Emerging AI-Driven Ransomware Threats in the Middle East
AI advancements are enabling ransomware groups in the Middle East to enhance their operations, posing significant cybersecurity challenges.
Encrygma is selling the entire Full Cyber Weapon Research of Emerging AI-Driven Ransomware Threats in the Middle East for ₿ 0.10 BTC. Contact us.
Executive Takeaway — TL;DR
- Category:
- State Cyber Warfare
- Severity:
- Medium
- Actor Type:
- Ransomware Group
- Geography:
- Middle East
- Confidence:
- Confirmed
- Source:
- Raptor Cyber Intelligence
- Read Time:
- 5 min
Introduction
The integration of artificial intelligence (AI) into cyber operations is reshaping the threat landscape in the Middle East. Ransomware groups are increasingly leveraging AI to automate and sophisticate their attacks, presenting new challenges for cybersecurity professionals.
AI Integration in Ransomware Operations
AI technologies are lowering the barriers to entry for cybercriminals, enabling them to execute more complex and evasive attacks. Ransomware groups are utilizing AI for tasks such as automating coding, conducting social engineering, and generating polymorphic malware that adapts to evade detection. This evolution is leading to a surge in the number and sophistication of ransomware groups operating in the region. (cybernews.com)
Notable Ransomware Groups in the Middle East
-
BQT.Lock: Emerging in mid-2025, BQT.Lock operates from the Middle East under the leadership of Karim Fayad. The group combines financial extortion with ideological motives linked to Hezbollah and Iranian state-sponsored cyber activities. BQT.Lock employs a ransomware-as-a-service (RaaS) model, offering various subscription levels and sharing profits with partners. Their attacks have targeted entities in the U.S., India, Saudi Arabia, UAE, and Israel, utilizing advanced techniques such as data exfiltration via Discord webhooks and credential theft from browsers. (en.wikipedia.org)
-
Sicarii: A RaaS operation that surfaced in December 2025, Sicarii is notable for a critical flaw in its encryption: the malware discards its own keys after encrypting files, making decryption permanently impossible for both victims and operators. While Sicarii has reported several victims since its creation, the group has recently indicated an intention to encrypt everything against as many victims as possible, primarily within the Middle East and one entity based in the U.S. (halcyon.ai)
State-Sponsored AI Cyber Capabilities
State actors in the Middle East are also advancing their AI capabilities for cyber operations. Iran, for instance, has established a National AI action plan with a $20 billion USD investment, backed by the National Development Fund of Iran. The plan includes the incorporation of the National Artificial Intelligence Organization and directives from IRGC commander General Pakpour to develop AI-guided weapons. Reports indicate that AI has been deployed for Afghan border control, and AI-ready weapons have been advertised by the Iranian army ahead of the 2026 Iran war. (en.wikipedia.org)
Impact on Cybersecurity Infrastructure
The proliferation of AI-driven cyber threats is impacting the Middle East's cybersecurity infrastructure. A report by PwC indicates that 62% of Middle East organizations expect their cyber budgets to increase in 2026, compared to 50% globally. However, 88% of organizations in the region cite a lack of knowledge as the biggest barrier to adopting AI for cyber defense, compared to 50% globally. This highlights the need for enhanced education and resources to effectively counter AI-driven cyber threats. (pwc.com)
Conclusion
The integration of AI into cyber operations is significantly altering the threat landscape in the Middle East. Ransomware groups are leveraging AI to enhance their attacks, while state actors are developing AI capabilities for cyber warfare. This evolution necessitates a proactive and informed approach to cybersecurity, emphasizing the need for continuous adaptation and investment in advanced defense mechanisms.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

GopherWhisper APT Escalates Global Espionage Campaign Targeting Government Infrastructure

Jewelbug APT Expands Espionage and Crypto Fraud Operations Across Middle East and Asia

