Middle East cyber threats enter a new phase as ransomware surges and AI joins the attacker’s toolkit
Ransomware activity in the Middle East surged dramatically between April 2025 and June 2026, with financially motivated groups and state-linked actors increasingly using targeted campaigns and generative AI. The report highlights prolific ransomware groups, notable vulnerabilities (including Fortinet FG-IR-24-535), and elevated activity in Turkey, the UAE and Saudi Arabia.

Ransomware has rapidly overtaken hacktivism as the most dynamic cyber threat across the Middle East, with financially motivated groups, state-linked espionage campaigns and the first operational use of generative AI reshaping the region’s risk profile. A newly released regional threat analysis found ransomware-related threat intelligence feeds jumped from 17 in April 2025 to 357 by June 2026 — a rise of more than twenty-fold over the 17-month reporting period — while hacktivist activity declined after March 2026.
"Ransomware activity surged more than twenty-fold during the 17-month reporting period," the report states, highlighting how attackers are increasingly following economic logic rather than purely exploiting geopolitical instability.
The analysis identifies several prolific ransomware operators and evolving TTPs. Among the most active groups were Nova, Qilin, LockBit5 and DragonForce, and a newer actor, The Gentlemen, which exploited a Fortinet vulnerability (FG-IR-24-535) in combination with VPN credential attacks and the use of Rclone to exfiltrate sensitive data. These campaigns are increasingly targeted and strategic: attackers focus on facility management, manufacturing, industrial operations, infrastructure providers and property-management firms where operational disruption quickly produces economic pressure.
Hacktivism, while decreasing in volume, remained the largest threat category overall by sheer number of incidents. Israel accounted for 7,112 threat intelligence feeds — nearly 38% of all hacktivist activity recorded — with groups such as Handala, DARKSTORM, NoName057(16), SKYNET and OpIsrael conducting denial-of-service attacks, website defacements and data leaks. The report notes Handala broadened its geographic focus in 2026, targeting UAE critical infrastructure and demonstrating how campaigns can spread beyond their original political boundaries.
Significant state-linked activity and the arrival of AI in attacker toolkits were key themes. The Iranian-linked actor MuddyWater was documented using Google’s Gemini model to obfuscate PowerShell code, a technique that complicates detection and analysis. Evidence was also found of AI-assisted malware development linked to Nimbus Manticore (UNC1549), suggesting adversaries are experimenting with generative models to accelerate coding, modify malware and adapt tools against defenders.
- Ransomware feeds: 17 (April 2025) → 357 (June 2026)
- Hacktivist volume: Israel — 7,112 feeds (≈38% of hacktivist activity)
- Country indicators: UAE — 2,588 activity indicators; Saudi Arabia — 1,880 indicators
- Notable groups: Nova, Qilin, LockBit5, DragonForce, The Gentlemen, MuddyWater, Nimbus Manticore (UNC1549)
- Vulnerabilities highlighted: Fortinet (FG-IR-24-535), issues in Ivanti, Microsoft, Kubernetes, React Server Components, Apache Parquet
Geographically, Turkey experienced the highest level of ransomware targeting in the region, tied to its large industrial base and logistics role. The UAE and Saudi Arabia also recorded elevated activity — the UAE with 2,588 indicators spanning ransomware, espionage, credential theft and dark-web activity, and Saudi Arabia with 1,880 indicators — reflecting their expanding digital footprints and strategic importance.
Outlook: As ransomware operators prioritise high-value targets and state-linked actors refine espionage techniques, defenders face a multi-front challenge. Unpatched vulnerabilities remain a primary entry point, particularly at the network edge (VPN gateways, firewalls and remote-access systems). Concurrently, the operationalisation of generative AI for code obfuscation and malware development signals a likely acceleration in attack sophistication. Organisations in critical infrastructure, manufacturing and finance should prioritise patch management, network-edge hardening and threat-hunting capabilities to mitigate an increasingly complex and economically driven threat landscape.
Stay in the loop
Join our weekly newsletter and get the latest MENA startup news, funding rounds, and insights delivered straight to your inbox.