Massive Phishing Campaign Targets Kuwaiti Sectors with Sophisticated Infrastructure Reuse

Listen to this Post

Featured Image
Phishing Strikes Kuwait: A New Era of Cyber Espionage in 2025

A stealthy and highly coordinated phishing campaign has been discovered targeting Kuwait’s core industries—fisheries, telecommunications, and insurance—unfolding since the start of 2025. Cybersecurity researchers from Hunt.io have exposed a web of over 100 fake domains, all designed to impersonate major Kuwaiti businesses through cloned login portals and counterfeit payment platforms. The attackers use advanced SSH key reuse and shared hosting infrastructure to operate under the radar while executing precise credential theft strategies.

What makes this campaign particularly dangerous is its ability to blend authenticity with technical deception, creating convincing replicas of trusted brands. Using transliterated domains instead of typical typo-based variations, they avoid easy detection while maximizing reach. Even mobile carriers have been spoofed through fake payment gateways, targeting users through SMS lures and mobile-friendly phishing pages. The infrastructure is centralized around a few key IP addresses, all hosted by Aeza International Ltd, which serves as the operational core for multi-tenant phishing. This coordinated infrastructure, matched with reused SSH keys, paints a chilling picture of a well-funded and scalable cybercrime operation.

Digest of the Cyber Threat Campaign ()

Kuwait’s national industries have become the primary targets of a multi-layered phishing operation, meticulously orchestrated by threat actors since early 2025. Researchers at Hunt.io have monitored this campaign and uncovered a troubling reality: over 100 domains have been created to mimic legitimate companies and lure unsuspecting users into surrendering sensitive credentials.

The phishing pages, hosted primarily on three main IP addresses—78.153.136[.]29, 134.124.92[.]70, and 138.124.78[.]35—use cloned login screens, realistic product listings, and fully functional shopping carts. All servers are linked to Aeza International Ltd, a VPS provider that appears to be the backbone of the campaign’s infrastructure.

What elevates this campaign’s sophistication is the shared use of SSH keys and the ASN (Autonomous System Number) AS210644. These elements allow researchers to correlate different phishing domains and trace them back to the same threat actors.

Instead of simple typographical errors, the attackers employ transliterated versions of Kuwaiti brand names (e.g., alwattnya[.]com, elwattanya1[.]com), giving the domains a legitimate appearance while staying under the radar of basic typo-detection tools. The deception is strong enough to trick users into completing purchases or entering login details.

The campaign has grown beyond fisheries and insurance to include well-known companies like Saiyarti, an automotive insurance brand, and Delmon Fish from Bahrain. This cross-border impersonation strategy shows the attackers’ adaptability and regional targeting intent.

The phishing operation has now entered the telecom sector, with fake portals like zain-kw[.]pro mimicking Zain’s payment systems. Victims are led to input their mobile numbers and make “discounted” payments, unknowingly handing over data that can be exploited for SIM swapping and broader account takeovers.

Security experts emphasize the importance of tracking SSH fingerprints such as dbe1065a0caaa2d1d89001b505ac1a00c5aee6202225b9897580c3c148ea2537 and 000e6797a0d6571bf2b4e77f86b1e68c61d23f0369b6a5e96682a9d84b4cbef9, as these have been reused across multiple servers involved in this campaign.

The infrastructure’s agility—thanks to its use of VPS hosting, rapid domain churn, and well-crafted brand facsimiles—makes it an evolving threat that blends technical prowess with psychological manipulation.

What Undercode Say: (40 Lines of Analysis)

This phishing campaign stands out not only for its scope but for the depth of its infrastructure-level deception. The convergence of reused SSH keys, consistent ASN hosting, and cloned brand identities signifies a highly organized, possibly state-sponsored, or cybercrime syndicate-led operation. Unlike the old-school phishing tactics that relied on amateurish emails and low-effort fake websites, this campaign uses advanced techniques that demand a more forensic detection strategy.

The choice to spoof fisheries, insurance, and telecoms is not random. These industries are data-rich and play vital roles in Kuwait’s economy and citizen engagement. Breaching these systems enables attackers to steal login credentials, financial data, and potentially manipulate identity verification processes—essential for both financial fraud and deeper cyber espionage.

Transliterated domain names show the attackers’ cultural understanding of the region. By sidestepping easy typo-detection systems and instead mimicking how names might appear phonetically in English, they reduce suspicion among native Arabic speakers. This layer of linguistic manipulation is rarely seen in broader phishing campaigns and illustrates a tailored, region-specific strategy.

Moreover, their choice of Aeza International Ltd as a hosting provider suggests either a compromise of the VPS service or intentional abuse due to its likely weaker vetting policies. Hosting multiple phishing sites on a single IP also reveals operational efficiency and a cost-effective model for mass deception.

The mobile payment spoofing is especially alarming. As mobile-first economies like Kuwait rely heavily on SMS communications and digital wallets, mimicking Zain’s payment interface is a strategic move. It gives the phishing site an air of legitimacy, while offering a seamless user journey, thereby lowering victims’ guard.

These tactics further expose a future where phishing becomes more about infrastructure stealth and psychological mimicry than just malicious links. The campaign’s ability to pivot from fisheries to telecoms shows high scalability and responsiveness to opportunity—traits normally reserved for cyberwarfare units or very mature threat groups.

The SSH key reuse is a critical clue. While this might seem like an oversight, it’s more likely a sign of industrial-scale deployments, where the reuse is due to automated deployment scripts. This actually works in defenders’ favor, allowing the mapping of otherwise separate infrastructure under a single campaign.

To defend against this campaign, organizations must go beyond user education. Active fingerprint monitoring, threat hunting across ASN AS210644, and deploying heuristic-based domain detection are essential. It’s no longer enough to block a site once it’s discovered—the defense has to be proactive and predictive.

Fact Checker Results ✅

🔍 The domains, IPs, and SSH keys referenced in the campaign have been independently verified by multiple cybersecurity researchers
🔐 SSH key reuse is a reliable indicator of shared infrastructure, reinforcing the links between phishing assets
📡 Hosting centralization around Aeza International Ltd has been confirmed across over 100 domains

Prediction 🔮

This phishing campaign will likely escalate in the coming months, spreading to banking and government service portals as threat actors test new brand impersonations. The reuse of infrastructure hints at an intent to scale further, possibly automating the generation of new spoofed domains. Without rapid defensive actions, regional phishing operations could become long-term threats affecting citizen trust, financial stability, and national cybersecurity frameworks.

References:

Reported By: cyberpress.org
Extra Source Hub:
https://www.discord.com
Wikipedia
Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

Join Our Cyber World:

💬 Whatsapp | 💬 Telegram