Bahamut

First seen
2016-05-01 00:00:00
Primary motivation
espionage
Sophistication
advanced
Resource level
organization
Actor type
nation-state
Last IoC activity
2026-07-21 00:32:39
Profile updated
2026-07-07 11:55:24

Targeted industries: government-and-public-sector media-and-entertainment technology-and-telecommunications

Targeted regions: country_code:ae country_code:sa country_code:in

Context

Bahamut is a threat actor primarily operating in Middle East and Central Asia, suspected to be a private contractor to several state sponsored actors. They were observed conduct phishing as well as desktop and mobile malware campaigns.

Reports & references

  • bellingcat.com — Bahamut Pursuing Cyber Espionage Actor Middle East (report)
  • bellingcat.com — Bahamut Revisited Cyber Espionage Middle East South Asia (report)

External references