Group-IB today announced the launch of Masked Actors: BelArabi, the first Arabic-language edition of its global Masked Actors podcast. The series brings Group-IB’s frontline threat intelligence and investigations to Arabic-speaking audiences, opening with a deep dive into the motivations behind state-linked cyber activity and how geopolitics can shape the threat landscape across the Middle East, Türkiye, and Africa (META).
Masked Actors: BelArabi is an original Arabic-language production, not a translation of the English-language series. Developed for Arabic-speaking audiences across the region, it turns complex cyber threat intelligence into accessible, locally grounded conversations about who is behind cyberattacks, why they happen, and how understanding an adversary’s motivations and behavior can help organizations identify emerging threats earlier.
According to Group-IB’s High-TechCrime Trends 2026 report, as digital ecosystems expand rapidly across the Middle East and Africa, the cyber threat landscape is becoming more complex and nuanced, with tracked phishing activity disproportionately targeting high-impact sectors like internet services (52.49%) and financial institutions (28.50%). With these evolving challenges and attacks impacting communities and organizations inthe region, building broad digital risk awareness is more critical than ever.
Across the season, the series will examine the different forces shaping cybercrime in the region,including state-linked activity, the cybercriminal economy, and hacktivism, helping bridge this gap by breaking down how threat actors operate into simple, accessible language for diverse regional audiences. It will explore the boundaries between state, criminal, and hacktivist activity as they are becoming increasingly blurred, making an understanding of adversaries’ motivations, behavior, and infrastructure critical to effective cyber defense.
The recently aired first episode, hosted by Mohammad Younis, Cyber Investigation Specialist at Group-IB, in conversation with Mansour Alhmoud, Cyber Intelligence Analystat Group-IB, explores what drives cyberattacks — from financial and ideological motivations to state-linked activity — before examining MuddyWater, a state-linked threat actor that Group-IB has tracked since 2017.
Drawing on Group-IB’s recent investigations into MuddyWater, the episode examines most recent threat activity targeting organizations across the META region, and highlighting Operation Olalampo, which occurred days before the US-Iran war started, and introduced four new malware families and showed signs of AI-assisted development. The research provides a real-world example of Group-IB’s Prediction-First approach: tracking malicious activity while it is still unfolding and giving organizations earlier visibility into emerging threats.
The series reflects Group-IB’s wider approach in the Middle East and Africa: combining global threat visibility with local expertise, languages, and region-specific intelligence. Group-IB operates Digital Crime Resistance Centers in the United Arab Emirates, Saudi Arabia, and Egypt, where locally based experts investigate and analyze threats affecting organizations across the region.
“Cybersecurity conversations in this region are often borrowed from elsewhere. With Masked Actors: BelArabi, we wanted to start with our region’s own realities and make the intelligence behind them accessible in Arabic,” said Mohammad Gamal, Cyber Investigation Specialist at Group-IB. “It is not simply about explaining how an attack works. We want listeners to understand who may be behind it, what motivates them, and why that context matters to organizations operating here.”
“Understanding why an attack happens is as important as understanding how,” said Mansour Alhmoud, Cyber Intelligence Analyst at Group-IB. “When we understand an adversary’s motivations, behavior, and infrastructure, we have more context to recognize emerging activity earlier. Our research into MuddyWater demonstrates why this matters: intelligence is most valuable when it gives defenders time to act while an operation is still unfolding, rather than simply explaining what happened afterward.”











