CSIDB logo
Incident

Etihad Etisalat Company

Incident posture

Attack window
Jan 2020
Location
Saudi Arabia
Status
Historical
CIA posture
Available to members
Updated
2026-09-26 16:41

Linked entities

Victim
Etihad Etisalat Company
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Q1 2020
Discovered
Undetermined
Disclosed
Jan 2021
Resolved
Pending

Summary

Based on the available information, no specific details about an incident affecting Etihad Etisalat Company are provided in the supplied article. The article describes a broader hacking campaign by a Hezbollah‑linked group targeting various telecom operators and ISPs, but does not name the company among its victims.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

The source material provided does not contain any reference to Etihad Etisalat Company (also known as Mobily) in connection with the Lebanese Cedar cyber‑espionage campaign. That article focuses on a series of intrusions attributed to a Hezbollah‑affiliated threat actor and names several telecom and ISP victims, but Etihad Etisalat Company is not among them. Because the text does not mention the company, there are no disclosed details about a breach, impact, or response actions specific to Etihad Etisalat Company. Consequently, a factual chronology of an incident involving that entity cannot be constructed from the given information. The absence of a mention means that any description of the company’s involvement would be speculative and therefore excluded.

The article reports that the Lebanese Cedar group began its hacking activity in early 2020 and was uncovered by the Israeli firm Clearsky in a report published on 28 January 2021. Clearsky identified at least 250 compromised web servers worldwide, exploiting unpatched Atlassian Confluence (CVE‑2019‑3396), Atlassian Jira (CVE‑2019‑11581) and Oracle Fusion (CVE‑2012‑3152) vulnerabilities. After gaining initial access, the attackers deployed web shells such as ASPXSpy, Caterpillar 2, Mamad Warning and an open‑source JSP file browser, and on internal networks used the Explosive remote access trojan for data exfiltration. The campaign’s victims listed in the source include Vodafone Egypt, Etisalat UAE, SaudiNet in Saudi Arabia and Frontier Communications in the United States. No further technical or impact details are provided for any of those organizations, and the text does not attribute any of the described tactics, techniques or procedures to Etihad Etisalat Company. Therefore, based solely on the supplied article, no narrative of an incident affecting Etihad Etisalat Company can be offered.

Sources

Sources available to members: 1 source.

CSIDB