Bahamut is a highly capable, likely mercenary espionage actor known for prolific Android and iOS spyware, elaborate fake-persona infrastructure and disinformation, operating across the Middle East and South Asia.
Additional names this actor is known by across other vendors' naming schemes — cross-referenced from external crosswalk sources, not RaqibCTI's own curated aliases (shown at the top of this page). Each source is attributed to its own licence.
Bahamut was named by BlackBerry/Bellingcat and has been active since at least 2017. MITRE tracks the related Windshift activity as G0112, folding 'Bahamut' in as an alias, though several vendors describe Bahamut and Windshift as overlapping-but-separate clusters targeting individuals for surveillance across the Middle East and critical infrastructure.
The group is distinguished by unusually polished operational security and social engineering: bespoke phishing sites, fake news outlets and elaborate personas support delivery of custom mobile spyware. On Android it repackages legitimate VPN, chat and utility apps (e.g., Trojanized SoftVPN/OpenVPN via fake SecureVPN sites, and the 'SafeChat' lure), while historically also fielding iOS profiles and Windows components.
Capabilities focus on exfiltrating messages from WhatsApp, Signal, Telegram, Viber and Messenger, plus documents, photos, location and credentials. ESET documented sustained fake-VPN Android campaigns (2022 onward); other reporting tied SafeChat-style lures to South Asian, particularly Indian, targets.
MENA relevance: Bahamut/Windshift has repeatedly surveilled individuals in Gulf and broader Middle Eastern government and critical-infrastructure contexts, alongside South Asian targeting. Confidence in the activity is high; attribution to any specific state or contracting sponsor is low and remains an open question, consistent with a hack-for-hire model.
+22 more relationships — see the relationships browser.