Saturday, August 15, 2026
LIVE
Ugandan villages still contest land titles as oil development advances///Nigerian Troops Repel Bandit Attack on Kebbi Workers///NLC Queries Lagos Chairman Over Ties to Pro-Tinubu Group///Côte d’Ivoire Names New Leader for Blé Goudé’s COJEP Party///United States Highlights Civilian Deaths in Nigeria Terror Fight///Zimbabwe Pledges New Ferry and Road Repair After Lake Kariba Disaster///Ebola death toll reaches two thousand in Democratic Republic of the Congo///Forced Conscription Reports Emerge Across Ethiopia Oromia Region///Ebola outbreak reaches displacement camps in eastern Democratic Republic of the Congo///Hacking Group Claims Data Theft from Shell and Other Global Firms///Turkey warns of radical measures if Israel rejects Gaza peace deal terms///Nigerian President Urged to Engage Niger Delta Leader for Reelection Campaign///Ugandan villages still contest land titles as oil development advances///Nigerian Troops Repel Bandit Attack on Kebbi Workers///NLC Queries Lagos Chairman Over Ties to Pro-Tinubu Group///Côte d’Ivoire Names New Leader for Blé Goudé’s COJEP Party///United States Highlights Civilian Deaths in Nigeria Terror Fight///Zimbabwe Pledges New Ferry and Road Repair After Lake Kariba Disaster///Ebola death toll reaches two thousand in Democratic Republic of the Congo///Forced Conscription Reports Emerge Across Ethiopia Oromia Region///Ebola outbreak reaches displacement camps in eastern Democratic Republic of the Congo///Hacking Group Claims Data Theft from Shell and Other Global Firms///Turkey warns of radical measures if Israel rejects Gaza peace deal terms///Nigerian President Urged to Engage Niger Delta Leader for Reelection Campaign///
Subscribe
Africa
Independent · Digital
The African Herald
PoliticsAI-assisted

Libyan Refinery Targeted in Prolonged Spy Campaign With AsyncRAT

A recent cyber espionage campaign has targeted Libyan organizations, including an oil refinery, a telecommunications provider, and a state institution, from November 2025 to February 2026. This campaign specifically focused on Libya's critical…

A recent cyber espionage campaign has targeted Libyan organizations, including an oil refinery, a telecommunications provider, and a state institution, from November 2025 to February 2026. This campaign specifically focused on Libya's critical infrastructure, notably within the oil sector, which produced around 1.37 million barrels per day in 2025. This marks the highest output in over a decade.

The attacks utilized the AsyncRAT backdoor, a remote access trojan commonly employed in both cybercrime and state-linked operations. This raises concerns about potential state-sponsored involvement.

The initial point of entry was through spear-phishing emails that were tailored to Libyan political and social events. These emails contained lure documents, including one titled "Leaked CCTV footage – Saif al-Gaddafi's assassination.gz," which was relevant due to the assassination of Saif al-Gaddafi in February 2026.

Compromised systems were found to contain malicious Visual Basic Script (VBS) files with topical names, such as "video_saif_gadafi_2026.vbs." These scripts were downloaded from a file-sharing platform and triggered a multi-stage infection process.

This process involved a PowerShell-based dropper disguised as an image file, which created a scheduled task for persistence, named "devil," and then removed itself to minimize forensic detection.

A recent cyber espionage campaign has targeted Libyan organizations, including an oil refinery, a telecommunications provider, and a state institution, from November 2025 to February 2026.
Kwame Osei · The African Herald

The final payload was AsyncRAT, capable of keylogging, screen capture, credential theft, and remote command execution. The attackers maintained access to at least one oil company network during November and December 2025, and again in February 2026, indicating a focus on intelligence gathering.

Additional samples linked to the campaign were uploaded to VirusTotal as early as April 2025, using Libya-themed naming conventions, such as:

Audio_Libya_algeria.vbs Voice_Egypt_hafter_Libya.vbs Libya_Jordan_File.vbs names_libya444.vbs

These samples followed a similar execution pattern, deploying AsyncRAT and suggesting a coordinated campaign targeting Libyan entities.

Advertisement

While the use of AsyncRAT suggests potential state involvement, attribution remains inconclusive due to its public availability and use by both state actors and financially motivated groups. However, the level of targeting and geopolitical context increase the likelihood of state-aligned interests.

This campaign underscores how cyber actors exploit geopolitical instability to access high-value targets. Libya's political instability and global energy security concerns create an environment conducive to espionage operations.

The campaign serves as a reminder of the growing intersection between cyber threats and global political dynamics, urging organizations, particularly in the energy sector, to remain vigilant against phishing campaigns leveraging current events.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories