Thursday Sep 18, 2025
HE
NEWSLETTER
www.israelhayom.com
  • Home
  • News
    • Israel
    • Israel at War
    • Middle East
    • United States
  • Opinions
  • Jewish World
    • Archaeology
    • Antisemitism
  • Lifestyle
    • Food
    • Travel
    • Fashion
    • Culture
  • Magazine
    • Feature
    • Analysis
    • Explainer
  • In Memoriam
www.israelhayom.com
  • Home
  • News
    • Israel
    • Israel at War
    • Middle East
    • United States
  • Opinions
  • Jewish World
    • Archaeology
    • Antisemitism
  • Lifestyle
    • Food
    • Travel
    • Fashion
    • Culture
  • Magazine
    • Feature
    • Analysis
    • Explainer
  • In Memoriam
www.israelhayom.com
Home News Middle East

Gaza hackers used phishing attacks to target individuals, corporations in 39 countries

Kaspersky Lab cybersecurity firm: Gaza Cybergang shows lack of infrastructure, advanced tools no impediment to success • We expect damage caused by Gaza Cybergang to intensify and cyberattacks to extend into other regions with links to Palestinian issues," he said.

by 
Published on  04-11-2019 08:06
Last modified: 05-26-2019 13:09
Gaza hackers used phishing attacks to target individuals, corporations in 39 countriesReuters

The Arabic-speaking Gaza Cybergang has targeted high-profile individuals and corporations across the Middle East and North Africa | Photo: Reuters

Share on FacebookShare on Twitter

Kaspersky Lab published its findings on the a cyber espionage operation known as SneakyPastes, which targeted individuals and organizations with Middle-Eastern political interests across 39 countries worldwide. In 2018, the campaign made use of disposable email addresses to spread the virus through phishing attacks before downloading the malware in chained stages using multiple free sites. Since Kaspersky shared its findings with law enforcement, a significant portion of the attack infrastructure has been taken down.

The Arabic-speaking Gaza Cybergang responsible for the campaign is a politically motivated collective of interrelated groups actively targeting the Middle East and North Africa, with a particular focus on the Palestinian territories. Kaspersky Lab has identified at least three groups within the gang. Although these groups share similar aims and targets – cyberespionage related to Middle Eastern political interests, the methods they employed vary in sophistication.

The groups include the more advanced Operation Parliament and Desert Falcons as well as the less sophisticated MoleRats, which was responsible for launching SneakyPastes in the spring of 2018.

SneakyPastes began with politically themed phishing attacks. In order to avoid detection and hide the location of the command and control server, additional malware was downloaded to victim devices in chained stages using a number of free sites including Pastebin and Github. The various malicious implants used PowerShell, VBS, JS and dotnet to secure resilience and persistence within infected systems. The final stage of intrusion was a Remote Access Trojan, which made contact with the command and control server and then gathered, compressed, encrypted and uploaded a wide range of stolen documents and spreadsheets to the server. The name SneakyPastes derives from the attackers' heavy use of paste sites to gradually sneak the RAT onto victim systems.

The SneakyPastes operation was at its most active between April and Nov. 2018, focusing on a small list of targets that comprised diplomatic and government entities, nongovernmental organizations and media outlets. Around 240 high-profile individuals and corporations across 39 countries appear to have fallen victim to the operation, with the majority situated in the Palestinian territories, Jordan, Israel and Lebanon. Victims included embassies, government entities, media outlets, journalists, activists and political parties, as well as organizations in the education, banking, healthcare sectors.

"The discovery of Desert Falcons in 2015 marked a turning point in the threat landscape as it was then the first known fully Arabic speaking APT," said Amin Hasbini, head of Kaspersky's Middle East Research Center global research and analysis team.

"We now know that its parent, Gaza Cybergang, has been actively targeting Middle Eastern interests since 2012, initially relying most on the activities of a fairly unsophisticated but relentless team. … It shows that lack of infrastructure and advanced tools are no impediment to success. We expect the damage exerted by all three Gaza Cybergang groups to intensify and the attacks to extend into other regions that are also linked to Palestinian issues," he said.

Tags: Gazahackersphishing

Related Posts

Syrian president to Netanyahu: 'Our country is indivisible'Haim Goldberg/Flash90/AFP

Syrian president: Talks with Israel may yield results in days

by ILH Staff

Ahmad al-Sharaa said a security agreement with Israel was essential and must respect Syria’s airspace and territorial integrity. He argued...

Protests, clashes, and chants of 'Death to Khamenei' in IranNone

Protests, clashes, and chants of 'Death to Khamenei' in Iran

by Neta Bar

Iran’s opposition marked the third anniversary of the killing of Mahsa Amini, who died after being beaten by the regime’s...

Israel arming thousands of Druze fighters in southern SyriaReuters

Israel arming thousands of Druze fighters in southern Syria

by ILH Staff

Under US pressure, Syria accelerates talks with Israel on a deal it hopes will secure the return of territory recently...

Menu

Analysis 

Archaeology

Blogpost

Business & Finance

Culture

Exclusive

Explainer

Environment

 

Features

Health

In Brief

Jewish World

Judea and Samaria

Lifestyle

Cyber & Internet

Sports

 

Diplomacy 

Iran & The Gulf

Gaza Strip

Politics

Shopping

Terms of use

Privacy Policy

Submissions

Contact Us

About Us

The first issue of Israel Hayom appeared on July 30, 2007. Israel Hayom was founded on the belief that the Israeli public deserves better, more balanced and more accurate journalism. Journalism that speaks, not shouts. Journalism of a different kind. And free of charge.

All rights reserved to Israel Hayom

Hosted by sPD.co.il

  • Home
  • News
    • Israel at War
    • Israel
    • United States
    • Middle East
    • Sports
  • Opinions
  • Jewish World
    • Archaeology
    • Antisemitism
  • Lifestyle
    • Food
    • Travel
    • Fashion
    • Culture
  • Magazine
    • Feature
    • Analysis
    • Explainer
    • Environment & Wildlife
    • Health & Wellness
  • In Memoriam
  • Subscribe to Newsletter
  • Submit your opinion
  • Terms and conditions

All rights reserved to Israel Hayom

Hosted by sPD.co.il

Newsletter

[contact-form-7 id=”508379″ html_id=”isrh_form_Newsletter_en” title=”newsletter_subscribe”]

  • Home
  • News
    • Israel at War
    • Israel
    • United States
    • Middle East
    • Sports
  • Opinions
  • Jewish World
    • Archaeology
    • Antisemitism
  • Lifestyle
    • Food
    • Travel
    • Fashion
    • Culture
  • Magazine
    • Feature
    • Analysis
    • Explainer
    • Environment & Wildlife
    • Health & Wellness
  • In Memoriam
  • Subscribe to Newsletter
  • Submit your opinion
  • Terms and conditions

All rights reserved to Israel Hayom

Hosted by sPD.co.il