Agbi

rewrite this content and keep HTML tags as is: Iran-backed hacking groups target Middle East academia


rewrite this content and keep HTML tags as is:

  • Universities face cyberattacks
  • Academic hacking grows rapidly
  • Two Iran-linked groups named

Iranian state-linked hacking groups have targeted academic, logistics and professional-services organisations across the Middle East, a cybersecurity report has found.

Static Kitten, an intelligence-gathering group linked to the Islamic Republic, has sought access to university institutions as Gulf states invest billions of dollars in research programmes focused on AI, quantum computing and other advanced technologies.

The group has been active since at least early 2017 and uses legitimate remote monitoring and management software to conduct operations. Its principal route into organisations is through “spear-phishing” emails containing documents embedded with malicious code.

The cyber world has long been contested by Iran and its adversaries. In 2016, suspected Iranian hackers successfully penetrated the Saudi foreign ministry while in 2009 the Israeli-US stuxnet malware paralysed Iran’s Natanz nuclear facility.

Analysts said in March that more than 60 hacker groups or collectives mobilised within hours of the start of the latest US-Israeli conflict with Iran and more than 100 cyber incidents were recorded across the Middle East in the first 72 hours.

Academic bodies are attractive to state-linked hackers because they hold sensitive research and intellectual property that align with national intelligence priorities, US cybersecurity company CrowdStrike said.

Middle Eastern organisations accounted for 8 percent of all academic-sector cyber targeting observed globally between July 2025 and June 2026, according to CrowdStrike.

The findings are contained in its 2026 Threat Hunting Report, which documents how criminal gangs and state-linked groups are targeting organisations, exploiting trusted systems and using artificial intelligence to accelerate their operations.

CrowdStrike did not identify the Middle Eastern institutions or countries involved, meaning it is unclear whether any of the activity affected GCC states. However, it said the region’s share “aligns with the density of high-value research institutions and universities” in the Middle East.

Academic-sector cyber activity increased 17 percent globally during the period covered by the report, the largest rise among the industries examined. State-linked groups were responsible for 45 percent of the activity, while cybercriminals accounted for 55 percent.

Further reading:

Further reading:

The report also identified Spectral Kitten, another Iran-linked group that attempted to infiltrate logistics and professional-services organisations in the Middle East.

CrowdStrike associates the collective with “destructive” cyber operations, although the report did not identify its regional targets. It did not state whether the logistics activity involved shipping, ports or other transport infrastructure.

North Korean state-linked groups were also active across the Middle East.

Famous Chollima, which uses fraudulent identities to obtain remote jobs and funnel salaries to the government in Pyongyang, targeted technology, financial services and professional-services organisations in the region. Stardust Chollima, which has previously pursued cryptocurrency and fintech companies, also focused on those sectors as well as legal firms.

AI as both weapon and target

The latest report said CrowdStrike’s threat-hunting division is now generating leads triggered by AI agents at 2.5 times the rate of those triggered by people. The company said this demonstrated how AI was increasing the volume and speed of suspicious activity that security teams must investigate.

Attackers are particularly targeting the AI systems used by businesses. CrowdStrike said hackers had exploited AI infrastructure, abused companies’ large language models and compromised popular software packages to reach their users.

“AI is now embedded in modern adversary operations,” said Adam Meyers, CrowdStrike’s head of counter-adversary operations. “It is changing how attacks are planned, executed, and scaled while expanding the attack surface organisations must defend.”



Source link