HomeSecurityMiddle East war: 149 DDoS attacks "hit" 110 organizations

Middle East war: 149 DDoS attacks hit 110 organizations

Cybersecurity researchers have warned of a surge in hacking activity in retaliation for the coordinated U.S. and Israeli military campaign against Iran . “ The hacking threat in the Middle East is particularly uneven, with two groups, Keymous+ and DieNet, responsible for nearly 70% of all attack activity between February 28 and March 2 , ” Radware said in a report Tuesday. The first DDoS attack was launched by Hider Nex (also known as the Tunisian Maskers Cyber ​​Force) on February 28, 2026.

Middle East DDoS war

According to details shared by Orange Cyberdefense, Hider Nex is a darknet hacking group from Tunisia. It uses a hack-and-leak, combining DDoS attacks with data breaches to leak sensitive data and advance its geopolitical agenda. The group emerged in mid-2025.

Increase in DDoS attacks during war

In total, 149 DDoS attacks were recorded by hackers targeting 110 different organizations in 16 countries.

See also: US banks on alert for Iranian cyberattacks

The attacks were carried out by 12 different groups, including Keymous+, DieNet and NoName057(16), which accounted for 74.6% of the total activity. Of these attacks, the vast majority, 107, were concentrated in the Middle East, disproportionately targeting public infrastructure and state targets. Europe was the target of 22.8% of the total global activity during this period.

Nearly 47.8% of targeted organizations worldwide belonged to the government sector, followed by the financial (11.9%) and telecommunications (6.7%) sectors.

“The digital front is expanding alongside the physical in the region, with hacker groups simultaneously targeting more nations than ever before in the Middle East,” Radware reported. “The distribution of attacks in the region was heavily concentrated in three specific nations: Kuwait, Israel, and Jordan, with Kuwait associated with 28%, Israel with 27.1%, and Jordan with 21.5% of total attacks.”

In addition to Keymous+, DieNet, and NoName057(16), some other groups that have been involved in disruptive operations include Nation of Saviors (NOS), Conquerors Electronic Army (CEA), Sylhet Gang, 313 Team, Handala Hack, APT Iran, Cyber ​​Islamic Resistance, Dark Storm Team, FAD Team, Evil Markhors, and PalachPro (according to data from Flashpoint, Palo Alto Networks Unit 42, and Radware).

See also: Cloudflare: Ready to face any cyber threat from Iran

Middle East war: 149 DDoS attacks hit 110 organizations

Cyber ​​operations recorded so far:

  • Pro-Russian hacking groups , such as Cardinal and Russian Legion , have claimed to have breached Israeli military networks , including the Iron Dome missile defense system .
  • An active SMS phishing campaign has been observed using a malicious copy of the Israeli Home Front Command's RedAlert app to deliver surveillance and malware data-extraction.
  • Islamic Revolutionary Guard Corps (IRGC) targeted the energy and digital infrastructure sectors in the Middle East, hitting Saudi Aramco and an Amazon Web Services in the UAE with the aim of “causing maximum global economic pain as a countermeasure to military losses,” Flashpoint reported.
  • Cotton Sandstorm (aka Haywire Kitten) revived her old cyber persona, Altoufan Team , and claimed to have hacked websites in Bahrain.
  • Data collected by Nozomi Networks shows that the Iranian state-run hacking group, known as UNC1549 (also known as GalaxyGato, Nimbus Manticore, or Subtle Snail), was the fourth most active actor during the second half of 2025, focusing its attacks on defense, aerospace, telecommunications, and regional government agencies to advance the nation's geopolitical priorities.
  • Major Iranian cryptocurrency exchanges remained operational, but announced operational adjustments, either suspending or bundling withdrawals, and issued risk advisories urging users to prepare for possible connectivity disruptions.
  • “What we are seeing in Iran is not clear evidence of a massive capital flight, but rather a market managing volatility under limited connectivity and regulatory intervention,” said Ari Redbord, Global Head of Policy at TRM Labs. “For years, Iran operated a shadow economy that, in part, used cryptocurrencies to evade sanctions, through sophisticated offshore infrastructure. What we are seeing now – under the pressure of war, connectivity disruptions, and volatile markets – is a test of the resilience of that infrastructure and the regime’s ability to leverage it.”
  • Sophos said it "observed an increase in hacker activity, but not an escalation of the threat," mainly from pro-Iranian actors, including the Handala Hack group and APT Iran. The groups mainly carry out DDoS attacks, website defacements.
  • The National Cyber ​​Security Centre (NCSC) has warned organisations of an increased risk of Iranian cyberattacks, urging them to strengthen their cyber posture to better respond to DDoS attacks, phishing activity and ICS targeting.
Middle East war: 149 DDoS attacks hit 110 organizations

In a post shared on LinkedIn, Cynthia Kaiser, Senior Vice President of the ransomware research center at Halcyon and former Deputy Assistant Director in the Cyberspace Division of the Federal Bureau of Investigation, said that Iran has a history of using cyber operations to retaliate for “perceived political offenses,” adding that these activities have increasingly incorporated ransomware.

See also: AWS data centers: Drone attacks caused extensive damage

“Tehran has long preferred to turn a blind eye, or at least ignore, private cyberattacks against targets in the United States, Israel and other allied countries,” Kaiser added. “That’s because access to cybercriminals gives the government options. As Iran considers its response to U.S. and Israeli military actions, it is likely to activate any of these cyber actors if it believes their activities could have a meaningful retaliatory effect.”

Cybersecurity firm SentinelOne has also said that organizations in Israel, the US and allied nations are likely to face cyberattacks, particularly in the sectors of government, critical infrastructure, defense, financial services and media.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

“Iranian threat actors have historically demonstrated a willingness to combine espionage, disruption, and psychological impact operations to advance strategic objectives,” Nozomi Networks said. “In times of instability, these operations often intensify, targeting critical infrastructure, energy networks, government agencies, and private industry far beyond the immediate conflict zone.”

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS