Threats · 159 days ago
This campaign breaks the usual mobile spyware pattern by combining phishing for iCloud and Signal access with Android spyware deployment. Attackers gain persistent access to cloud backups and messaging accounts, not just the compromised device, making standard mobile incident response insufficient. The shared infrastructure and repeated targeting across multiple countries reveal a reusable hack-for-hire service rather than isolated intrusions.
Researchers from Access Now, Lookout, and SMEX linked spearphishing cases from 2023 to 2025 targeting journalists and officials in the Middle East and North Africa. They identified overlapping domains, hosting, and code tied to the Bitter group, along with ProSpy Android spyware and account-access phishing. Victims include Egyptian and Lebanese journalists, with additional targets in Bahrain, UAE, Saudi Arabia, the UK, and possibly the US. The campaign uses fake personas and messages mimicking legitimate services like Signal to deliver spyware and steal credentials.
The persistence of shared infrastructure and cross-border reuse indicates this is an ongoing espionage threat delivered by a hack-for-hire vendor with suspected Indian government ties. The risk extends beyond device compromise to cloud and messaging account infiltration, which can maintain attacker visibility even after device remediation. This elevates the threat for journalists, activists, and government personnel in MENA and their support networks.
5 sources covering this story
Bitter-Linked Hack-for-Hire Campaign Targets Journalists Across MENA Region
Hack-for-hire phishing tied to Bitter targeted MENA journalists from 2023–2025, compromising an Apple account and enabling regional surveillance.
Middle East Hack-for-Hire Operation Traced to South Asian APT Group
A spear-phishing campaign which spread across the Middle East between 2023 and 2024 has now been linked to Bitter APT group
Hack-for-hire group caught targeting Android devices and iCloud backups | TechCrunch
Security researchers exposed a spying campaign by a hack-for-hire group that used Android spyware and phishing to steal iCloud credentials and hack victims’ devices.
The Record from Recorded Future
Two prominent Egyptian journalists targeted with elaborate spearphishing campaign
Digital civil rights nonprofit Access Now released a report on the findings with the mobile security company Lookout on Wednesday, saying they saw evidence the hackers may “use the methods and infrastructure associated with the attacks to deliver spyware and exfiltrate data.”
Hack-for-hire spyware campaign targets journalists in Middle East, North Africa
Access Now, Lookout and SMEX joined research forces to find a campaign involving suspected Indian government-connected group Bitter, ProSpy spyware and more.
Part of the PlainSec briefing for 2026-04-10