The cyber threat landscape across the Middle East is undergoing a profound transformation. While geopolitical hacktivism continues to dominate headlines, a new analysis suggests that the region’s most pressing digital risks are increasingly being driven by financially motivated ransomware groups, state-linked espionage campaigns, and the growing use of artificial intelligence by threat actors.
According to CloudSEK’s newly released Middle East Cyber Threat Landscape 2025–2026, ransomware activity surged more than twenty-fold during the 17-month reporting period, highlighting a significant shift in the nature of cyber attacks targeting governments, businesses and critical infrastructure. The report paints a picture of an increasingly complex environment in which organisations face multiple threat categories simultaneously. Cyber defenders must now contend with disruptive hacktivist attacks linked to regional political tensions, sophisticated espionage operations conducted by advanced persistent threat (APT) groups, highly organised ransomware campaigns, and the rapid exploitation of software vulnerabilities.
Ransomware emerges as the fastest-growing threat
One of the report’s most striking findings is the dramatic escalation in ransomware activity. CloudSEK recorded just 17 ransomware-related threat intelligence feeds in April 2025. By June 2026, that figure had reached 357, representing a more than twenty-fold increase in little over a year. The June 2026 peak was also nearly ten times higher than activity observed during the previous month.
This trend is especially significant because it unfolded while hacktivist activity was declining. Throughout much of 2025 and early 2026, politically motivated cyber campaigns dominated the regional landscape, often mirroring developments in broader geopolitical tensions. However, as hacktivist activity fell sharply after March 2026, ransomware continued to rise.
The divergence suggests that ransomware operators are not merely opportunistically exploiting periods of geopolitical instability. Instead, they appear to be following their own economic logic, targeting organisations capable of paying substantial ransoms and offering lucrative opportunities for data theft and extortion. Among the most active ransomware groups identified in the report were Nova, Qilin, LockBit5 and DragonForce. The report also highlights the emergence of The Gentlemen, which has exploited the Fortinet vulnerability https://www.fortiguard.com/psirt/FG-IR-24-535, combined with VPN credential attacks and the use of Rclone to exfiltrate sensitive data.
Unlike indiscriminate cyber campaigns of the past, modern ransomware attacks are becoming more strategic. The industries most heavily targeted are those where operational disruption can rapidly translate into financial losses or public consequences. Facility management, manufacturing, industrial operations, infrastructure providers and property-management firms have become attractive targets because attackers understand that even brief interruptions can create significant economic pressure.
Turkey experienced the highest level of ransomware targeting in the region, reflecting its extensive industrial base and strategic role in manufacturing and logistics. Across the region, governments and financial services organisations also remained major targets, reflecting both the value of the information they hold and their significance to national economies.
Geopolitical tensions continue to fuel cyber conflict
Despite the surge in ransomware, hacktivism remains the largest threat category by overall volume. Israel was the most targeted country in CloudSEK’s dataset, accounting for 7,112 threat intelligence feeds and nearly 38% of all hacktivist activity recorded during the reporting period.
Groups including Handala, DARKSTORM, NoName057(16), SKYNET and OpIsrael continued to conduct disruptive operations, often linked to wider geopolitical narratives. While these campaigns frequently focus on denial-of-service attacks, website defacements and data leaks, their strategic significance extends beyond immediate damage. Cyber operations increasingly serve as vehicles for political messaging, propaganda and influence. The report notes that some groups are expanding their geographic focus. Handala, historically associated with attacks against Israeli organisations, was observed targeting UAE critical infrastructure during 2026, illustrating how cyber campaigns can spread beyond their original political boundaries. This expansion reinforces concerns that cyber operations have become another theatre through which regional disputes can play out.
Perhaps the most intriguing development identified by CloudSEK is the growing use of generative AI within active cyber campaigns. For years, cybersecurity professionals debated how AI might reshape both attack and defence. The report suggests that the discussion is now moving from theory to practice.
CloudSEK documented the Iranian-linked threat actor MuddyWater using Google’s https://gemini.google.com model to obfuscate PowerShell code. While seemingly technical, this represents a significant development because code obfuscation can make malicious software more difficult for defenders to detect and analyse. The report also identified evidence of AI-assisted malware development linked to Nimbus Manticore (UNC1549). By using AI to accelerate coding, modify malware or adapt attack tools, cyber criminals and state-backed actors may be able to shorten development cycles and respond more quickly to defensive measures.
Security researchers have increasingly warned that generative AI could serve as a force multiplier for attackers, enabling faster creation of phishing campaigns, malware variants and social-engineering content. While today’s AI-powered attacks remain relatively limited, the technology’s trajectory suggests its influence will continue to grow.
UAE and Saudi Arabia face mounting cyber pressure
Two of the region’s largest economies also featured prominently within the findings. The UAE recorded 2,588 activity indicators across ransomware, espionage operations, credential theft and dark-web activity. CloudSEK observed campaigns by MuddyWater targeting maritime and industrial organisations using region-specific phishing techniques and multi-stage malware delivery chains.
Saudi Arabia registered 1,880 activity indicators and was repeatedly mentioned in ransomware and espionage investigations. Both nations have become increasingly attractive targets because of their accelerated digital-transformation programmes, growing technology investments and strategic regional importance. CloudSEK assesses organisations operating within critical infrastructure sectors in both countries as having elevated exposure to cyber threats, particularly when compared with organisations in less strategically sensitive industries.
Vulnerabilities remain attackers’ favourite doorway
While ransomware groups and nation-state actors often attract the most attention, many attacks still begin with something remarkably mundane: unpatched software. The report highlights vulnerabilities affecting technologies from companies including Fortinet, Ivanti and Microsoft, alongside weaknesses involving Kubernetes deployments, React Server Components and Apache Parquet environments.
Many of these vulnerabilities score at or near the highest levels on the Common Vulnerability Scoring System (CVSS), reflecting their potential severity. Network-edge infrastructure including VPN gateways, firewalls and remote-access systems remains particularly attractive because successful exploitation can provide immediate access to internal networks. This reinforces a longstanding cybersecurity lesson: attackers often do not require sophisticated zero-day exploits when publicly accessible systems remain unpatched.
