Bahamut is a highly capable, likely mercenary espionage actor known for prolific Android and iOS spyware, elaborate fake-persona infrastructure and disinformation, operating across the Middle East and South Asia.
Bahamut was named by BlackBerry/Bellingcat and has been active since at least 2017. MITRE tracks the related Windshift activity as G0112, folding 'Bahamut' in as an alias, though several vendors describe Bahamut and Windshift as overlapping-but-separate clusters targeting individuals for surveillance across the Middle East and critical infrastructure.
The group is distinguished by unusually polished operational security and social engineering: bespoke phishing sites, fake news outlets and elaborate personas support delivery of custom mobile spyware. On Android it repackages legitimate VPN, chat and utility apps (e.g., Trojanized SoftVPN/OpenVPN via fake SecureVPN sites, and the 'SafeChat' lure), while historically also fielding iOS profiles and Windows components.
Capabilities focus on exfiltrating messages from WhatsApp, Signal, Telegram, Viber and Messenger, plus documents, photos, location and credentials. ESET documented sustained fake-VPN Android campaigns (2022 onward); other reporting tied SafeChat-style lures to South Asian, particularly Indian, targets.
MENA relevance: Bahamut/Windshift has repeatedly surveilled individuals in Gulf and broader Middle Eastern government and critical-infrastructure contexts, alongside South Asian targeting. Confidence in the activity is high; attribution to any specific state or contracting sponsor is low and remains an open question, consistent with a hack-for-hire model.
| Technique | Name | Tactic | Observed use |
|---|---|---|---|
| T1665 ↗ | Hide Infrastructure | defense evasion | BAHAMUT's operational security is notable for having no domain or IP address cross-over between operational functions -- no domains or IP addresses used to control or distribute Windows malware are reused for phishing or for administering malware for any other operating system. |
| T1036 ↗ | Masquerading | defense evasion | Malicious mobile apps were disguised as legitimate VPN applications (e.g., trojanized SoftVPN/OpenVPN) complete with convincing supporting web presence to appear legitimate to app-store reviewers and users. |
| T1204.002 ↗ | User Execution: Malicious File | execution | Group relies on malware only as a last resort but is highly adept at phishing, tending to aim for mobile phones of specific individuals as a way into an organization, requiring the target to install/open the malicious application. |
| T1203 ↗ | Exploitation for Client Execution | execution | Use of zero-day exploits was identified among the group's Windows malware samples, reflecting a skill level beyond most other known threat-actor groups; specific CVEs were not named in the source. |
| T1566 ↗ | Phishing | initial access | BAHAMUT is behind a number of extremely targeted and elaborate phishing and credential-harvesting campaigns against government officials and private-sector VIPs in the Middle East and South Asia; the group typically uses spearphishing messages as an initial attack vector. |
| T1195.002 ↗ | Supply Chain Compromise: Compromise Software Software Supply Chain (trojanized VPN apps) | initial access | Fake applications -- trojanized versions of legitimate VPN apps such as SoftVPN and OpenVPN, repackaged with Bahamut spyware code -- were used as an initial attack vector; nine malicious iOS apps were found in the Apple App Store and an assortment of Android apps directly attributable to BAHAMUT via unique fingerprints, complete with well-designed websites, privacy policies, and terms of service to bypass Google/Apple store safeguards. |
| T1598 ↗ | Phishing for Information | reconnaissance | The group runs extremely targeted and elaborate credential-harvesting campaigns as part of its phishing operations. |
| T1583.001 ↗ | Acquire Infrastructure: Domains | resource development | The group maintains segmented, non-overlapping domain and IP infrastructure across its Windows malware, phishing, and mobile-malware operations as part of its distinct operational tradecraft. |