
Ransomware activity targeting organisations across the Middle East increased more than 20-fold between April 2025 and June 2026, according to new research from CloudSEK. The cybersecurity company recorded a rise from 17 ransomware-related threat intelligence feeds in April 2025 to a peak of 357 in June 2026. The June figure was also almost ten times higher than the previous month.
The findings form part of CloudSEK’s Middle East Cyber Threat Landscape 2025–2026, which analyses ransomware, hacktivism, dark-web activity, adversary intelligence, malware and vulnerability intelligence between April 2025 and August 31, 2026. The report recorded its highest overall monthly threat activity in March 2026, with 2,245 threat intelligence feeds. Israel was the most targeted country across the dataset, with 7,112 feeds, followed by Turkey. Iran, the UAE, Saudi Arabia and Egypt also recorded significant activity.
CloudSEK said the findings point to a structurally complex regional threat environment in which organisations are dealing with financially motivated cybercrime alongside politically motivated hacktivism, state-linked espionage and destructive attacks.
Ransomware moves in the opposite direction
One of the report’s notable findings is the changing relationship between hacktivism and ransomware activity. Hacktivism accounted for the largest volume of threat activity during much of the reporting period, with major spikes during periods of geopolitical escalation in June 2025, October 2025 and March 2026. From April 2026, however, hacktivist activity declined sharply.
Ransomware followed a different trajectory, continuing to rise and reaching its peak in June 2026. CloudSEK identified Nova as the most prolific ransomware operator in its regional dataset, while groups including The Gentlemen, Qilin, LockBit5 and DragonForce were also associated with attacks affecting Middle Eastern organisations.
The Gentlemen, described by CloudSEK as an emerging ransomware operation, exploited the Fortinet authentication-bypass vulnerability CVE-2024-55591 and used VPN credential brute-forcing and Rclone for data theft. Ransomware activity was particularly concentrated on asset-heavy industries, including facility management, industrial operations, property management, infrastructure and manufacturing, where disruption can have immediate operational and financial consequences.
Geopolitical tensions continue to shape attacks
Hacktivism remained the largest threat category by volume. Israel accounted for 37.8% of regional hacktivist activity, with Iran also recording significant activity. CloudSEK tracked groups including SKYNET, HeziRash, DieNet, Keymous, OpIsrael, DARKSTORM, NoName057(16) and Handala during the reporting period.
The research also identified changes in the target profiles of some groups. Handala, which has historically focused heavily on Israeli organisations, was recorded targeting UAE critical infrastructure in April 2026. Alongside hacktivism, Iranian-linked threat actors including MuddyWater, Charming Kitten/APT35, APT42, Nimbus Manticore and OilRig continued espionage activity against organisations in the region.
AI enters offensive operations
CloudSEK also identified growing evidence of generative AI being incorporated into offensive cyber operations. The report documents MuddyWater using Google’s Gemini model to assist with PowerShell code obfuscation. CloudSEK also found evidence of AI-assisted malware development linked to Nimbus Manticore/UNC1549.
According to the research, Nimbus Manticore expanded its operations across aviation, defence, telecommunications, software development and government targets, using techniques including phishing, trojanised software installers and SEO poisoning, alongside its MiniFast and MiniJunk malware tools.
The findings indicate that generative AI is beginning to feature in the operational workflows of active threat actors rather than remaining purely a potential future capability.
UAE and Saudi Arabia remain under pressure
The UAE recorded 2,588 overall activity indicators in CloudSEK’s dataset, covering ransomware, dark-web exposure and state-linked activity. MuddyWater activity targeting UAE maritime and industrial organisations included region-specific phishing lures and a multi-stage Remcos RAT delivery chain. CloudSEK also observed the actor moving towards the Rust-based RustyWater implant.
Saudi Arabia recorded 1,880 overall activity indicators and continued to attract ransomware operators and activity from underground cybercrime markets. The Gentlemen targeted Saudi organisations during the reporting period, while Nimbus Manticore also included Saudi Arabia within its expanded operations.
CloudSEK identifies organisations in UAE and Saudi critical infrastructure among the higher-risk groups in its regional assessment, alongside Israeli government, defence and healthcare organisations and Turkish industrial and manufacturing companies.
Exposed infrastructure remains a major weakness
Network-edge infrastructure, particularly VPNs, firewalls and SSL gateways, remained a significant initial-access route. CloudSEK highlighted vulnerabilities affecting Fortinet FortiOS/FortiProxy, Ivanti Connect Secure and Microsoft Windows. The report also identified vulnerabilities in technologies including React Server Components, Kubernetes ingress-nginx, Erlang/OTP and Apache Parquet as contributing to the potential attack surface.
The nine major vulnerabilities examined in the report had an average CVSS score of 9.2, placing them within the High or Critical severity categories. CloudSEK recommends that organisations prioritise patching exposed network-edge and web infrastructure, strengthen Salesforce and API permissions, implement phishing-resistant authentication, segment operational technology networks and maintain immutable offline backups. The company also recommends testing DDoS response and broader incident-response capabilities.
A quieter threat environment does not mean a safer one
CloudSEK said the decline in hacktivist activity after March 2026 should not be interpreted as a broader reduction in cyber risk. Ransomware remained elevated while state-linked operators continued to develop their tooling and techniques, creating a threat environment where highly visible disruption can decline even as less visible criminal and espionage activity increases.
“The defining characteristic of the Middle East cyber landscape is no longer any single threat actor or attack technique. Organisations are dealing simultaneously with geopolitical hacktivism, financially motivated ransomware, state-linked espionage and rapid exploitation of exposed infrastructure. The ransomware surge is particularly significant because it continued even as hacktivist activity declined. Less visible cyber noise should not be mistaken for lower risk,” said Rahul Sasi, CEO, CloudSEK.



