Middle East Cyber Attacks

By Help AG

By 
Nicolai Solling, Director of Technology Services at Help AG, shares insight on the Flame virus and LinkedIn leaks, and the implications for Internet users in the Middle East.
The Middle East has over the last year seen a dramatic rise in malware attacks targeted as both private as well as government organisations recently fell victim to the much talked about Flame virus. Another major security breach that has drawn tremendous media attention has been the leakage of over 6.5 million user passwords from the business networking site LinkedIn.
Before we get into the discussion on the LinkedIn hack, let’s first gain an understanding of the much talked about Flame virus. Kaspersky Labs who first discovered the threat described it as the ‘most complex piece of malicious software yet.’ So with the widespread use of internet enabled devices and the increasing popularity of online portals for critical services such as e-banking in the region, what are the implications of this attack and how can internet users safeguard themselves against it?
Distribution method
The Flame virus is a highly advanced tool set of malicious code that can be executed on a windows based PC to gather or harvest data off the infected machine. It has now been revealed that the virus gains entry onto the machine by exploiting a vulnerability of the Windows Update Service. All updates provided for Windows require a security certificate signed by Microsoft. However, by providing a signed security certificate that appears to belong to Microsoft, the Flame virus bypasses this restriction. The unsuspecting PC then proceeds to download what appears to be a genuine Windows update which is in fact the loader for the Flame virus.
Once the loader has downloaded the actual virus, cyber criminals gain the ability to take screenshots, listen in to conversations through the system microphone and even capture video through an attached webcam.
The Implications
Currently, based on what we know about Flame, it would be safe to say that the average user should lose no sleep worrying about it. Flame wasn’t as distributed as initially feared. If you are running an updated antivirus and follow the normal practices, you will be safe.
The LinkedIn hack
Unlike Flame which was a targeted attack, the hacking of LinkedIn accounts has the potential to affect a tremendously larger group of users. Reports from the company, which had 161 million registered users as of 31 March 2012, suggest that over 6.5 million of these users’ passwords have been leaked from their database.
As a security measure, LinkedIn, and most internet companies, do not store passwords as clear-text but instead use a technique called Password Hashing. Hashing is a mathematical operation which converts the clear-text password into an irreversible hash-value of the password. So what can users do to protect themselves? The first and most obvious thing would be to change their LinkedIn password. Also, while on LinkedIn, users should check their profiles to make sure that no changes have been done. In particular, check the email addresses that have been linked to the profile and ensure that only authorised addresses are in this list.
An example being www.leakedin.org. A word of advice however would be to first change your LinkedIn password and then use this service to check if your old password was leaked.
Finally, make sure you develop your own password policy. This would involve changing your password at least once in two months and using strong passwords that use a combination of lower case, upper case, special characters and numbers. Users tend to re-use passwords across sites such as Facebook, LinkedIn, email accounts and even e-banking services. This is absolutely unacceptable as a single compromised account may lead to all other accounts being jeopardised.

More Sources

Khaleej Times Teach AI in schools to tackle future cybersecurity threats, say experts
News
لماذا تمثل حماية الإدراك المرحلة القادمة في تطور الأمن السيبراني؟

مقال ضيف بقلم أحمد علي، مدير قسم تصميم الحلول في المملكة العربية السعودية لدى شركة Help AG

1000_F_786457236_UiKejC5LhPKIG0WLtzV15rVVrh7XBzp2
News
MENA TECH: Why protecting perception is the next evolution of cybersecurity?

Guest article by Ahmad Ali, Solution Architecture – Manager, KSA, Help AG Every enterprise has always generated data. Increasingly, it is generating something far more valuable; a continuous understanding of itself. For most of the digital era, organizations understood cybersecurity through the lens of information....

Visualisation-of-Digital-Data-Security-Graphics-101439575-1
News
كيف تبني الإمارات الثقة في عصر الذكاء الاصطناعي - CNN

تتنامى أهمية الذكاء الاصطناعي بسرعة كبيرة بصفته سمة مميزة للاقتصادات الحديثة، وتتجه الدول حول العالم إلى توظيف قدراته لتحفيز النمو الاقتصادي والابتكار والتحول الوطني، وتسبق دولة الإمارات هذا التوجه العالمي من خلال دمج الذكاء الاصطناعي ليكون ركيزة أساسية في مختلف الجهات الحكومية والقطاعات الاقتصادية والخدمات العامة

digital-shield-protecting-data-cyber-world_718046-29848
News
Gulf News: Four pillars of trusted innovation to secure the UAE’s digital future.

Artificial intelligence is rapidly becoming a defining capability of modern economies. Around the world, nations are embracing AI as a catalyst for economic growth, innovation, and national transformation. The UAE is taking this one step further by embedding AI as a foundational capability across government, industry, and public services.

1732720821235
News
Khaleej Times: GCC firms shift focus to cyber resilience, sovereignty as AI reshapes threat landscape

Organisations across the Gulf are increasingly prioritising operational resilience and digital sovereignty as cybersecurity strategies adapt to faster, more complex threats, according to a new industry report. The latest annual State of the Market Report 2026 by Help AG highlights a shift away from traditional, reactive security models towards continuous, adaptive systems aligned with broader national and infrastructure goals.

Nikola Kukoljacs Gulf News
News
Help AG Strengthens Cybersecurity Leadership with DESC SOC Certification

Help AG's Security Operations Centre (SOC) has successfully achieved certification from the Dubai Electronic Security Center (DESC). This significant milestone independently validates the strength of our security operations, demonstrating the capabilities, operational maturity, and service excellence that underpin our cybersecurity offerings. The certification covers both our Managed Security Services (MSS) and Managed Security Controls Services (MSC) capabilities, enabling Help AG to deliver certified security services to Dubai Government entities. Beyond the certification itself, this achievement reflects the expertise, dedication, and collaboration of teams across the organization. It is a testament to the high standards we uphold, our commitment to operational excellence, and the trust our customers place in us every day.

Download the Content

I’m interested in the solutions & services from?

(Choose all that apply)

Schedule a Consultation