Security incidents in Iraqi cyberspace have begun to show an upward trend, with malicious activity mainly concentrated in Baghdad, Erbil, Basra, and Mosul.
According to a report by Los Angeles-based security firm IntelCrawler, malicious activities in Iraqi cyberspace have intensified over the past two months and new botnets have emerged.
The attackers rely on dynamic DNS services to communicate with the infected systems. Based on recent geopolitical conflicts in the region, the company speculates that the compromised computers could have been used in cyber-espionage campaigns or to carry out targeted attacks.
IntelCrawler reports that many of the malicious domains used as Command & Control servers are registered with free and public DNS providers. “The IP addresses detected were associated with subnets of various regional Internet Service Providers (ISPs) in Iraq, such as GORANNET, IQ-EARTH LINK, IQNETWORKS, IQ-NEWROZ, and IQ-TARINNET,” the company notes in a blog post.
The strongest malicious activity has been recorded in Baghdad, with a percentage exceeding 50%, followed at a safe distance by Erbil, Basra and Mosul.

