Back to all insights news

HP warns of ultra-realistic PDF invoice lures exploiting ‘Living-off-the-land’ techniques

The HP report uncovered cybercriminals hiding malicious code in pixel image data to infect users, then deleting the evidence to cover their tracks

Neesha Salian
Neesha Salian

16 September, 2025

HP warns of ultra-realistic PDF invoice lures exploiting ‘Living-off-the-land’ techniques

TT

16

Technology giant HP said on Monday that cyber attackers are refining age-old phishing and “living-off-the-land” (LOTL) techniques to bypass traditional detection tools, using highly polished fake PDF invoices and hidden malware in image files, according to its latest Threat Insights Report.

LOTL techniques, where attackers exploit legitimate tools and features built into Windows systems, have long been part of cybercriminals’ playbooks.

But HP researchers said increasingly complex campaigns using multiple, often uncommon binaries are making it harder to distinguish malicious activity from legitimate operations.

Image for illustrative purposes/ Getty Images

From fake PDF invoices to embedded malicious code: what fraudsters are using now

The report highlighted a new wave of sophisticated social engineering lures. In one campaign, attackers embedded a reverse shell in a small SVG image disguised as a realistic Adobe Acrobat Reader invoice, complete with a fake loading bar to trick users. The downloads were geo-fenced to German-speaking regions to hinder automated analysis and delay detection.

Other attacks involved hiding malicious code in Microsoft Compiled HTML Help files within image pixels, which were used to execute multi-step infection chains with LOTL tools like PowerShell and CMD scripts that erased traces of the attack.

Read: UAE cyber body warns of rising breaches linked to public wi‑fi use

HP also observed the resurgent Lumma Stealer malware spreading via IMG archive files, continuing operations despite a law enforcement crackdown in May.

“Attackers aren’t reinventing the wheel, but they are refining their techniques,” said Alex Holland, Principal Threat Researcher at HP Security Lab. “We’re seeing more chaining of living-off-the-land tools and use of less obvious file types, such as images, to evade detection. Take reverse shells – a simple script can achieve the same effect as a full RAT, slipping under the radar.”

HP said these campaigns illustrate the increasing creativity and adaptability of threat actors, who tailor attacks to regions and exploit trusted system tools to avoid detection.

The company said its HP Wolf Security platform allows malware to detonate safely in isolated containers, giving insight into evolving attack methods without endangering customers.

According to the report, data from April-June showed that at least 13 per cent of email threats bypassed one or more email gateway scanners.

Archive files were the most popular delivery type (40 per cent), followed by executables and scripts (35 per cent). Attackers increasingly used .rar files, leveraging trusted software like WinRAR to avoid suspicion.

Living off the land techniques pose challenges

“Living off the land techniques are notoriously difficult for security teams because it’s hard to tell legitimate activity from attacks,” said Dr Ian Pratt, global head of Security for Personal Systems at HP. “Even the best detection will miss some threats, so defense-in-depth with containment and isolation is essential to trap attacks before they can cause harm.”

The HP report analysed data from consenting HP Wolf Security customers between April and June this year.

Hassana Investment Company, AviLease form aircraft leasing JV

The JV will acquire a portfolio of 10 aircraft from AviLease, which are currently leased to Saudi-based airlines

Gulf Business
Gulf Business

16 September, 2025

Hassana Investment Company, AviLease form aircraft leasing JV
Image: AviLease

TT

16

Saudi Arabia’s Hassana Investment Company has partnered with AviLease, the aircraft lessor owned by the Public Investment Fund (PIF), to establish a dedicated aircraft leasing joint venture, the companies said on Monday.

Hassana will hold a majority stake in the venture, while AviLease will act as the aircraft service provider.

The JV will target both international and local investors, aiming to broaden access to aviation financing while supporting Saudi Arabia’s National Aviation Strategy.

JV to acquire aircraft from AviLease

As its first transaction, the joint venture will acquire 10 fuel-efficient aircraft from AviLease, currently leased to Saudi-based airlines.

“This strategic partnership underscores our commitment to investing in resilient assets that generate sustainable, long-term cash flows,” said Hani Aljehani, acting CEO and CIO of Hassana. “Through our collaboration with AviLease, we aim to strengthen our exposure to the aviation leasing sector while advancing the kingdom’s broader aviation aspirations.”

Fahad Al-Saif, chairman of AviLease, said the partnership highlighted the role of Saudi investment institutions in supporting the kingdom’s aviation ambitions and marked the private sector’s first step into this growth area.

He said the venture would also attract both local and international investments to Saudi financial markets.

Edward O’Byrne, CEO of AviLease, said: “Partnering with Hassana reinforces our role as a PIF company delivering long-term value through best-in-class asset management and origination.

“The proposed joint venture is a foundational step in building a scalable platform that supports the growth of Saudi Arabia’s aviation ecosystem.”

Red Sea Global to open Shura Island resorts, golf course soon

Shura Island will eventually feature 11 resorts, with additional openings planned in the coming months

Neesha Salian
Neesha Salian

15 September, 2025

Red Sea Global to open Shura Island resorts, golf course soon
Image: Supplied

TT

16

Red Sea Global (RSG), the Saudi developer behind The Red Sea and AMAALA tourism projects, will open the first phase of resorts and attractions on Shura Island in the coming weeks, marking a key milestone in the kingdom’s efforts to expand luxury tourism.

The initial launch includes the debut of three hotels, SLS The Red Sea, The Red Sea EDITION, and InterContinental The Red Sea Resort, as well as Shura Links, the country’s first island golf course.

“As the heart of The Red Sea, Shura Island represents everything Red Sea Global stands for: bold ambition, deep respect for nature, and a commitment to redefining tourism in Saudi Arabia and beyond,” said John Pagano, group CEO of RSG. “With the soft opening of Shura in the coming weeks, we move closer to achieving our mission to set new standards in regenerative tourism, while realising Vision 2030.”

Read: Red Sea Global’s CEO shares how the firm is delivering on Saudi’s tourism agenda

Red Sea Global’s Shura Island to be home to 11 resorts

Shura Island will eventually feature 11 resorts, with additional openings planned in the coming months, including properties operated by Faena, Fairmont, Four Seasons, Grand Hyatt, Jumeirah, Miraval, Raffles, and Rosewood.

Designed by Foster + Partners under the “Coral Bloom” concept, the dolphin-shaped island integrates architecture with surrounding coral reefs and runs entirely on renewable energy, RSG said.

The destination will be accessible by boat or electric vehicle across the 3.3-kilometre Shura crossing, which includes Saudi Arabia’s longest internal bridge. Red Sea International Airport, already serving domestic and international routes, will add direct Qatar Airways flights from next month.

Alongside its resorts, Shura Island will also host a limited collection of homes, with the first properties expected to be handed over in late 2025.

Shura Links, the 18-hole golf course opening this month, has been designed with sustainability in mind, using eco-friendly water and landscaping systems.

RSG said its wider projects across The Red Sea and AMAALA are expected to create 120,000 jobs, supporting the Kingdom’s Vision 2030 goals of economic diversification and sustainable development.

Money20/20 Middle East kicks off as fintech momentum builds in Saudi Arabia

The event features more than 450 exhibiting brands, over 600 investors and upwards of 45,000 attendees

Neesha Salian
Neesha Salian

15 September, 2025

Money20/20 Middle East kicks off as fintech momentum builds in Saudi Arabia
Image courtesy: Tahaluf

TT

16

Money20/20 Middle East began today at the Riyadh Exhibition and Convention Centre in Malham, marking a major step in the kingdom’s ambition to cement its role as a global fintech hub under Vision 2030. The event will run until September 17.

The event follows the success of 24 Fintech in September 2024, which drew 37,000 attendees, 300 exhibitors, and more than 350 investors. The new edition is nearly double in scale, with over 450 brands, 600 investors, and upwards of 45,000 participants.

Anchored by the theme “Where Money Does Business”, the three-day conference features a high-profile speaker line-up including US CFTC acting chair Caroline D Pham; Ant International president Douglas Feagin; Standard Chartered’s chief data officer Dr Mohammed Rahim; and SWIFT chief innovation officer Tom Zschach.

Sessions across seven stages will cover AI in finance, embedded finance, regulatory harmonisation, and inclusive innovation.

Highlights include Venturescape, a pre-event platform for venture capital deal-making, and the MoneySurge20/20 Pitch Competition, offering $400,000 in equity-free funding for startups.

What participants and attendees have to say about Money20/20

For many, Money20/20 is more than just another fintech gathering. Participants describe it as a rare forum where global players and regional leaders meet on equal footing. Founders view it as a chance to secure capital and partnerships, while banks and regulators see an opportunity to shape the future of finance at a time when policy and innovation are converging in the kingdom and wider Gulf.

We spoke to several attendees, including speakers, about the importance of the event and the opportunities it creates. Their perspectives highlight the different forces shaping the fintech ecosystem — from capital structures and regulation to inclusivity and savings culture — and why Riyadh has become the stage for these conversations. Here are excerpts from discussions.

Armineh Baghoomian, MD and head of EMEA, and co-head of Global Fintech at Partners for Growth, said: “At Money20/20 Middle East, the conversation around funding choices for fintechs is more critical than ever. In markets like Saudi Arabia, equity can be overly dilutive, and commercial banks often lack the flexibility to finance fast-evolving businesses effectively. Growth debt fills that gap, providing a flexible, founder-friendly alternative that enables companies to scale strategically into new markets, invest in talent, or accelerate product development, without giving away too much ownership too soon. At Partners for Growth, we’ve pioneered growth debt globally for over two decades and are proud to bring that expertise to the GCC. In Saudi Arabia, Vision 2030 and the Financial Sector Development Program are fueling fintech innovation at pace, and debt is an essential part of the funding landscape. Partners for Growth was one of the first to introduce structured facilities for fintech in the region, including Sharia-compliant structures, and we have already committed close to $400m to support innovative companies across the GCC.

“I look forward to speaking on the ‘Capital Crossroads: When Should Fintechs Choose Equity, Debt or Credit’ panel to dig into the funding choices fintech founders face. The right capital structure can be the difference between incremental progress and transformative growth, and growth debt is increasingly at the heart of that decision.”

Hisham Al-Falih, co-founder and CEO of Lean Technologies, said: “Money20/20 comes at a time when fintech in the Middle East is moving from the sidelines to the very centre of economic transformation. In Saudi Arabia, the support of Vision 2030 and forward-thinking regulators has created the conditions for this shift, where real-time payments, open financial access, and data-driven innovation are becoming the foundations of a modern economy.

“At Lean, we are building the infrastructure behind this change. It’s what allows the likes of Tabby to extend credit to thousands of consumers traditional lenders overlooked, and what will soon enable freelancers, long excluded from traditional banking, to access the capital they need to grow. Together, these developments signal a financial system being rebuilt for the realities of a digital, inclusive economy, and this is only the beginning of what’s possible for the next generation of financial innovation across MENA.”

Hasan Haider, managing partner, +VC, said: “Money 20/20 is a reminder of how fast fintech is evolving and how much momentum is flowing into the GCC, supporting Saudi Arabia’s Vision 2030 and the Financial Sector Development Program. The conversations around open banking, embedded finance, AI, and regulation speak directly to the realities early-stage founders face. Open banking is unlocking new competition, embedded finance is reshaping customer journeys, AI is moving from hype to practical tools, and regulators are accelerating frameworks for growth. These shifts create opportunity, but for founders, raising capital at this stage remains one of the biggest pain points. Too often it is slow, complex, and lacking in meaningful support.

“At +VC, we exist to change that. We invest early, with transparent terms and rapid decisions, and then partner deeply with founders through mentorship, community, and capital access. This approach has already supported fintech innovators such as Capifly in Saudi Arabia with Sharia-compliant venture finance, Holo in the UAE digitising mortgages, and Mantas building parametric insurance for cloud outages. Our vision is clear: to be the partner of choice for high-growth founders who can execute in these fast-moving spaces. Saudi fintech is just beginning, and we are committed to helping build its category-defining companies.”

Naif AbuSaida, founder of Hakbah, shared, “The Middle East’s fintech sector is poised for significant innovation and growth, as the region strengthens its position as a global financial services hub. In H1 2025 alone, fintech funding tripled YoY to $596m, representing 39 per cent of total capital secured across MENA. Capitalising on this momentum, Money20/20 Middle East is showcasing what the next decade of fintech in the Middle East looks like; the positive impact of public-private partnerships and collaboration; and how innovation in financial services is poised to drive economic growth on a global scale and further contribute to the region’s economic diversification.

“We are delighted to be speaking at the event to illustrate the transformative impact of AI and technology on the region’s savings industry. With more than 1.3 million registered users – 70 per cent of whom are under the age of 30 – there is clear evidence of strong demand for digital solutions that help to transform people’s savings habits. This momentum is helping to build, enable, and empower a new, fully inclusive savings culture in Saudi Arabia, in line with the National Household Savings and Financial Literacy strategy.”

beIN launches beIN STREAM to expand digital footprint in UAE

The beIN STREAM device is now available across the UAE at beIN SHOPS in Yas Mall (Abu Dhabi) and Al Manar Mall (Ras Al Khaimah), through authorised distributors, and online via Amazon.ae, Virgin Megastore, and Noon

Gulf Business
Gulf Business

15 September, 2025

beIN launches beIN STREAM to expand digital footprint in UAE
Image: Supplied

TT

16

beIN MEDIA GROUP, the global sports and entertainment media networks, has officially launched its new subscription service, beIN STREAM, in the United Arab Emirates.

beIN STREAM offers UAE audiences seamless access to premium sports and entertainment content via a Wi-Fi-enabled streaming device that connects directly to any smart TV. Built for convenience and flexibility, the service delivers live and on-demand viewing experiences without long-term commitments.

Subscribers can enjoy exclusive beIN SPORTS coverage, including the UEFA Champions League, tennis Grand Slams, and Formula 1, alongside blockbuster films and top entertainment channels. Each subscription also comes with complimentary access to the beIN CONNECT app, allowing users to stream content anytime, anywhere, across multiple devices.

Read: beIN-backed ACE shuts down Streameast, the world’s largest sports piracy network

The beIN STREAM device is now available across the UAE at beIN SHOPS in Yas Mall (Abu Dhabi) and Al Manar Mall (Ras Al Khaimah), through authorised distributors, and online via Amazon.ae, Virgin Megastore, and Noon.

The launch underscores beIN’s commitment to expanding its digital services and making world-class content more flexible and accessible to diverse audiences in the region.

For more details, visit: bein.com/beinstream

Middle East banks brace for deepfake-driven identity fraud

Middle East banks must shift from reactive to proactive defence strategies, says LexisNexis Risk Solutions director

Rajiv Pillai
Rajiv Pillai

15 September, 2025

Middle East banks brace for deepfake-driven identity fraud
Rob Woods, director, fraud and identity, LexisNexis Risk Solutions/Image: Supplied

TT

16

Financial institutions across the Middle East are facing a new wave of digital fraud, with synthetic identities and AI-powered deepfakes testing the resilience of traditional verification processes. According to Rob Woods, director, fraud and identity, LexisNexis Risk Solutions, the region’s unique demographic and regulatory environment creates both opportunity and vulnerability.

Why the Middle East is a prime target

“The region’s broad diversity of international expatriates living, working and traveling creates a range of identity verification requirements. This complexity allows fraudsters to exploit uncommon identity types to bypass verification processes,” Woods explains. With millions of people moving through the region every year, verification systems can become fragmented, leaving space for fraudsters to innovate.

Advances in generative AI have only sharpened the threat. “Deepfake technology has advanced significantly in the past two to three years thanks in large part to AI. Fraudsters now use these widely accessible consumer tools to create real-time overlaying deepfakes in minutes,” says Woods. The sophistication of these fakes means “humans increasingly struggle to differentiate between authentic and fake videos or images.”

Traditional security controls such as manual reviews or static document checks are no longer sufficient. “AI-powered technology designed to detect deepfakes provides the most effective solution against AI-generated fraud,” Woods stresses.

For banks, the shift to digital-first customer onboarding is a double-edged sword: it enables scale and convenience but also opens the door to AI-enabled synthetic identities. “Detecting legitimate customers in digital onboarding has become progressively more challenging due to high-quality AI-generated deepfakes and the prolific use of synthetic identities,” Woods notes.

He adds that relying heavily on manual processes creates bottlenecks and worsens customer experience. Instead, “banks can use machine learning and deep neural networks to quickly adapt to new fraud tactics. Advanced technological solutions provide the most reliable detection against these attacks.”

Behavioural biometrics as a differentiator

Among the emerging solutions, behavioural intelligence is proving particularly effective. “To detect fraud, behavioural intelligence analyses device signals, such as how a person has historically typed or swiped on a device versus how they are attempting to interact today,” Woods explains.

By identifying subtle differences in how a genuine user engages with their device, banks can spot red flags early. “When combined with deepfake detection, layers of intelligence help differentiate genuine users from synthetic ones,” he adds.

Despite these technological advances, a lack of systemic collaboration remains a weakness in the region. “Fraud prevention is hampered by the lack of a unified online identity system and inconsistent privacy regulations across countries. Companies often hesitate to share information, citing competitive concerns,” says Woods.

He highlights positive momentum in the UAE, where banks are already collaborating within a digital community to exchange fraud intelligence. “Adopting privacy-by-design principles enables fraud intelligence sharing through unique digital identities,” he explains. “Risk insights from data consortiums also play a key role.”

Not all institutions can deploy large-scale, custom fraud detection systems. Smaller banks and fintechs often struggle with budget and resource constraints. But Woods believes scalability is possible through collaboration. “Organisations of any size can join a global community of like-minded entities to share knowledge and combat fraud as a network,” he says.

Through platforms such as LexisNexis Risk Solutions, “tier-one banks, small lenders and fintechs” can tap into shared fraud intelligence and continuous machine learning updates. “An AI-powered solution that enables document authentication and biometric verification helps organisations confidently approve trusted transactions while detecting deepfakes and forged documents,” Woods explains.

The case for regional cooperation

With fraud rings now operating like professional networks, the region needs an equally networked response. “Fraud rings today operate like corporations. They are highly matrixed and networked with one another. What’s the best way to fight a network? The answer is a network that shares risk insights,” Woods argues.

Here, regulators and law enforcement play a pivotal role. “Fraud risk insights become more effective when regulators and law enforcement actively engage by sharing intelligence that leads to arrests and convictions,” he says. Ensuring compliance with privacy laws while enabling secure intelligence exchange will be crucial for long-term resilience.

Woods emphasises that effective fraud prevention cannot come at the cost of user experience. “Fraud prevention and a great customer experience are both business-critical. Both can be achieved at the same time,” he notes.

Read: UAE cyber body warns of rising breaches linked to public wi‑fi use

The solution lies in a risk-based, intelligence-driven approach. “Adding too many layers of authentication or low-tolerance fraud interventions may reduce fraud but risks alienating genuine users. By leveraging frictionless intelligence and network-based decisioning behind the user journey, banks can improve the experience for legitimate customers while applying risk-based authentication to higher-risk transactions.”

The road ahead: new fraud typologies

Looking ahead, Woods expects the fraud landscape in the Middle East to evolve further. “Middle East banks will see a continued rise in authorised push payment fraud and scams, including impersonation and purchase scams,” he says.

“As banks in the GCC improve fraud and authentication controls, fraudsters may involve customers in fraudulent activities to disguise their operations,” Woods warns. To stay ahead, institutions must adopt adaptive, AI-driven tools capable of detecting emerging fraud tactics in real time.

Middle East banks must shift from reactive to proactive defence strategies. Technology, intelligence-sharing, and regulatory alignment will be key to building resilience.

More news in insights