Security researchers at ClearSky have uncovered an advanced cyber espionagetargeting entities in the Middle East. Also known as “Thamar Reservoir,” the campaign dates back to 2011 and appears to be utilizing sophisticated attack techniques to achieve its goals.
According to the researchers, the attackers are trying to gain access to the computer systems of the targeted victims, with the ultimate goal of compromising their email accounts, while there does not appear to be a financial motive behind the attacks, which demonstrates the involvement of state-sponsored hackers.
In some cases, victims are not a direct target – attackers use the compromised accounts/computers to carry out further attacks against their ultimate targets.
The techniques used by digital espionage actors to carry out attacks are the following:
- Hacking trusted websites to create fake pages
- Use of sophisticated malware
- Phishing emails for the purpose of monitoring and collecting information.
- Phone calls to potential victims
- Sending phishing messages via social networks
Experts point to the low level of sophistication of the attacks: attackers do not take effective measures to conceal their activities and expose the attack infrastructure.
The majority of the victims of the Thamar Reservoir campaign are located in the Middle East, while the list of victims targeted so far includes government and diplomatic organizations, human rights organizations, journalists, and high-ranking executives in the defense and security industries.

