Bahamut
- First seen
- 2016-05-01 00:00:00
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- organization
- Actor type
- nation-state
- Last IoC activity
- 2026-07-21 00:32:39
- Profile updated
- 2026-07-07 11:55:24
Targeted industries: government-and-public-sector media-and-entertainment technology-and-telecommunications
Targeted regions: country_code:ae country_code:sa country_code:in
Context
Bahamut is a threat actor primarily operating in Middle East and Central Asia, suspected to be a private contractor to several state sponsored actors. They were observed conduct phishing as well as desktop and mobile malware campaigns.
Reports & references
- bellingcat.com — Bahamut Pursuing Cyber Espionage Actor Middle East (report)
- bellingcat.com — Bahamut Revisited Cyber Espionage Middle East South Asia (report)