Minacce · 173 giorni fa
Questa campagna rompe il consueto schema dello spyware mobile combinando phishing per l'accesso a iCloud e Signal con la distribuzione di spyware Android. Gli aggressori ottengono accesso persistente ai backup cloud e agli account di messaggistica, non solo al dispositivo compromesso, rendendo insufficiente la risposta standard agli incidenti mobili. L'infrastruttura condivisa e il targeting ripetuto in più paesi rivelano un servizio di hack-for-hire riutilizzabile piuttosto che intrusioni isolate.
5 fonti che coprono questa storia
Bitter-Linked Hack-for-Hire Campaign Targets Journalists Across MENA Region
Hack-for-hire phishing tied to Bitter targeted MENA journalists from 2023–2025, compromising an Apple account and enabling regional surveillance.
Middle East Hack-for-Hire Operation Traced to South Asian APT Group
A spear-phishing campaign which spread across the Middle East between 2023 and 2024 has now been linked to Bitter APT group
Hack-for-hire group caught targeting Android devices and iCloud backups | TechCrunch
Security researchers exposed a spying campaign by a hack-for-hire group that used Android spyware and phishing to steal iCloud credentials and hack victims’ devices.
The Record from Recorded Future
Two prominent Egyptian journalists targeted with elaborate spearphishing campaign
Digital civil rights nonprofit Access Now released a report on the findings with the mobile security company Lookout on Wednesday, saying they saw evidence the hackers may “use the methods and infrastructure associated with the attacks to deliver spyware and exfiltrate data.”
Hack-for-hire spyware campaign targets journalists in Middle East, North Africa
Access Now, Lookout and SMEX joined research forces to find a campaign involving suspected Indian government-connected group Bitter, ProSpy spyware and more.
Part of the PlainSec briefing for 2026-04-10