International Cyber Expo International Cyber Expo
  • About Us
Tuesday, 21 July, 2026
IT Security Guru
International Cyber Expo
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

SneakyPastes: Basic But Effective Operation By Gaza Cybergang Hits Middle East Related Targets In 39 Countries.

by The Gurus
April 18, 2019
in Scam Of The Week
SneakyPastes: Basic But Effective Operation By Gaza Cybergang Hits Middle East Related Targets In 39 Countries.
Share on FacebookShare on Twitter

In 2018, the Gaza Cybergang, now known to comprise several groups of varying sophistication launched a cyberespionage operation targeting individuals and organisations with a Middle-Eastern political interest. The campaign, named SneakyPastes made use of disposable email addresses to spread the infection through phishing, before downloading the malware in chained stages using multiple free sites. This low cost but effective approach helped the group to hit around 240 high profile victims in 39 countries worldwide, including political, diplomatic, media and activist entities, among others. Kaspersky Lab’s research was shared with law enforcement and has resulted in the takedown of a significant part of the attack infrastructure.

The Gaza Cybergang is an Arabic speaking, politically motivated collective of interrelated threat groups actively targeting the Middle East and North Africa, with a particular focus on the Palestinian Territories. Kaspersky Lab has identified at least three groups within the gang, with similar aims and targets – cyberespionage related to Middle Eastern political interests – but very different tools, techniques and levels of sophistication. There is an element of sharing and overlap between them.

The groups include the more advanced Operation Parliament and Desert Falcons, known since 2018 and 2015 respectively, and an underpinning, less complex group, also known as MoleRats that has been active since at least 2012. In the spring of 2018, this basic group launched operation SneakyPastes.

SneakyPastes began with politically themed phishing attacks, spread using disposable email addresses and domains. Malicious links or attachments that were either clicked or downloaded then installed the infection on the victim device.

In order to avoid detection and hide the location of the command and control server, additional malware was downloaded to victim devices in chained stages using a number of free sites including Pastebin and Github. The various malicious implants used PowerShell, VBS, JS, and dotnet to secure resilience and persistence within infected systems. The final stage of intrusion was a Remote Access Trojan, which made contact with the command and control server and then gathered, compressed, encrypted and uploaded a wide range of stolen documents and spreadsheets to it. The name SneakyPastes derives from the attackers’ heavy use of paste sites to gradually sneak the RAT onto victim systems.

Kaspersky Lab researchers worked with law enforcement to uncover the full cycle of attack and intrusion for the SneakyPastes operation. These efforts have resulted not just in a detailed understanding of the tools, techniques, targets and more, but in the actual takedown of a significant part of the infrastructure.

The SneakyPastes operation was at its most active between April and mid-November 2018, focusing on a small list of targets that comprised diplomatic and government entities, NGOs and media outlets. Using Kaspersky Lab telemetry and other sources, there appear to be around 240 high profile individual and corporate victims, in 39 countries worldwide, with the majority located in the Palestinian Territories, Jordan, Israel and Lebanon. Victims included embassies, government entities, media outlets and journalists, activists, political parties and individuals, as well as education, banking, healthcare and contracting organisations.

“The discovery of Desert Falcons in 2015 marked a turning point in the threat landscape as it was then the first known fully Arabic speaking APT. We now know that its parent, Gaza Cybergang has been actively targeting Middle Eastern interests since 2012, initially relying most on the activities of a fairly unsophisticated but relentless team – the team that in 2018 launched operation SneakyPastes. SneakyPastes shows that lack of infrastructure and advanced tools is no impediment to success. We expect the damage exerted by all three Gaza Cybergang groups to intensify and the attacks to extend into other regions that are also linked to Palestinian issues,” said Amin Hasbini, Head of Middle East Research Center, Global Research and Analysis Team (GReAT) at Kaspersky Lab.

All Kaspersky Lab products successfully detect and block this threat.

In order to avoid falling victim to a targeted attack by a known or unknown threat actor, Kaspersky Lab researchers recommend implementing the following measures:

· Use advanced security tools like Kaspersky Anti Targeted Attack Platform (KATA) and make sure your security team has access to the most recent cyber threat intelligence.

· Make sure you update all software used in your organisation on a regular basis, particularly whenever a new security patch is released. Security products with Vulnerability Assessment and Patch Management capabilities may help to automate these processes.

· Choose a proven security solution such as Kaspersky Endpoint Security that is equipped with behavior-based detection capabilities for effective protection against known and unknown threats, including exploits.

· Ensure your staff understand basic cybersecurity hygiene, as many targeted attacks start with phishing or other social engineering technique.

A report on the Gaza Cybergang’s operation SneakyPastes can be found on Securelist.

About Kaspersky Lab

Kaspersky Lab is a global cybersecurity company, which has been operating in the market for over 21 years. Kaspersky Lab’s deep threat intelligence and security expertise is constantly transforming into next generation security solutions and services to protect businesses, critical infrastructure, governments and consumers around the globe. The company’s comprehensive security portfolio includes leading endpoint protection and a number of specialized security solutions and services to fight sophisticated and evolving digital threats. Over 400 million users are protected by Kaspersky Lab technologies and we help 270,000 corporate clients protect what matters most to them.

ShareTweet
Previous Post

Trend Micro Releases Innovations

Next Post

Home Office apologises after revealing details of hundreds of EU citizens.

Recent News

What Does the Cyber Industry Want to See From the New UK Government?

What Does the Cyber Industry Want to See From the New UK Government?

July 20, 2026
Purple Logo, capitalised letters: SALT.

Salt Security tackles AI governance challenge with 100 pre-built agentic security policies

July 20, 2026
New Continuous Runtime Security Validation service aims to strengthen fintech cyber resilience

New Continuous Runtime Security Validation service aims to strengthen fintech cyber resilience

July 20, 2026
Scams Now Drive Almost Half of All Malware Detections as Attackers Weaponise Everyday Trust

Scams Now Drive Almost Half of All Malware Detections as Attackers Weaponise Everyday Trust

July 20, 2026

Eskenzi PR banner ad

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol