Skip to main content
Mallory
Back to intelligence
state-sponsored-espionagephishing-campaign-intelligenceremote-access-implantidentity-impersonation-fraud

Hack-for-Hire Spyware Campaign Targeted Journalists in the Middle East and North Africa

Updated 2mo agoFirst seen Apr 8, 202610 sources

Access Now, Lookout, and SMEX reported a suspected hack-for-hire espionage campaign targeting journalists and activists across the Middle East and North Africa through spearphishing, fake social media personas, messaging apps, and sustained social engineering. Researchers said the operation used infrastructure linked to the APT group Bitter and likely deployed ProSpy Android spyware, which can steal files, contacts, messages, and geolocation data, activate microphones and cameras, and install malicious apps. The activity has reportedly been ongoing since at least 2022, with broader targeting that may have included civil society figures and possibly government officials.

Two Egyptian journalists, Mostafa Al-A’sar and Ahmed Eltantawy, were among the identified targets in an elaborate campaign that ran between October 2023 and January 2024 and spoofed trusted services including Apple and Signal. A prominent Lebanese journalist was also reportedly targeted, and researchers said the attackers relied on overlapping infrastructure with possible ties to Asia, though Access Now said it lacked enough evidence to definitively name a sponsor. Neither Egyptian journalist’s accounts were ultimately compromised, but press freedom groups warned that surveillance of reporters endangers their safety, sources, and ability to work.

Share:
Hack-for-Hire Spyware Campaign Targeted Journalists in the Middle East and North Africa
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

8 events from the most recent confirmed update back to the earliest known activity.

8 EVENTS
Apr 13, 20262mo ago

Lookout attributes ProSpy campaign to BITTER APT

By April 13, 2026, reporting on Access Now and Lookout’s findings said Lookout attributed the espionage campaign targeting journalists and opposition figures in the Middle East to the South Asian threat group BITTER, also known as T-APT-17 and APT-Q-37. The attribution was based on code similarities between the ProSpy Android spyware used in the campaign and BITTER’s earlier Dracarys malware.

BITTER APT Uses Signal, Google, and Zoom Lures to Spread ProSpy Spyware
Apr 8, 20262mo ago

Committee to Protect Journalists condemns surveillance

Following publication of the findings on April 8, 2026, the Committee to Protect Journalists condemned the spying campaign, warning that surveillance of journalists endangers their safety, sources, and ability to work. The statement marked a public response from a press freedom organization to the reported activity.

Researchers reveal broader 2023–2025 targeting across multiple countries

On April 8, 2026, reporting on the hack-for-hire campaign said it targeted not only Egyptian and Lebanese civil society members but also government officials and other targets connected to Bahrain, Egypt, the UAE, Saudi Arabia, the UK, and potentially the United States between 2023 and 2025. The disclosure marked a broader understanding of the campaign’s scope and victimology than previously captured.

Hack-for-hire group caught targeting Android devices and iCloud backups | TechCrunch

Researchers publish findings on MENA spyware campaign

On April 8, 2026, Access Now, Lookout, and SMEX publicly reported the suspected hack-for-hire espionage campaign targeting journalists and activists in the Middle East and North Africa. The report described social-engineering tactics, named victims including Mostafa Al-A’sar and a prominent Lebanese journalist, and said attribution to a specific sponsor remained unconfirmed.

Oct 1, 20233y ago

Egyptian journalists targeted in spearphishing campaign

Between October 2023 and January 2024, attackers targeted Egyptian journalists Mostafa Al-A’sar and Ahmed Eltantawy with an elaborate spearphishing operation using fake personas and spoofed Apple and Signal services. The campaign sought access to their Apple and Google accounts and used infrastructure capable of delivering Android spyware, though neither victim’s accounts were ultimately compromised.

Jan 1, 20233y ago

Ahmed Eltantawy targeted again with Predator spyware in 2023

Citizen Lab previously found that Ahmed Eltantawy’s phone was targeted again with Intellexa’s Predator spyware in 2023. This was separate from the later spearphishing campaign documented by Access Now and Lookout.

Jan 1, 20224y ago

Hack-for-hire spyware campaign active in MENA by at least 2022

Access Now, Lookout, and SMEX said the broader espionage campaign targeting journalists and activists in the Middle East and North Africa had been active since at least 2022. Researchers linked shared infrastructure in the attacks to Bitter and assessed the operation likely used ProSpy Android spyware.

Jan 1, 20215y ago

Predator spyware targeted Ahmed Eltantawy's phone in 2021

Citizen Lab previously found that Egyptian journalist Ahmed Eltantawy’s phone was targeted with Intellexa’s Predator spyware in 2021. This establishes earlier surveillance activity against one of the later campaign’s victims.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

38 LINKEDOpen in app
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.