META & Pakistan Intelligence Insights Report, July 2025
← Research Hub

META & Pakistan Intelligence Insights Report, July 2025

Discover what shaped the threat landscape across the Middle East, Turkey, Africa (META), and Pakistan this July.

Group-IB’s monthly Intelligence Insights offers a concise summary of major cybercrime trends, critical vulnerabilities, and regional campaigns impacting your business environment. Our July edition reveals growing trends in signed driver abuse, vulnerability exploitation, and region-specific phishing campaigns targeting key sectors.

Key Highlights

Critical SharePoint Vulnerabilities ExploitedCritical SharePoint Vulnerabilities Exploited

Two zero-day flaws (CVE-2025-53770 and CVE-2025-53771) in on-premises SharePoint were exploited in mid-July by multiple threat actors, including Storm-2603, Linen Typhoon, and Violet Typhoon, leading to remote code execution and ransomware attacks.

Abuse of Signed Kernel DriversAbuse of Signed Kernel Drivers

Group-IB’s blog “Exploiting Trust” reveals how attackers still obtain valid Microsoft signatures to run malicious Windows kernel drivers, bypassing defenses and gaining deep system control.

 

Regional Trends

 

Real Estate Lure Targets MEA
A fake DocuSign-themed real estate document was used to deliver remote access malware — resembling tactics used by MuddyWater and Brazil-based clusters.

 

QR Code Phishing on the Rise
Attacks impersonating company staff use QR codes to harvest credentials, with some spoofing internal IT infrastructure.

 

New Classiscam Activity in GCC
A new wave of phishing scams targeting users across the GCC was detected in July.

Stay ahead of threats with timely intelligence from Group-IB.

 

Download the July 2025 META & Pakistan Intelligence Insights and equip your team with actionable knowledge to bolster your cyber defense.