Iran-Linked Hackers Target Middle East Universities As Academic Attacks Rise
AGBI reported that Iran-linked groups have targeted academic, logistics and professional-services organisations in the Middle East as CrowdStrike recorded a 17 percent global rise in academic-sector cyber activity.

Middle Eastern organisations accounted for 8 percent of academic-sector cyber targeting observed worldwide between July 2025 and June 2026, according to CrowdStrike's 2026 Threat Hunting Report.
The same research tracked Iran-linked groups pursuing universities, logistics companies and professional-services organisations across the region.
Universities Draw Espionage And Criminal Interest
Static Kitten has sought access to academic institutions through spear-phishing documents carrying malicious code, while also using legitimate remote monitoring and management tools.
The group has been active since at least 2017 and is linked to intelligence collection for Iran.
Universities hold scientific work, technical data and intellectual property that can overlap with national intelligence priorities.
The targets include programmes focused on AI, quantum computing and other advanced technologies.
Campus networks can therefore attract state-linked espionage and financially motivated intrusion at the same time.
CrowdStrike recorded a 17 percent global increase in academic-sector activity during the reporting period, the largest rise among the industries examined.
State-linked operators accounted for 45 percent of the activity and cybercriminals for 55 percent.
Logistics And Professional Services Face A Second Group
Spectral Kitten attempted to infiltrate Middle Eastern logistics and professional-services targets.
CrowdStrike associates the group with destructive operations, although it did not identify the regional victims or say whether ports, shipping companies or freight systems were involved.
North Korean groups were also active in the region.
Famous Chollima used fraudulent identities to obtain remote jobs and divert salaries to Pyongyang, while Stardust Chollima focused on technology, financial-services, professional-services and legal targets.
AI Raises The Volume Of Defensive Leads
CrowdStrike's threat-hunting division is receiving AI-agent-triggered leads at 2.5 times the rate of leads initiated by people.
Adam Meyers, the company's head of counter-adversary operations, said AI is changing how attacks are planned, executed and scaled.
CrowdStrike did not identify the affected Middle Eastern institutions or countries, so direct exposure among GCC universities remains unconfirmed.




















