Tech Features
In the Crosshairs of APT Groups: A Feline Eight-Step Kill Chain
By Alexander Badaev, Information security threat researcher, Positive Technologies Expert Security Center and Yana Avezova, Senior Research Analyst, Positive Technologies
In cybersecurity, “vulnerability” typically evokes concern. One actively searches for it and patches it up to build robust defenses against potential attacks. Picture a carefully orchestrated robbery, where a group of skilled criminals thoroughly examines a building’s structure, spots vulnerabilities, and crafts a step-by-step plan to breach security and steal valuables. This analogy perfectly describes the modus operandi of cybercriminals, with the “kill chain” acting as their detailed blueprint.
In a recent study, analysts from Positive Technologies gathered information on 16 hacker groups attacking the Middle East analyzing their techniques and tactics. It is worth noting that most of the threats in Middle Eastern countries come from groups believed to be linked to Iran—groups such as APT35/Charming Kitten or APT34/Helix Kitten. Let’s see how APT groups operate, how they initiate attacks, and how they develop them toward their intended targets.
Step 1: The Genesis of Intrusion (Attack preparation)

It all begins with meticulous planning and reconnaissance. APT groups leave no stone unturned in their quest for vulnerable targets. They compile lists of public systems with known vulnerabilities and gather employee information. For instance, groups like APT35 aka Charming Kitten known for targeting mainly Saudi Arabia and Israel, gather information about employees of target organizations, including mobile phone numbers, which they leverage for nefarious purposes like sending malicious links disguised as legitimate messages. After reconnaissance, they prepare tools for attacks, such as registering fake domains and creating email or social media accounts for spear phishing. For example, APT35 registers accounts on LinkedIn and other social networks to contact victims, persuading them through messages and voice calls to open malicious links.
Step 2: The Initial Access: Gaining a Foothold

Once armed with intelligence, cybercriminals proceed to gain initial access to their target’s network. Phishing campaigns, often masquerading as legitimate emails, serve as the primary means of infiltration. An example is the Desert Falcons group, observed spreading their malware through pornographic phishing. Notably, some groups go beyond traditional email phishing, utilizing social networks and messaging platforms to lure unsuspecting victims, as seen with APT35, Bahamut, Dark Caracal, and OilRig. Moreover, techniques like the watering hole method, where attackers compromise trusted websites frequented by their targets, further highlight the sophistication of these operations. Additionally, attackers exploit vulnerabilities in resources accessible on the internet to gain access to internal infrastructure. For example, APT35 and Moses Staff exploited ProxyShell vulnerabilities on Microsoft Exchange servers.
Step 3: Establishing Persistence: The Art of Concealment

Having breached the perimeter, APT groups strive to establish a foothold within the victim’s infrastructure, ensuring prolonged access and control. This involves deploying techniques such as task scheduling, as seen in the campaign against the UAE government by the OilRig group, which created a scheduled task triggering malicious software every five minutes. Additionally, many malicious actors set up malware autostart, like the Bahamut group creating LNK files in the startup folder or Dark Caracal’s Bandook trojan. Some APT groups, such as APT33, Mustang Panda, and Stealth Falcon, establish themselves in victim infrastructures by creating subscriptions to WMI events for event-triggered execution. Furthermore, attackers exploit vulnerabilities in server applications to install malicious components like web shells, which provide a backdoor for remote access and data exfiltration.
Step 4: Unraveling the Network: Internal Reconnaissance

After breaking in, APT groups don’t just sit there. They explore the system like a thief casing a house to find valuables and escape routes. This digital reconnaissance involves several steps. First, they perform an inventory check, identifying the computer’s operating system, installed programs, and updates, like figuring out a house’s security measures. For instance, APT35 might use a simple command to see if the computer is a powerful 64-bit system, capable of handling more complex tasks. Second, they map the network layout, akin to identifying valuable items and escape routes. APT groups might use basic tools like “ipconfig” and “arp” (like Mustang Panda) to see how devices are connected and communicate. They also search for user accounts and activity levels, understanding who lives in the house (figuratively) and their routines. Malicious tools, like the Caterpillar web shell used by Volatile Cedar, can list all usernames on the system. Examining running programs is another tactic, like checking for security guards. Built-in commands like “tasklist” (used by APT15 and OilRig) can reveal a list of programs currently running.
Finally, APT groups might deploy programs that hunt for secrets hidden within files and folders, like searching for hidden safes or documents. The MuddyWater group, for example, used malware that specifically checked for directories or files containing keywords related to antivirus software. By gathering this comprehensive intel, APT groups can craft targeted attacks, steal sensitive data like financial records or personal information, or exploit vulnerabilities in the system to cause even more damage.
Step 5: Harvesting Credentials: Unlocking the Vault

Access to privileged credentials is the holy grail for cyber attackers, granting them unrestricted access to critical systems and data. One common tactic is “credential dumping,” where tools like Mimikatz (used by APT15, APT33, and others) snatch passwords directly from a system’s memory, similar to stealing a key left under a doormat. Keyloggers, used by APT35 and Bahamut for example, acts like a hidden camera, silently recording keystrokes to capture usernames and passwords as victims type them in.
These stolen credentials grant access to even more sensitive areas. APT groups also exploit weaknesses in how passwords are stored. For instance, some target the Windows Credential Manager (like stealing a notepad with written down passwords). Brute-force attacks, trying millions of combinations, can crack weak passwords. Even encrypted passwords can be vulnerable if attackers have specialized tools. By employing these tactics, APT groups bypass initial security and access sensitive information or critical systems.
Step 6: Data Extraction: The Quest for Valuable Assets

Once inside, APT groups aren’t shy about snooping around. They leverage stolen credentials to capture screenshots, record audio and video (like hidden cameras and microphones), or directly steal sensitive files and databases. For instance, the Dark Caracal group employed Bandook malware, which can capture video from webcams and audio from microphones. This stolen data becomes their loot.
To ensure a smooth getaway, APT groups often employ encryption and archiving techniques. Imagine them hiding their stolen treasure chests—the Mustang Panda group, for example, encrypted files with RC4 and compressed them with password protection before shipping them out. This makes it difficult for defenders to identify suspicious activity amongst regular network traffic.
Step 7: Communication Channels: Establishing Control

APT groups rely on hidden communication channels with command-and-control (C2) servers to control infected machines and exfiltrate data. They employ various tactics to blend in with regular network traffic. This includes using common protocols (like IRC or DNS requests disguised as legitimate web traffic) and encrypting communication for further stealth.
However, some groups take it a step further. For instance, OilRig used compromised email servers to send control messages hidden within emails and then deleted them, making their C2 channel nearly invisible. These innovative techniques make it difficult for security measures to detect malicious activity, highlighting the importance of staying informed about evolving APT tactics.
Step 8: Covering Tracks: Erasing Digital Footprints

As the operation ends, APT groups meticulously cover their tracks to evade detection and prolong their presence in the compromised environment. Techniques like file obfuscation, masquerading, and indicator removal are employed to erase digital footprints and thwart forensic investigations. For example, the Bahamut group used icons mimicking Microsoft Office files to disguise malware, and the OilRig group used .doc file extensions to make malware appear as office documents. The Moses Staff group named their StrifeWater malware calc.exe to make it look like a legitimate calculator program.
To further bypass defenses, attackers often proxy the execution of malicious commands using files signed with trusted digital certificates. The APT35 group used the rundll32.exe file to execute the MiniDump function from the comsvcs.dll system library when dumping the LSASS process memory. Meanwhile, the Dark Caracal group employed a Microsoft Compiled HTML Help file to download and execute malicious files. Many APT groups also remove signs of their activity by clearing event logs and network connection histories, and changing timestamps. For instance, APT35 deleted mailbox export requests from compromised Microsoft Exchange servers. This meticulous cleaning makes it much more difficult for cybersecurity professionals to conduct post-incident investigations, as attackers often remove their arsenal of software from compromised devices after achieving their goals.
Conclusion: A Call to Vigilance
In a nutshell, the threat landscape in the Middle East is fraught with peril, as APT groups continue to refine their tactics and techniques to evade detection and wreak havoc on unsuspecting organizations. By understanding the anatomy of cyber intrusions and remaining vigilant against emerging threats, organizations can bolster their defenses and mitigate the risks posed by these sophisticated adversaries. Together, let us remain steadfast in our commitment to safeguarding the digital frontier against cyber threats.
Tech Features
The Financial Sector Facing Its Black Swan: How AI Agents Are Redefining the Industry
By Julio de Salvo, Chief Solution Officer for MENA & APAC at Globant
For decades, the financial industry has managed to replace banknotes and coins with “invisible” assets through different technological implementations. However, innovation in the sector has generally moved at a slow pace when dealing with something as sensitive as people’s finances. In 2026, the black swan is beginning to emerge: the first steps of AI agents that will redefine the industry (as they will many others). The financial black swan is not a crisis: it is a huge change. Across the Middle East and Africa, where a convergence of government-backed modernization agendas, digitally native consumers, and institutional ambition is accelerating the timeline for transformation.
The first step has been the use of Gen AI without the customer perceiving it. Coding, fraud prevention, phishing detection, and credit assessment are some of its tasks. But it is now beginning to become a tool for managing users’ finances. In the MENA region, this shift is already visible at the institutional level. Across the 25 MEA banks benchmarked by the Evident AI Index (June 2026), the established leaders are no longer running pilots, they are directing investment toward high-friction processes where AI can materially reshape productivity, scalability, and competitiveness. UAE-based banks and fintechs are already validating agent-initiated transaction pipelines in production environments. These are some of the examples, but there are more.
In July 2026, the revealing Mills Review, published by the FCA (Financial Conduct Authority), the UK’s official financial regulator, pointed out that AI agents will become the new financial interface. Essentially, an AI assistant will manage budgets, answer queries, generate reports on demand, and move money between accounts. How much was spent on a vacation in total, how a stock portfolio performed over the past month, or canceling an annual subscription will be as easy as making a query to ChatGPT today. For MENA consumers, who have in many cases leapfrogged legacy banking behaviors entirely, this vision is the baseline expectation.
The Mills Review also argues that Open Banking will evolve toward a model in which AI agents will have access to a broader range of financial products to enable intelligent decisions across different areas, and highlighted that this will lead to an evolution in regulation. In the GCC, this evolution is being actively shaped by regulators and governments alike, with initiatives such as Dubai’s target of 90%+ digital transactions by 2026 signaling not just ambition, but structural commitment to a cashless, AI-enabled financial ecosystem.
The agentic AI opportunity in the region is real, but it remains underexploited. According to EY-Parthenon’s 2025 Generative AI in Banking Survey, 99% of respondents are familiar with agentic AI, yet only 31% have pursued implementation, with a further 46% expressing interest. Awareness, in other words, has raced ahead of execution. This gap between recognition and production-grade deployment is precisely where the competitive battle will be won or lost.
This represents a major shift in the industry, where historically the leading banks have, for the most part, remained the same. Differentiation can now change everything, and it would not be surprising if new players manage to break into the ranks of the world’s most important financial institutions. In the Middle East, the region’s financial landscape already includes a new generation of digital-first challengers sitting alongside heritage institutions, all of which are now actively exploring or deploying agentic capabilities. The reason sounds obvious when explained: if the experience with an AI assistant can manage customers’ money better, it will prevail. This is not an exaggeration: just four years ago, nobody knew ChatGPT, and now we have become so accustomed to it that we all ask ourselves: why shouldn’t I manage my assets with a chatbot that can provide reports and recommendations? A study by JPMorgan found that half of Gen Z wanted to use them to manage their finances.
The infrastructure for agentic commerce is also being built in real time across the GCC. Mastercard has conducted regional pilots in partnership with Majid Al Futtaim, enabling consumers to search, select, and purchase VOX Cinema tickets programmatically through an integrated AI assistant. In May 2026, Visa launched its global Agentic Ready program in the UAE, with early adopters including ADCB, ADIB, Emirates NBD, Mashreq, Tabby, Wio, and Ziina already validating agent-initiated transaction pipelines in production.
We are living in a time of change. In its 2026 report on the financial sector, the World Economic Forum urged organizations to move with “urgency” and “discipline”. The greatest benefits, it stated, will go to those working on a holistic redesign of workflows and technology architecture. In the MENA region, the conditions for genuine transformation are already in place: strong institutional will, government-aligned modernization agendas, and a consumer base that has leapfrogged legacy behaviors entirely.
One of the major questions is why, if the financial sector has such a strong technological tradition, the emergence of AI Agents represents a black swan. There are several reasons. First, historically, customers used banks to execute transactions; therefore, in the executive conversations avoiding risk was prioritized over innovation. This is changing with the emergence of digital banks, which are generally more inclined toward disruption, and shifts in consumer habits. In the GCC specifically, consumers who bypassed branch banking and moved directly to mobile-first financial services are now primed to embrace AI-managed financial experiences with little friction. The challenge of the future is not to provide a tool, but to redesign experiences to address this transition comprehensively. AI has the potential to resolve the technological debt involved in migrating traditional banks, which have historically struggled the most with this transition.
The second reason is the technical debt banks have demonstrated in dealing with change. This has also occurred in other industries, but the idea of paying for a premium license for every employee and expecting immediate returns only leads to frustration. There is significant resistance when it becomes clear that certain tasks and workflows will inevitably be different from what has been established. In the Middle East, where several national banks have invested heavily in core banking modernization programs over the past decade, the foundations are more favorable than in many Western markets, but the final leap from modernized infrastructure to genuinely agentic deployment still requires focused capability and deliberate execution.
The third reason is regulation. Technology companies, banks, and authorities will need to maintain an ongoing dialogue to ensure that innovation and integrations do not affect users’ personal data or security, while ensuring that restrictions do not become a barrier to progress. One of the most valuable lessons from the banking sector’s legacy is the importance of being extremely careful when dealing with something as sensitive as people’s money.
For many years, the impact of AI was often explained as something that belonged to a distant future. In the financial sector, it is already a reality: it is part of multiple tasks and is beginning to become an asset in the customer proposition. With AI Agents, innovation can no longer, and should no longer, go unnoticed. New habits require the redesign of customer journeys, and this could represent a revolution for the sector. For Middle East banks, the opportunity is particularly compelling: a region where government will, consumer readiness, regulatory pragmatism, and institutional investment have aligned at the same moment. What is required now is the execution capability to convert that alignment into production-grade deployment. What is at stake is no small matter: the management of millions of people’s money and a battle for the competitiveness of banks on a scale rarely seen before. For those that move with urgency and discipline, the financial black swan is a transformation to be led.
Tech Features
Beyond the Transaction: Elevating the Standard for Customer Trust in the AI Era
By: Debo Zhang, CEO at HONOR GCC
In the hyper-competitive consumer technology sector, the launch of a flagship device is often treated as the finish line. However, true brand leadership is forged not in the showroom, but in the months and years that follow. At HONOR, we view the point of purchase not as a conclusion, but as day one of a long-term partnership with our users.
As we aggressively push the boundaries of intelligent hardware—from integrating Agentic OS to setting new benchmarks in physical durability and battery density—we recognize that advanced specifications represent only half of the premium equation. The other half is an unyielding commitment to the customer’s lifecycle experience. If a brand fails to support its users when they need it most, the underlying technological advancements lose their meaning.
Operationalizing Community Care
Our commitment to giving back to the GCC community dictates our operational investments. We do not just build resilient devices; we build resilient support networks designed to remove the friction of long-term ownership. Our recurring monthly Service Days are not promotional events—they are structural community investments.
By deliberately absorbing operational costs—such as completely waiving labor fees for expert repairs and offering complimentary professional device cleaning and disinfection—we ensure that maintaining a premium device remains accessible. We view ongoing device care, including free system upgrades and screen film replacements, as a fundamental responsibility rather than a secondary revenue stream.
Respecting the User’s Time and Individuality
True leadership in customer service also requires a profound respect for the user’s time and individuality. Recognizing that our customers’ lives are deeply integrated with their technology, we have designed our after-sales operations to adapt to the user, rather than forcing the user to adapt to us. Offering complimentary return shipping for repairs and providing complimentary gifts when repair timelines are extended are direct measures to eliminate inconvenience.
Furthermore, we understand that a smart device is a highly personal extension of the user. Incorporating free laser engraving and custom art back films into our regular service offerings transforms a standard maintenance visit into an opportunity for users to refresh and personalize their technology.
As the Middle East accelerates its digital transformation, consumers are demanding more than just innovation; they demand reliability, accountability, and respect. HONOR’s rapid growth across the region proves a fundamental business truth: when a technology brand prioritizes post-purchase empowerment and community care over short-term transactional gains, sustainable market leadership naturally follows.
Tech Features
Beyond Bandwidth: The Internet Foundations Behind the Next Wave of Digital Growth
By Dr Chafic Chaya, Regional Manager, Public Policy and Government Affairs, Middle East, RIPE NCC
A business launching an artificial intelligence service rarely thinks about Internet routing. A company moving its applications to the cloud does not normally ask whether its country has deployed IPv6. And when consumers make a digital payment, stream content or access an online government service, they certainly do not think about where networks exchange traffic. They notice these things mainly when something fails.
For many years, discussions around digital infrastructure focused primarily on coverage and speed. Connecting more people and businesses, expanding fibre networks and increasing mobile broadband capacity were natural priorities. Those objectives remain important, but they are no longer sufficient.
As economies become increasingly dependent on cloud computing, artificial intelligence, digital financial services, connected industries and online government services, another question is becoming just as important: can the Internet infrastructure underneath these services scale securely and remain resilient when disruption occurs?
The next phase of digital competitiveness will therefore require us to look beyond bandwidth.
From connectivity to capability
The Internet is becoming the operating environment for entire economies. Factories depend on connected systems. Financial institutions depend on real-time transactions. Governments deliver essential services digitally. Businesses increasingly rely on cloud platforms located across different networks and jurisdictions. Artificial intelligence adds another layer of demand through large-scale data processing, distributed computing and machine-generated traffic.
Connectivity is moving beyond simple availability toward quality, reliability, affordability and resilience. This shift matters because digital innovation can only scale when the underlying infrastructure scales with it.
A country may have excellent broadband coverage, but businesses will still face limitations if networks cannot exchange traffic efficiently, if addressing resources constrain future growth, if routing is vulnerable to errors or attacks or if international connectivity depends on too few pathways.
This is why digital infrastructure needs to be understood as an ecosystem rather than simply as a collection of telecom networks.
Telecom operators are essential, but no network operates alone
Telecom operators remain central to this ecosystem. They make substantial investments in fibre, mobile networks, backbone infrastructure and international capacity. Continuing those investments is essential as traffic grows and businesses demand faster and more reliable services.
But the Internet is fundamentally a network of networks. Its resilience depends not only on individual operators, but also on how networks interconnect with one another and how effectively the wider technical ecosystem functions.
Internet Exchange Points allow networks to exchange traffic locally, while data centres bring content and computing resources closer to users. Submarine cables and terrestrial routes provide international connectivity. The Domain Name System enables users to find services, and Internet Protocol addresses allow billions of devices and services to communicate. Routing systems determine how information travels between networks. Weakness in any of these layers can affect the services built above them.
This is an important distinction. Building a resilient digital economy cannot be the responsibility of telecom operators alone. It requires cooperation between network operators, Internet service providers, data centres, cloud platforms, governments, regulators and the technical community.
The invisible foundations of scalability
Some of the most important investments in the Internet receive relatively little public attention.
The Internet Protocol version 6 (IPv6) is one example. IPv6 is the latest version of the Internet Protocol. As the supply of IPv4 addresses has long been exhausted at the global level, IPv6 provides the much larger pool of Internet addresses needed for the Internet to continue expanding and for new digital services and technologies to grow, while reducing dependence on increasingly complex mechanisms used to extend the life of IPv4. For businesses, governments and operators planning for millions of additional connected devices, cloud workloads and digital services, IPv6 should increasingly be considered basic infrastructure for future growth rather than an optional technical upgrade.
Another example is routing security. Every day, networks around the world exchange information about how Internet traffic should reach its destination. Mistakes or malicious announcements can redirect traffic or make services unreachable. Resource Public Key Infrastructure (RPKI) provides a mechanism that helps network operators verify whether a network is authorised to announce particular Internet address resources.
Local interconnection is equally important. When two networks operating in the same market can exchange traffic locally through efficient interconnection and Internet Exchange Points, data may no longer need to travel thousands of kilometres through another country and a different jurisdiction before returning to nearby users. The result is lower latency, greater efficiency and improved resilience.
Internet measurement completes the picture. Policymakers and operators need reliable data to understand how traffic flows, where connectivity is concentrated, where dependencies exist and how networks react during disruptions. You cannot strengthen what you cannot see.
Resilience has a cost, but so does fragility
One of the harder questions is economic. Network redundancy costs money, as do alternative international routes. Maintaining multiple upstream connections, deploying security measures, training engineers and continuously upgrading infrastructure all require investment.
In competitive markets, operators understandably need to balance these investments against commercial realities. The solution, however, cannot simply be to minimise infrastructure costs.
Digital dependency changes the calculation. When banking, healthcare, government platforms, logistics, cloud services and business operations depend on continuous connectivity, the economic impact of prolonged disruption can quickly outweigh the cost of building greater resilience.
Failures across interconnected digital systems can cascade into other sectors. For governments and businesses, resilience should therefore increasingly be treated as an investment characteristic, not simply as an emergency response.
The objective is not to eliminate every possible failure, as no network can guarantee that. Instead, the goal is to avoid unnecessary concentration, introduce diversity wherever practical, continuously improve security and ensure that systems can recover quickly.
The Middle East is moving from adoption to infrastructure maturity
Saudi Arabia and the United Arab Emirates provide a useful example. The lesson is that Progress tends to occur when policy attention, technical capacity building and implementation by network operators reinforce one another. Infrastructure transformation is rarely achieved through regulation alone, nor through technology alone. It requires sustained cooperation between policymakers and the people who actually operate networks.
The race to build AI capacity is attracting billions of dollars in investment across our region and around the world. But compute without connectivity cannot deliver value. Connectivity without resilience cannot guarantee continuity. And infrastructure without cooperation cannot scale indefinitely. The strongest digital economies will therefore not simply be those with the most infrastructure. They will be those with Internet ecosystems that are open, interconnected, secure, scalable and resilient enough to support whatever comes next
-
News11 years ago
SENDQUICK (TALARIAX) INTRODUCES SQOOPE – THE BREAKTHROUGH IN MOBILE MESSAGING
-
Trending11 months agoOPPO A6 Pro 5G Review: Reliable Daily Driver
-
Tech News2 years agoDenodo Bolsters Executive Team by Hiring Christophe Culine as its Chief Revenue Officer
-
VAR1 year agoMicrosoft Launches New Surface Copilot+ PCs for Business
-
Automotive2 years agoAGMC Launches the RIDDARA RD6 High Performance Fully Electric 4×4 Pickup
-
Tech News2 years agoToshiba Announces MG10-D Series of Enterprise HDDs with Capacities up to 10TB
-
Tech Interviews3 years ago
Navigating the Cybersecurity Landscape in Hybrid Work Environments
-
Tech News1 year agoNothing Launches flagship Nothing Phone (3) and Headphone (1) in theme with the Iconic Museum of the Future in Dubai


