← ALL ARTICLES
// NATION-STATE & ESPIONAGE

Nation-State & Espionage Intelligence

30 articles. Nation-state cyber operations and espionage campaigns. APT tracking, attribution analysis, and geopolitical context across MENA, EU, and US.

🌍 GLOBAL CRITICAL

Google Disrupts UNC2814: Chinese Espionage Group Breached 53 Telecoms and Governments Across 42 Countries Using Google Sheets C2

Google disrupted UNC2814, a suspected PRC espionage group that breached 53 telecoms and governments across 42 countries using Google Sheets as C2.

2026-02-25
🇺🇸 USA HIGH

APT IRAN's 375TB Lockheed Martin Claim: Fabricated Data Dump, Real Information Operation

Self-named hacktivist collective claims 375TB exfiltration from Lockheed Martin. Zero verified samples after 10 days. Separately, MOIS-backed Handala.

2026-03-30
🌍 GLOBAL CRITICAL

F5 BIG-IP: Critical RCE Exploited in the Wild After Five-Month Misclassification

F5 reclassifies BIG-IP APM vulnerability CVE-2025-53521 from denial-of-service to unauthenticated RCE. Memory-resident webshells deployed.

2026-03-30
🇺🇸 USA CRITICAL

FBI Director Patel: Handala Publishes 300+ Emails from Personal Gmail - 11 Prior Breaches on HIBP

Iran's MOIS-backed Handala published 300+ emails and photos from FBI Director Kash Patel's personal Gmail. The account appeared in 11 prior data breaches.

2026-03-29
🇺🇸 USA CRITICAL

MuddyWater Pre-Positions Dindoor and Fakeset Backdoors on US Bank, Airport, Defense Networks

Iran's MuddyWater embedded Deno-based and Python backdoors on a US bank, airport, and defense company weeks before US-Israeli strikes on Iran.

2026-03-05
🇸🇦 Saudi PDPL CRITICAL

DarkSword: iOS Zero-Day Exploit Chain Targets Four Countries, Full Kit Leaked

A 6-vulnerability iOS exploit chain deploying three malware variants targeted users across Saudi Arabia, Turkey, Malaysia, and Ukraine.

2026-03-26
🇮🇷 THREAT BRIEF HIGH

Operation Olalampo: MuddyWater Deploys AI-Assisted Rust Malware Across MENA

Iranian APT MuddyWater launched Operation Olalampo targeting Gulf governments with new AI-assisted malware including GhostFetch, CHAR backdoor.

2026-01-26
🇺🇸 THREAT BRIEF CRITICAL

Cisco SD-WAN Zero-Day (CVE-2026-20127) Exploited Since 2023 by Sophisticated APT

Critical auth bypass in Cisco Catalyst SD-WAN exploited by APT UAT-8616 since 2023. CVSS 10.0. Five Eyes joint advisory. CISA emergency directive ED 26-03.

2026-02-25
🇪🇬 Egypt HIGH

Predator in Egypt: Intellexa Leaks Expose State Spyware Operations Against Activists

Amnesty International revealed Predator spyware deployed against Egyptian activists via zero-click exploits. US sanctions imposed on Intellexa consortium.

2025-12-01
🇺🇸 USA CRITICAL

Yale New Haven Health: 5.6M Patient Records Stolen in Ivanti VPN Exploit

China-linked attackers exploited an Ivanti VPN zero-day with RESURGE rootkit to steal 5.6M patient records across five Connecticut hospitals.

2025-03-01
🇯🇴 Jordan

Jordan NCSC 2024: 6,758 Cyber Incidents Mark 175% Annual Surge

Jordan's NCSC reported 6,758 incidents in 2024, a 175% surge over 2023, issuing 6,922 alerts and achieving a 97% detection rate against known threat indicators.

2024-01-01
🇧🇭 Bahrain PDPL

Bahrain Pegasus Campaign: 12+ Activists Hacked with Zero-Click Exploits

Citizen Lab documented Bahrain's use of NSO Group's Pegasus spyware against at least nine activists via zero-click iMessage exploits requiring no user.

2021-08-01
🇱🇧 Lebanon

Lebanese Cedar APT: Hezbollah Hackers Breach 250+ Telecom Servers

Hezbollah-linked Lebanese Cedar APT exploited unpatched Atlassian and Oracle servers to breach 250+ telecom servers globally, stealing call records.

2021-01-01
🇶🇦 Qatar

Al Jazeera: 36 Journalists Hacked with NSO Pegasus Spyware

Zero-click iMessage exploits deployed by Saudi- and UAE-linked operators compromised 36 Al Jazeera journalists' iPhones. Citizen Lab identified the KISMET.

2020-12-01
🇯🇴 Jordan

Jordan ISPs: Five Providers Caught Collecting Intrusive User Data

Business and Human Rights Centre investigation found five Jordanian ISPs, including Orange, collecting intrusive user data beyond service needs without.

2020-01-01
🇧🇭 Bahrain PDPL

BeAware Bahrain: COVID App Mass Surveillance & Public Data Exposure

Amnesty rated BeAware among the world's most dangerous contact-tracing apps, conducting live GPS tracking linked to national IDs and broadcasting.

2020-06-01
🇶🇦 Qatar

Ehteraz COVID App: 1M+ Users' Health Data at Risk

Amnesty discovered a critical API flaw in Qatar's mandatory Ehteraz contact-tracing app that exposed health data of 1M+ users via predictable QID enumeration.

2020-05-01
🇧🇭 Bahrain PDPL

BAPCO: Iranian Dustman Wiper Malware Destroys Oil Company Systems

Iran-linked APT34 deployed Dustman wiper malware against Bahrain's national oil company BAPCO, gaining initial access months earlier via a compromised VPN.

2019-12-01
🇧🇭 Bahrain PDPL

Bahrain Electricity & Water Authority: Iranian ICS Intrusion

Iranian state actors gained command-and-control of Bahrain EWA's industrial control systems managing electricity and water for the kingdom alongside NSA.

2019-07-01
🇱🇧 Lebanon

DNSpionage: Lebanese Finance Ministry DNS Hijacked

Iranian APT hijacked DNS records for Lebanon's Ministry of Finance and Middle East Airlines, intercepting email credentials and VPN logins.

2018-11-01
🇱🇧 Lebanon

Krypton Security: 'Largest Hack in Lebanon's History'

Cybersecurity CEO Khalil Sehnaoui breached Ogero Telecom, government ministries, banks, and airport systems in what was called Lebanon's largest hack.

2018-07-01
🇱🇧 Lebanon

Dark Caracal: Lebanese Intelligence's Global Spyware Campaign

EFF and Lookout exposed a Lebanese intelligence espionage campaign run from a GDGS building in Beirut, targeting thousands of victims across 21+ countries.

2018-01-01
🇺🇸 USA

Anthem: 78.8M Patient Records Stolen by Chinese APT

Chinese state-sponsored hackers operated undetected for 11 months inside the second-largest US health insurer, stealing 78.8M patient records.

2015-02-01
🇶🇦 Qatar

RasGas: Shamoon Wiper Malware Takes LNG Giant Offline

Iran-linked Shamoon malware wiped corporate systems at Qatar's RasGas LNG producer, two weeks after devastating Saudi Aramco's 35,000 workstations.

2012-08-01
🇱🇧 Lebanon

Gauss: Nation-State Banking Trojan Targeting 6 Lebanese Banks

A Stuxnet-related Gauss trojan targeted six major Lebanese banks including Bank of Beirut and BlomBank, stealing online banking credentials from 2,500.

2012-08-01
🇪🇬 Egypt

Telecom Egypt: State DPI Traffic Hijacking via Sandvine

Citizen Lab discovered Egyptian ISPs using Sandvine PacketLogic deep packet inspection to hijack subscriber traffic for ad injection and cryptocurrency.

2017-01-01
🇴🇲 Oman PDPL

Oman Administrative Court: APT34 (OilRig) Espionage Breach

Iranian APT34 penetrated Oman's Administrative Court as part of a long-running espionage campaign exposed when Lab Dookhtegan leaked the group's tools in 2019.

2016-01-01
🇯🇴 Jordan

Pegasus in Jordan: 35+ Journalists and Activists Targeted with NSO Spyware

Citizen Lab and Access Now documented systematic Pegasus deployment against 35+ journalists, lawyers, and activists in Jordan over four years.

2019-01-01
🇰🇼 Kuwait

xHunt: Targeted Campaign Against Kuwait's Shipping and Transport Sector

Palo Alto Unit 42 uncovered a multi-year espionage campaign using custom anime-named backdoors to target Kuwait's shipping sector and government entities.

2019-01-01
🇰🇼 Kuwait

Chafer APT39: Iranian Espionage Campaign Targets Kuwait Government

Iran-linked APT39 (Chafer) conducted a multi-year espionage campaign against Kuwaiti government agencies, targeting diplomatic, military.

2018-01-01