messaging applications leveraging persistent social engineering efforts, which may result in the delivery of Android spyware depending on the target’s device.”

The Committee to Protect Journalists condemned the campaign.

“Spying on journalists is often the first step in a broader pattern of intimidation, threats, and attacks,” said the group’s regional director, Sara Qudah. “These actions endanger not only journalists’ personal safety, but also their sources and their ability to do their work. Authorities in the region must stop weaponizing technology and financial resources to surveil journalists.”

Access Now said it didn’t have enough information to attribute who was behind the attacks it identified.

ESET first published research on the ProSpy malware last year, after finding it targeting residents of the United Arab Emirates.

The post Hack-for-hire spyware campaign targets journalists in Middle East, North Africa appeared first on CyberScoop.

  –

Read More  – CyberScoop 

Post navigation

❮ Previous Post: Node.js Trust Falls: Dangerous Module Resolution on Windows  – Zero Day Initiative – Blog
Next Post: Masjesu Botnet Emerges as DDoS-for-Hire Service Targeting Global IoT Devices  – The Hacker News ❯

You may also like

AttackFeed by Joe Wagner | UNC1069 Social Engineering of Axios Maintainer Led to npm Supply Chain Attack  - The Hacker News
Attack Feeds
UNC1069 Social Engineering of Axios Maintainer Led to npm Supply Chain Attack  – The Hacker News
April 3, 2026
AttackFeed by Joe Wagner | Browser Extensions Are the New AI Consumption Channel That No One Is Talking About  - The Hacker News
Attack Feeds
Browser Extensions Are the New AI Consumption Channel That No One Is Talking About  – The Hacker News
April 10, 2026
AttackFeed by Joe Wagner | TrapDoor Supply Chain Attack Spreads Credential-Stealing Malware via npm, PyPI, and CratesIO  - The Hacker News
Attack Feeds
TrapDoor Supply Chain Attack Spreads Credential-Stealing Malware via npm, PyPI, and CratesIO  – The Hacker News
May 25, 2026
AttackFeed by Joe Wagner | Threat Actors Exploit Critical FortiClient EMS Flaw to Deploy Credential Stealer  - The Hacker News
Attack Feeds
Threat Actors Exploit Critical FortiClient EMS Flaw to Deploy Credential Stealer  – The Hacker News
May 28, 2026
  • Attack Feeds
  • Privacy/Governance Feed
  • Gov/ISAC Feeds
  • Alert Feeds
  • Privacy Policy
  • Wagner Cybersecurity

Copyright © 2026 AttackFeed by Joe Wagner.

Theme: Oceanly News Dark by ScriptsTown

We are using cookies for analytics purposes only.  We do not store, track or sell user information.

You can find out more about which cookies we are using or switch them off in .

AttackFeed by Joe Wagner
Powered by  GDPR Cookie Compliance
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Strictly Necessary Cookies

Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.