Arbian Ghosts is a hacktivist group observed in the context of the 2025 surge of Middle Eastern cyber activity associated with the Israel-Iran conflict. The group has been identified as targeting Jordan as part of broader regional spillover operations conducted by numerous hacktivist collectives during that period. Available reporting places Arbian Ghosts among politically motivated actors participating in disruptive cyber campaigns rather than as a clearly established state-sponsored intrusion set. High-confidence public information directly linking the group to specific malware families, intrusion tradecraft, or sustained espionage activity is currently limited. Based on confirmed reporting, Arbian Ghosts is best characterized as a regional hacktivist actor associated with politically motivated targeting of Jordan during the conflict-driven escalation of cyber operations in the Middle East.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.