Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
state-sponsored-espionagegovernment-diplomatic-threatphishing-campaign-intelligenceloader-delivery-mechanism

Middle East Conflict Triggers Spike in State-Linked Espionage and Malware Campaigns

Updated 3mo agoFirst seen Mar 11, 20262 sources

Escalating conflict following Operation Epic Fury (US/Israel strikes inside Iran) has coincided with increased cyber activity targeting Middle East and adjacent interests. Proofpoint reported that Iran-aligned TA453 (Charming Kitten / Mint Sandstorm / APT42) continued intelligence collection during the conflict, including a credential-phishing attempt against a US think tank observed on 8 March, and noted additional campaigns against Middle East government organizations with suspected links to multiple state or state-aligned actors (including suspected attribution to China, Belarus, Pakistan, and Hamas). Despite reported Iranian internet shutdown measures after the initial strikes, espionage-focused operations were assessed as ongoing.

Check Point Research separately identified China-linked activity targeting Qatar, using conflict-themed lures (e.g., fake “war news”/damage imagery) to deliver malware, including PlugX and Cobalt Strike, with tradecraft described as a multi-stage chain involving a compromised server and DLL hijacking via a legitimate application (Baidu NetDisk) to load the backdoor—highlighting rapid weaponization of breaking news to target energy and military sectors. Other items in the set were not part of this conflict-driven espionage theme: one report described a Russian-speaking ‘BlackSanta’ BYOVD-based “EDR killer” delivered via HR workflow abuse and steganographic images, and a weekly threat bulletin summarized unrelated breaches and research (e.g., AkzoNobel, LexisNexis, Wikimedia worm, TriZetto, and AI-related threats).

Share:
Middle East Conflict Triggers Spike in State-Linked Espionage and Malware Campaigns
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the most recent confirmed update back to the earliest known activity.

7 EVENTS
Mar 10, 20263mo ago

Proofpoint and Check Point publicly disclose conflict-themed espionage activity

On 2026-03-10, public reporting from Proofpoint and Check Point detailed a surge in espionage operations exploiting the Iran conflict as lure content. The disclosures linked the activity to several state-aligned actors and described malware including PlugX, Cobalt Strike, and a Rust-based backdoor loader.

Multiple state-aligned actors intensify espionage against Middle East targets

Proofpoint reported heightened campaigns against Middle East government and diplomatic organizations by actors aligned with or suspected to be linked to China, Belarus, Pakistan, and others. The activity used compromised government email accounts, credential-harvesting pages, archives, LNK files, loaders, and in some cases Cobalt Strike via DLL sideloading.

TA453 continues credential phishing despite Iranian internet shutdown

Proofpoint observed Iran-aligned TA453 continue credential-phishing against a US think tank target even after the conflict started and despite an Iranian internet shutdown. The engagement had begun before the conflict and persisted afterward, showing operational continuity during the crisis.

Mar 1, 20264mo ago

Separate Qatar oil and gas campaign deploys Rust loader and Cobalt Strike

A parallel campaign targeted Qatar’s oil and gas sector with a password-protected archive and a new Rust-based loader that hid malicious code inside an NVDA component to evade detection. The intrusion chain ultimately deployed Cobalt Strike for deeper access.

Camaro Dragon uses fake missile-strike lure to deploy PlugX in Qatar

One infection chain used a decoy file claiming to show photos of an Iranian missile strike near a US base in Bahrain, then retrieved additional payloads from a hacked server. The attackers used DLL hijacking with a legitimate Baidu NetDisk application to execute the PlugX backdoor, enabling file theft, keystroke logging, and screen capture.

China-linked campaigns begin targeting Qatar after conflict outbreak

Check Point reported that China-nexus operations targeting Qatar started on 2026-03-01, one day after Operation Epic Fury began. The campaigns rapidly pivoted to use Middle East conflict themes as social-engineering bait during heightened regional tensions.

Feb 28, 20264mo ago

US and Israeli strikes inside Iran launch Operation Epic Fury

Proofpoint reported that US and Israeli strikes inside Iran began on 2026-02-28 under the name Operation Epic Fury. The conflict and Iran’s subsequent regional retaliation became the basis for later war-themed cyber lures and espionage activity.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

7 LINKEDOpen in app
Threat actors
2 linked
Organizations
2 linked
Check Point Software TechnologiesBaidu
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.