• About WordPress
    • WordPress.org
    • Documentation
    • Learn WordPress
    • Support
    • Feedback
Skip to content
May 26, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Watchtower
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Vulnerability Report
Light/Dark Button
  • Home
  • News
  • Cyber Security
  • A phishing attack launched against the cyber espionage organisation of the Palestinian government
  • Cyber Security

A phishing attack launched against the cyber espionage organisation of the Palestinian government

Ddos July 9, 2018 2 minutes read
Phishing Simulation

Last year cyberespionage organisation against Palestinian law enforcement agencies has now launched a re-attack against Palestinian government officials. According to a survey by Israeli network security company Check Point, the new attack began in March 2018 and appeared to be consistent with a set of operations detailed in the two reports of Cisco Talos and  Palo Alto Networks last year. The report describes the spear phishing attacks against Palestinian law enforcement agencies. Malicious emails attempt to infect victims through Micropsia info stealer, a Delphi-based malware that contains many references from Big Bang and Power. The string of the game’s episode character.

Now the same cyberespionage organisation seems to be reappearing. The only thing they have changed is malware, now using C++ encoding. Like Micropsia, the new malware is also a powerful backdoor that can be extended at any time using the second stage module. According to Check Point, the organisation uses the improved backdoor to infect victims to collect fingerprints from victim workstations, then collects the names of .doc, .odt, .xls, .ppt, and .pdf files and sends the list to the attack. Server.

This year the organisation appears to be a member of the Palestinian National Authority, and the theme of the spear phishing email is a monthly news report from the Palestinian Political and National Steering Committee, sent to relevant personnel of the agency. Unlike 2017, this malicious attachment is a compressed file containing the bait file and the malware itself.

Check Point believes that behind these attacks is an APT organisation called Gaza Cybergang, also known as Gaza Hackers / Molerats, which in 2016 linked the organisation to the terrorist organisation Hamas. Last week, the Israeli government accused Hamas of trying to lure soldiers into installing malware on their phones.

Source: bleepingcomputer

Rate this post

Support Our Threat Intelligence

If you find our CVE report and cybersecurity news helpful, consider supporting our work.

Buy Me a Coffee Logo Buy Me a Coffee PayPal
Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Share this article:

Facebook Post LinkedIn Telegram

Related posts:

  1. ANY.RUN Confirms Security Incident Involving Employee Email Compromise
  2. TA453 Deploys New BlackSmith Malware Toolset in Phishing Attack on Religious Figure
  3. Phishing Attacks Targeting Higher Education Institutions on the Rise
  4. Rogue RDP: Abusing RDP for File Theft and Espionage
  5. Information Stealer Malware on the Rise: ACSC Issues Urgent Cybersecurity Warning
Tags: Palestinian government phishing attack

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚑

Get notified instantly when a Proof of Concept (PoC) exploit is published.

πŸ”

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

πŸ“Š

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

πŸ”΄ Live Critical Threats

  • CVE-2026-42773CVSS 9.3
    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
  • CVE-2026-42774CVSS 9.3
    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
  • CVE-2026-9478CVSS 9.8
    A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the...
  • CVE-2026-9477CVSS 9.8
    A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This issue...
  • CVE-2026-9476CVSS 9.8
    A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the...
  • CVE-2026-9475CVSS 9.8
    A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This affects the function...
  • CVE-2026-9458CVSS 9.8
    A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is...
  • CVE-2026-9457CVSS 9.8
    A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. The affected element is...
  • CVE-2026-9456CVSS 9.8
    A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function...
  • CVE-2026-9455CVSS 9.8
    A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This issue affects...
Powered by CVE WATCHTOWER

Recent Zero-Day Vulnerabilities

  • Exploited in the Wild: Critical OWA Spoofing Flaw (CVE-2026-42897) Hits On-Premises Exchange Servers
  • Exploited in the Wild: Maximum CVSS 10 SD-WAN Flaw (CVE-2026-20182) Grants Admin Control
  • Exploited in the Wild: Critical 9.8 CVSS RCE Hits Canon GUARDIANWALL MailSuite
  • Exploit Code Released: Public PoC Dumps for Windows BitLocker Bypass and SYSTEM Elevation Zero-Days
  • Exploited in the Wild: “Dirty Frag” Linux Vulnerability Grants Instant Root Access
  • Under Active Attack: Ivanti EPMM Zero-Day Exploited in the Wild via Harvested Admin Credentials
Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • Disclaimer
    • Privacy Policy
    • DMCA NOTICE
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    Copyright Daily CyberSecurity Β© All rights reserved.