• 5 minuti
  • Pubblicato

Ransomware surges in the Middle East as AI gives hackers new power

Barbara Carminati Autrice di cybersecurity e privacy QWERTYmag

Scritto da Barbara Carminati

Ransomware surges in the Middle East as AI gives hackers new power QWERTYmag © www.qwertymag.it
Ransomware surges in the Middle East as AI gives hackers new power © www.qwertymag.it

Ransomware attacks have jumped twenty-fold in the Middle East, with AI-driven hacking tools now targeting critical infrastructure and major economies. Both criminal and state-backed groups are reshaping the region's cyber threat landscape.

Ransomware attacks have soared across the Middle East, multiplying more than twenty times in just over a year. Artificial intelligence is now helping attackers launch more sophisticated digital extortion campaigns. According to CloudSEK, both cybercriminals and state-linked groups are using a mix of old vulnerabilities and new AI tools to breach governments, industry, and critical infrastructure.

  • Ransomware overtakes hacktivism as the main threat

    By June 2026, CloudSEK tracked 357 ransomware-related threat intelligence feeds in the region, up from just 17 in April 2025. This sharp increase came as hacktivist activity, once the main cyber threat, dropped off after March 2026. The data shows a clear shift: ransomware groups are now focused on organizations with the resources to pay and the most to lose from downtime, rather than simply taking advantage of political unrest.

    Groups such as Nova, Qilin, LockBit5, DragonForce, and the newly emerged The Gentlemen are running coordinated campaigns. The Gentlemen, for example, have exploited the Fortinet vulnerability FG-IR-24-535, combined with VPN credential attacks and Rclone-based data theft. Unlike the random attacks of the past, today's ransomware is targeted-hitting facility management, manufacturing, infrastructure, and property-management firms where even short outages can cause major financial losses. Turkey has become the most targeted country, likely due to its industrial base and logistical role. Governments and financial services also remain frequent targets.

  • CloudSEK's regional breakdown places Israel as the highest overall cyber-threat activity country, followed by Turkey, Iran, the UAE and Saudi Arabia.

  • AI becomes a tool for attackers

    The most concerning trend is the use of generative AI by threat actors. CloudSEK documented Iranian-linked MuddyWater using Google's Gemini model to hide PowerShell code, making malicious software harder to spot and analyze. There is also evidence that Nimbus Manticore (UNC1549) is using AI to speed up malware development and adapt attack tools quickly. Security researchers have warned that generative AI could make phishing, malware, and social engineering more effective. The report confirms this is already happening-AI is now helping attackers, even if its full impact is still unfolding.

  • Geopolitics and cyber conflict remain connected

    Even with the rise of ransomware, hacktivism still accounts for the largest number of incidents. Israel saw nearly 38% of all hacktivist activity, with 7,112 threat intelligence feeds logged. Groups like Handala, DARKSTORM, NoName057(16), SKYNET, and OpIsrael continue to launch denial-of-service attacks, website defacements, and data leaks, often tied to political disputes. In 2026, Handala expanded its focus to target UAE critical infrastructure, showing how cyber campaigns can cross borders and raise regional tensions.

  • UAE and Saudi Arabia face growing threats

    The UAE and Saudi Arabia, two of the region's largest economies, are now major targets. The UAE recorded 2,588 activity indicators across ransomware, espionage, credential theft, and dark-web operations. Saudi Arabia had 1,880 such indicators. Both countries are facing ongoing attacks from groups like MuddyWater, which has targeted maritime and industrial organizations with tailored phishing and multi-stage malware. Their rapid digital growth and strategic roles have made them especially attractive to both criminal and state-backed attackers.

  • Unpatched vulnerabilities remain a weak spot

    While advanced ransomware and AI-driven attacks get the most attention, many breaches still start with basic issues: unpatched software. CloudSEK's report highlights vulnerabilities in Fortinet, Ivanti, Microsoft, Kubernetes, React Server Components, and Apache Parquet. Network-edge devices-VPN gateways, firewalls, remote-access systems-are common entry points, showing that attackers often rely on missed updates to get in. Fortinet's public security guidance for CVE-2025-25249, affecting FortiOS and FortiSwitchManager, urges immediate upgrades to versions 7.0.18+, 7.4.9+, and related releases. For Italian organizations, following the latest ACN cybersecurity directives is now essential to reduce these risks.

  • Regional escalation, global impact

    The Middle East's cyber crisis is not happening in isolation. As seen in recent reports of attacks on Gulf infrastructure, the same tactics-ransomware, AI, and exploiting vulnerabilities-are being used in Africa and Latin America as well. The mix of financially motivated crime, state-linked espionage, and AI-powered attacks is quickly changing the global cyber threat landscape.

    CloudSEK's findings show a region where old assumptions no longer hold. Ransomware is now the fastest-growing threat, AI is shaping attack strategies, and critical infrastructure is more exposed than ever. For organizations in the Middle East, isolated threats are a thing of the past; defenders now face simultaneous attacks that combine economic extortion, political sabotage, and new technology. Inaction and complacency are no longer options in a landscape where attackers are evolving faster than most defenses. The Middle East has become a testing ground for the next wave of cyber warfare, and the rest of the world is watching closely.

  • Articoli correlati