Although direct attribution is difficult, it is clear that the security agencies of these countries have established ongoing close relations with groups of threat actors conducting attacks against civil society. In Egypt, entities involved in digital surveillance and cyberattacks operate under the auspices of intelligence agencies reporting to the president, the military, and the Ministry of the Interior.45 In Iran, cyberoperations are primarily conducted under the oversight of the Islamic Revolutionary Guard Corps (IRGC), a powerful military and security organization.46 The governments of both Iran and Syria have utilized cybermilitias (patriotic or state-recruited hackers) for operations conducted against regime opponents. In Syria, the Assad regime relied on different groups of pro-government hackers to help fight the uprising. Most notably, the Syrian Electronic Army (SEA) gained notoriety with aggressive, and at times spectacular, attacks against foreign and opposition targets during the early phase of the conflict. The group also infiltrated the strategic exchanges of rebel fighters.47 As the conflict evolved, its operations slowed, but in late 2017 the SEA once again resurfaced as the regime’s force for online policing and public relations.48 The offensive capabilities of these three regimes have developed in response to the Internet’s increasing strategic significance for national security, economic well-being, and communication. Cyberattacks have become an important instrument in the geopolitical tensions that mark the region—often reflecting ongoing conflicts between rival countries. Saudi Arabia and Iran, for instance, have launched different forms of attacks against each other, including disinformation campaigns and operations against critical infrastructure.49 Resourceful state and non-state actors dubbed Advanced Persistent Threat groups use continuous and sophisticated hacking techniques to gain access to information systems and steal or destroy valuable data. They are often identical or overlapping with threat actors targeting civil society. In addition, threat actors from one country occasionally cooperate with groups in other countries to exchange information on targets or outsource operations. For example, threat campaigns in support of the Syrian regime received assistance from both Russia and Iran.50 Although Egypt, Syria, and Iran have all invested significant resources in Internet controls and surveillance, the digital security experts interviewed for this report agree that the relative capacities of these countries do not match the level of powerful countries like China and Russia. Nonetheless, all three regimes have significant capacity to threaten civil society, and they continue to invest in expanding these capacities. However, their attacks against civil society are often technically simple, using off-the-shelf or pirated malware and techniques, and relying on the security failures of targets. These threat actors compensate for a lack of technical sophistication with thorough social engineering, which enables them to spread efforts for delivering basic malware in carefully crafted messages.51 At the same time, investigations into the technical background of digital attacks against civil society also reveal evidence of constant learning and threat evolution. For instance the “Nile Phish campaign,” attributed to the Egyptian government, initially relied on an open-source phishing tool to do its damage.52 45 Privacy International (2019). State of Privacy in Egypt. https://privacyinternational.org/state-privacy/1001/state-privacy-egypt. 46 Anderson, C., & Sadjadpour, K. (2018). Iran’s cyber threat: espionage, sabotage and revenge. Carnegie Endowment for International Peace. http://carnegieendowment.org/files/Iran_Cyber_Final_Full_v2.pdf. 47 Franceschi-Bicchierai, L. (2015, April 3). The Syrian Electronic Army’s Most Dangerous Hack. Vice Motherboard. https://www. vice.com/en_us/article/nze5nk/the-syrian-electronic-armys-most-dangerous-hack. 48 Abas, A., & Al-Masri, A. (2018, May 17). The new face of the Syrian Electronic Army. OpenCanada. https://www.opencanada.org/ features/new-face-syrian-electronic-army. 49 Kausch, K. (2017). Cheap Havoc: How Cyber-Geopolitics Will Destabilize the Middle East. German Marshall Fund of the United States, Policy Brief No. 35, Berlin. http://www.gmfus.org/publications/ cheap-havoc-how-cyber-geopolitics-will-destabilize-middle-east. 50 Harding, L., & Arthur, C. (2013, April 30). Syrian Electronic Army: Assad’s cyber warriors. The Guardian. https://www.theguardian. com/technology/2013/apr/29/hacking-guardian-syria-background; Scott-Railton, J., Abdulrazzak, B., Hulcoop, A., Brooks, M., & Kleemola, K. (2016, August 2). Group5. Syria and the Iranian Connection. https://citizenlab.ca/2016/08/group5-syria/. 51 Scott-Railton, J. (2016). Security for the high-risk user: Separate and unequal. IEEE Security & Privacy, 14(2), 79-87. 52 Scott-Railton, J.; Marczak, B., Raoof, R., & Maynier, E. (2017). Nile Phish: Large Scale Phishing Campaign Targeting Egyptian Civil Society. The Citizen Lab, Toronto. https://citizenlab.ca/2017/02/nilephish-report/. 15

Select target paragraph3