Emerging Ransomware Threats in the Middle East: Advanced Malware Analysis
Recent cyber operations in the Middle East have introduced sophisticated ransomware families, utilizing novel malware techniques and advanced command-and-control infrastructures.
Executive Takeaway — TL;DR
- Category:
- Offensive Tools
- Severity:
- Critical
- Actor Type:
- Ransomware Group
- Geography:
- Middle East
- Confidence:
- Confirmed
- Source:
- Raptor Cyber Intelligence
- Read Time:
- 5 min
In early 2026, the Middle East witnessed a surge in cyber operations, with state-sponsored and hacktivist groups deploying advanced ransomware families. These operations have introduced novel malware techniques, including polymorphic ransomware, rootkits, fileless malware, and sophisticated command-and-control (C2) infrastructures.
Emerging Ransomware Families
The BQT.Lock cyberattack group, also known as BaqiyatLock, emerged in mid-2025, operating from the Middle East under the leadership of Karim Fayad. This group utilizes a ransomware-as-a-service (RaaS) model, blending financial extortion with ideological motives linked to Hezbollah and Iranian state-linked cyber activities. (en.wikipedia.org)
In February 2026, the Iranian state-backed group MuddyWater, also known as Seedworm, Static Kitten, and TEMP.Zagros, initiated "Operation Olalampo," targeting multiple organizations and individuals primarily in the Middle East and North Africa. This campaign employed new malware families, including CHAR, GhostFetch, HTTP_VIP, and GhostBackDoor, with one variant communicating through a Telegram bot used for command and control. (en.wikipedia.org)
Advanced Malware Techniques
The BQT.Lock group has been reported to use a ransomware-as-a-service (RaaS) model, blending financial extortion with ideological motives linked to Hezbollah and Iranian state-linked cyber activities. (en.wikipedia.org)
MuddyWater's "Operation Olalampo" utilized new malware families, including CHAR, GhostFetch, HTTP_VIP, and GhostBackDoor, with one variant communicating through a Telegram bot used for command and control. (en.wikipedia.org)
The MuddyWater group has been linked to Iranian state-sponsored cyber activities, with operations targeting global government and commercial networks. (en.wikipedia.org)
Command-and-Control Infrastructure
MuddyWater's "Operation Olalampo" utilized a Telegram bot for command and control, demonstrating the group's ability to adapt and use widely available communication platforms for malicious purposes. (en.wikipedia.org)
Conclusion
The Middle East's cyber threat landscape in early 2026 is characterized by the emergence of sophisticated ransomware families employing advanced malware techniques and innovative command-and-control infrastructures. Organizations in the region must enhance their cybersecurity measures to detect and mitigate these evolving threats effectively.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Secp0 and Qilin Ransomware Groups Escalate Global Attacks on Real Estate and Electronics Sectors

Gunra and Medusa Ransomware Groups Intensify Double-Extortion Campaigns Against Critical Infrastructure

