On April 8, 2026, Access Now's Digital Security Helpline published a forensic analysis of a cross-border spear-phishing campaign that targeted Egyptian journalist and former political prisoner Mostafa Al-A'sar and Egyptian journalist and former MP Ahmed Eltantawy, who launched a 2023 presidential campaign, in October 2023 and January 2024. Access Now updated the accompanying web summary on April 22, 2026; the forensic report itself carries a document modification date of April 7, 2026. A parallel investigation published the same day by the Lebanese digital rights organization SMEX documented a third case: a high-profile Lebanese journalist, who has not been named, whose Apple account was successfully compromised on May 19, 2025. SMEX measured the interval between the victim submitting a password and full account takeover at approximately 30 seconds, including real-time interception of the two-factor authentication code.
The mobile security company Lookout, which analyzed the infrastructure and malware alongside Access Now, published its own assessment the same day: the operation is most likely a hack-for-hire campaign with ties to BITTER APT, held at moderate confidence. That is the intelligence value of this case. Mercenary surveillance normally surfaces as a state buying a product from a vendor and pointing it at its own citizens. Here there is a contractor in the middle, and Lookout assesses that unknown entities likely hired it. The capability is documented in detail. The customer is not.
KEY FACTS
- WhatMulti-year spear-phishing and Android spyware campaign against MENA civil society, targeting Apple, Google and Microsoft accounts through impersonation of trusted services and contacts.
- WhoMostafa Al-A'sar and Ahmed Eltantawy (Egypt), plus one unnamed high-profile Lebanese journalist. Lookout assesses the wider campaign also likely reached targets in Bahrain, the UAE, Saudi Arabia, the United Kingdom, and Egyptian and Bahraini government entities.
- HowSpear-phishing via iMessage, WhatsApp, LinkedIn and email, using credential-harvesting pages, live 2FA relay, Google OAuth consent phishing, and Signal "Link Device" QR abuse. Android targets were steered to the ProSpy spyware.
- DataFor the Lebanese journalist, Apple account credentials and 2FA codes were captured and a virtual device was added to the account. The attacks on Al-A'sar and Eltantawy did not result in account compromise.
- ActorAccess Now and Lookout describe a hack-for-hire group. Lookout attributes ties to BITTER APT (also tracked as T-APT-17 and, per SMEX, APT-C-08) at moderate confidence. Access Now's own report stops at "a hack-for-hire threat group with ties to Asia."
- ImpactNo financial loss reported. The exposure is to journalistic sources, family members and associates in jurisdictions where those contacts face arrest.
WHAT HAPPENED
On October 18, 2023, Al-A'sar, then in Lebanon, received an iMessage from an account posing as Apple support, instructing him to verify a phone number tied to his account. The message showed the sender already knew the phone number and email address on the account. After repeated attempts, Al-A'sar submitted his credentials. Apple then prompted his trusted devices to approve a new sign-in, and the notification placed that sign-in in Cairo while he was physically in Lebanon. The location mismatch is what stopped the attack.
Access Now records that he refrained from engaging further and sought support.
Days later a second link arrived. Because Al-A'sar was on a call with the Helpline at the time, analysts scanned it live. It resolved to a page requesting his 2FA code, stating that the code had been sent to a number ending in the same two digits as his own. The attacker already held the password and needed only the second factor to complete the earlier sign-in. The domain com-en-uk[.]co had been registered on July 26, 2023, but passive DNS shows the subdomain signin-apple[.]com-en-uk[.]co first resolved on the day of the attack, indicating infrastructure stood up for this specific target.
Eltantawy was hit in the same window, within hours, using near-identical links that differed only in a trailing identifier. A second round followed in January 2024 from a different impersonation account and a different domain. Those URLs were disabled before the Helpline could examine them. Access Now's web summary states that the attackers failed to lure Eltantawy into taking action and did not succeed in compromising either Egyptian target's account.
The timing around Eltantawy is documented in the Access Now report. He had already been targeted with Cytrox's Predator spyware in September 2021 and again between May and September 2023, according to The Citizen Lab, which attributed that earlier operation to the Egyptian government. The first attempt on his Apple account came in October 2023, one month after Citizen Lab published and Apple shipped an update closing the vulnerability Predator had exploited.
Eltantawy was imprisoned in 2024 and barred from standing for election for five years; the International Commission of Jurists called the conviction politically motivated.
In parallel, on January 6, 2024, a LinkedIn profile using the name "Haifa Kareem" approached Al-A'sar with a job offer. He supplied a phone number and email. On January 24 an email from haifakareem657@gmail[.]com sent what appeared to be a Zoom interview link, shortened through rebrand.ly. He did not click it and referred it to the Helpline, which found a Google OAuth 2.0 consent phishing page. Rather than spoof a login screen, this attack asks the user to grant an attacker-controlled application permission to their real Google account.
The resulting token would have persisted until the victim revoked app access or changed the password. Shared hosting and a common JARM hash tied this infrastructure back to the October 2023 Apple attacks.
The Lebanese case ran in May 2025. SMEX documented a first attack on May 19, 2025 via Apple Messages that compromised the journalist's Apple account and resulted in a virtual device being attached to it. A second wave on May 21 and 22, delivered over WhatsApp, failed, but SMEX captured a complete exfiltration of username, password and 2FA codes and timed the takeover window at roughly 30 seconds. Access Now assesses the same actor is likely behind all three cases based on shared impersonation tactics, a common fingerprint and reused infrastructure.
THREAT ACTOR
The attribution here has three distinct layers and they should not be collapsed. Access Now's forensic report describes "a likely Advanced Persistent Threat" and reports that Lookout "independently assesses that the campaigns against these two individuals may be linked to a hack-for-hire threat group with ties to Asia." Access Now does not name a group anywhere in its report. Its web summary adds that there is not enough information to confidently conclude which government or governments may be behind the attacks.
Lookout's companion report, published the same day and linked from the Access Now report, goes further. " SMEX records the aliases as BITTER, APT-C-08 and T-APT-17.
Lookout's evidentiary chain runs through infrastructure, not code alone. The ProSpy distribution domain com-ae[.]net was linked to BITTER by the open-source Maltrail project, citing a FOFA fingerprint query built on JARM hash, page title, ASN and response length.
That query connects it to youtubepremiumapp[.]com, a 2022 command-and-control domain for the Dracarys Android malware that Meta attributed to BITTER in 2022. Lookout then found structural similarities between the Dracarys and ProSpy codebases despite different languages: parallel worker-class naming, numbered C2 command sets, and endpoint prefixes of "r3" versus "v3". Lookout notes BITTER is assessed as having suspected ties to the Indian government, citing research by Proofpoint and Threatray.
Lookout is equally clear about what does not fit. " That mismatch is precisely why Lookout reads the operation as contract work rather than direct BITTER tasking, pointing to prior overlap between BITTER's BitterDawn malware and the known hack-for-hire actor Bahamut, and to Rebsec, an Indian corporate espionage firm staffed by former Appin and Belltrox personnel that Google documented in 2022 targeting Saudi Arabia, Bahrain and the UAE with similar phishing domains.
WHAT WAS EXPOSED
- Confirmed compromise, Lebanon: Apple account credentials and two-factor authentication codes for a high-profile Lebanese journalist, with a virtual device added to the account. An Apple account compromise of this kind reaches iCloud backups, contacts, stored files and device sync.
- Attempted, Egypt: Al-A'sar's Apple password was submitted to a phishing page but the sign-in was not completed. No successful compromise of either Egyptian target's account is reported.
- ProSpy spyware capability, where installed: document, image, audio, video, archive and backup files, recently modified files, SMS messages, phone contacts, and device hardware and software information.
- Second-order exposure: Access Now states that a successful compromise would have exposed the targets' families, associates, colleagues and journalistic sources to persecution. For exiled journalists this is the operative harm, and it does not require the primary target to remain in-country.
TECHNICAL FAILURE CHAIN
The attackers already possessed the phone number and email address tied to Al-A'sar's Apple account before first contact, which made the impersonation credible. Personal identifiers are not secrets and cannot carry authentication weight.
Apple's push and code-based 2FA held only because a human noticed a geographic anomaly. In the Lebanese case the same control failed: SMEX documented real-time relay of the 2FA code and a takeover window of roughly 30 seconds. Any second factor a user can read and retype can be relayed by a live adversary-in-the-middle.
The January 2024 Google attack required no password theft at all. It requested authorization for an attacker-controlled application through Google's own legitimate consent flow, producing a token that survives until the user explicitly revokes third-party app access.
Lookout documented Signal "Link Device" QR phishing, complete with Arabic instructions. Linking grants an attacker a persistent parallel session on an end-to-end encrypted account without breaking any cryptography.
ProSpy reached Android devices as APKs from single-page lookalike sites impersonating Signal, ToTok and Botim, using package names typosquatting the genuine apps, including org.thoghtcrime.securesms against Signal's real org.thoughtcrime.securesms.
The actor kept one domain per IP, used short TLD-like domain strings with heavy subdomain diversification, randomized HTML variable and class names, and used JavaScript to block source inspection. The two research teams describe domain lifetime differently, and both observations are useful to a defender. Access Now found that the domains it examined were disabled shortly after use, available only around the time of the attack. Lookout reports the opposite at the layer above: first-level domains stayed active for months, with individual subdomains impersonating specific services created on the fly for specific victims. Read together, the long-lived base domain is the durable hunting artifact and the per-victim subdomain is the disposable part.
INDICATORS OF COMPROMISE
- hxxps[://]signin-apple[.]com-en-uk[.]co/sjhui/?HT520413 (Al-A'sar, October 2023)
- hxxps[://]signin-apple[.]com-en-uk[.]co/sjhui/?HT213054 (Eltantawy, October 2023)
- hxxps[://]review-appleid[.]en-ae[.]io/GR0hGV/?HT125340 (Eltantawy, January 2024)
- hxxps[://]rebrand[.]ly/Zoom-us-join-interview (Google OAuth consent phishing, January 2024)
- hxxps[://]id-apple[.]com-en[.]io/Txk62i/?HT584528 (Lebanese journalist, May 2025)
- 45[.]144[.]155[.]158 (AS9028, OHOST LLC), com-en-uk[.]co
- 109[.]236[.]85[.]63 and 185[.]2[.]83[.]5 (AS49981, WorldStream B.V.), en-account[.]info and review-ar[.]co
- 93[.]174[.]90[.]20 (AS202425, IP Volume Inc), en-ae[.]io
- 85[.]206[.]166[.]23 (AS61272), com-en[.]io
- 185[.]225[.]114[.]70, sgnl-app[.]info, first resolved March 11, 2025
- secure[.]appleuser[at]icloud[.]com, review[.]support[at]icloud[.]com, appleid[.]review[at]messages.app, appleid[.]review[at]icloud[.]com
- LinkedIn persona "Haifa Kareem" and email haifakareem657@gmail[.]com
- FamilyProSpy (ESET separately named a related family ToSpy; Lookout treats both as ProSpy)
- SHA-256:
42f28501f3e6be38c0ce4ff2a5bfa2dfe3c56f99ed81804de54cba3bc26a5025, filename signal_encyption_plugin.apk - Distribution URLhxxps[://]encryption-plug-in-signal[.]com-ae[.]net/signal_encyption_plugin.apk
- Redirect chainhxxp[://]encryption[.]sgnlapp[.]info/ to hxxps[://]signal[.]ct[.]ws/?i=1 to the APK
- Malicious package namesorg.thoghtcrime.securesms, ae.totok.chat, al.totok.chat, im.thebot.mesenger, the.messenger.bot, com.chat.connect, com.chatbot.botim
- sgnlapp[.]info, treasuresland[.]cc, relaxmode[.]org, track-portal[.]co, totokapp[.]info, totok-pro[.]io, regularsports[.]org, clubline[.]cc
- The eight above are the union of two lists that do not agree. Lookout's prose states the samples used six C2 servers, then enumerates seven, and its IOC appendix lists a different seven. Every domain in both lists is reproduced here.
- C2 endpoints use a /v3/ prefix, with commands numbered 0 through 9
- totok-pro[.]ai-ae[.]io, totok-pro[.]ae, encryption-plug-in-signal[.]com-ae[.]net, botim-app[.]pro, totok-pro[.]io, join-secure-call[.]ai-ae[.]io
Access Now published a further appendix of more than 40 first-level domains and their subdomains. Access Now states that it withheld part of the fingerprint, the complete indicator set and its detection logic in order to preserve ongoing monitoring capability.
REGULATORY EXPOSURE
This case does not fit the standard breach-liability model, and that is the point worth making to a compliance audience. There is no negligent data controller here. The victims are individuals, the operator is a commercial contractor, and the party with the strongest legal exposure is a customer nobody has identified. Named frameworks apply unevenly.
- Egypt, Data Protection Law No. 151/2020: the targets are Egyptian nationals, and Access Now records an unauthorized sign-in attempt originating from Cairo. Access Now does not attribute the operation to any government. Where a state is the suspected beneficiary of surveillance, domestic data protection statutes provide no practical remedy to the targeted individual.
- Lebanon: the confirmed compromise occurred against a Lebanese journalist. No enforcement action has been reported.
- Canada: Al-A'sar has relocated to Canada, though the October 2023 attacks occurred while he was in Lebanon. Residence establishes a nexus for any future Canadian criminal or privacy process.
- EU GDPR and UK GDPR: engaged only where targets are in the EU or UK. Lookout assesses the wider campaign likely reached UK targets. Articles 5(1)(f) and 32 govern the confidentiality and security obligations of any EU or UK provider drawn in, not the attacker.
- Gulf frameworks, Saudi PDPL (fines to SAR 5 million), UAE PDPL (which sets no statutory fine figure and defers administrative penalties to a Cabinet decision) and Bahrain PDPL: Lookout's lure inventory includes Bahrain's Ministry of Foreign Affairs, National Communication Center, Prime Minister's Office and Defence Force, plus Egypt's Ministry of Finance, and ESET assessed ProSpy as primarily targeting UAE users. These regimes regulate controllers, not foreign contractors, and none has announced action.
The enforcement gap is structural. Data protection law binds organizations that hold data. It does not reach a contractor selling intrusion, and it does not reach the buyer. No regulator in any implicated jurisdiction has opened a public proceeding in this matter.
INTELLIGENCE GAPS
This is the central unknown. Lookout assesses that unknown entities likely hired the operator, and Access Now's web summary says there is not enough information to confidently conclude which government or governments may be behind the attacks. Documented capability plus an unknown buyer is the defining feature of this case, and nothing in the published material closes it.
Access Now's report never names BITTER and stops at "a hack-for-hire threat group with ties to Asia." The naming is Lookout's, at its own stated moderate confidence, resting substantially on a third-party FOFA fingerprint and a 2022 Dracarys infrastructure overlap. Reporting that treats BITTER as a settled finding of the forensic investigation overstates both reports.
Lookout writes that it does not know whether this represents an expansion of BITTER's role or overlap between BITTER and an unknown hack-for-hire group.
Access Now's web summary describes spyware with the "potential ability" to access geolocation and to enable device microphones and cameras. Neither the capability table in Access Now's own report nor Lookout's enumerated C2 command set (0 through 9) includes microphone, camera or geolocation collection. Those documented commands cover files, SMS and contacts only. The stronger capability claim is not supported by the technical detail published alongside it.
ProSpy was found through infrastructure pivoting, not recovered from these victims' devices. The link between the phishing campaign and the malware is infrastructure-based.
Access Now notes the January 2024 URLs were disabled before analysts could examine them, limiting findings.
Lookout states it acquired 11 ProSpy samples and its IOC appendix lists 11 SHA-1 hashes, while its sample table contains 14 entries spanning August 7, 2024 to March 15, 2026.
Lookout describes the operation as running since at least 2022, while the documented phishing infrastructure is traced to 2023. Earlier activity is asserted but not detailed publicly.
ZERO|TOLERANCE Advisory
FIDO2 security keys or passkeys are the specific control that defeats the failure documented here. A relayed 30-second takeover works against codes and push prompts because they can be read and retyped. Origin-bound credentials cannot be relayed to a lookalike domain. Access Now's own recommendation is the same: security keys or passkeys rather than SMS or app codes.
Google Advanced Protection, Apple Lockdown Mode, Microsoft AccountGuard, Proton Sentinel and WhatsApp strict account settings raise the technical bar and flag the account to the provider as a likely target. For journalists and opposition figures this is a baseline, not a hardening extra.
The Google attack never needed a password. Review connected applications on Google and Microsoft accounts, revoke anything unrecognized, and for organizational tenants restrict third-party app access to admin-approved applications only. A token granted once persists until someone removes it.
Signal, WhatsApp and Telegram all support device linking, and both Lookout and SMEX documented abuse of it, including a virtual device added to the compromised Apple account. Make a periodic review of linked devices and active sessions a standing routine, and treat an unrecognized entry as a full compromise.
Every ProSpy sample arrived as an APK from a lookalike site posing as an update or add-on for Signal, ToTok or Botim. No legitimate messenger distributes an encryption plugin by direct download. Install only from official stores and verify package names.
The one attack stopped in Egypt was stopped because the target read the city on the notification and knew he was in a different country. Teach at-risk users to read the location and device fields before approving, and to report rather than simply dismiss.
The realistic loss in these cases is the contact list and the source correspondence, not the mailbox. Compartmentalize source material away from cloud-synced personal accounts, and hold a pre-agreed notification path to sources in case an account is compromised.
SOURCES
- Access Now, "Espionage for repression: forensic analysis of a cross-border hack-for-hire campaign targeting civil society in MENA," April 2026: https://www.accessnow.org/wp-content/uploads/2026/04/Espionage-for-repression-forensic-analysis-of-a-cross-border-hack-for-hire-campaign-targeting-civil-society-in-MENA-2026.pdf
- Access Now, "Espionage for repression: hack-for-hire attacks target MENA civil society," published April 8, 2026, updated April 22, 2026: https://www.accessnow.org/mena-phishing-2026/
- Lookout Threat Intelligence, "Beyond BITTER: MENA Civil Society Targeted in Hack-For-Hire Operation Linked to BITTER APT," Alemdar Islamoglu and Justin Albrecht, April 8, 2026: https://www.lookout.com/threat-intelligence/article/bitter-hack-for-hire
- SMEX, "Rotten Apple: An Invasive Threat Actor Targeting Civil Society in Lebanon," Ragheb Ghandour, April 8, 2026: https://smex.org/smex-may2025
- CyberScoop, "Hack-for-hire spyware campaign targets journalists in Middle East, North Africa," April 8, 2026: https://cyberscoop.com/hack-for-hire-spyware-campaign-targets-journalists-in-middle-east-north-africa/
- Committee to Protect Journalists, "Egyptian, Lebanese journalists targeted in cyberattacks," April 8, 2026: https://cpj.org/2026/04/egyptian-lebanese-journalists-targeted-in-cyber-attacks/
- The Citizen Lab, "Predator in the Wires: Ahmed Eltantawy Targeted with Predator Spyware After Announcing Presidential Ambitions," September 2023: https://citizenlab.ca/2023/09/predator-in-the-wires-ahmed-eltantawy-targeted-with-predator-spyware-after-announcing-presidential-ambitions/
- ESET, "New spyware campaigns target privacy-conscious Android users in the UAE," October 2025: https://www.welivesecurity.com/en/eset-research/new-spyware-campaigns-target-privacy-conscious-android-users-uae/