Back to all transport news

Red Sea International Airport begins handling both domestic and international flights

RSI is positioned within three hours’ flying time for 250 million people and within eight hours for 85 per cent of the global population

Rajiv Pillai
Rajiv Pillai

12 August, 2025

Red Sea International Airport begins handling both domestic and international flights
Employees of Red Sea International Airport/Image: Supplied

TT

16

Red Sea Global (RSG), the developer behind the regenerative tourism destinations The Red Sea and AMAALA, has announced that Red Sea International Airport (RSI) – operated by daa International – is now receiving both domestic and international flights, marking a significant step forward in its phased operations.

Domestic services have transitioned to the airport’s Main Terminal Building at Terminals 3 and 4, offering travellers an upgraded and seamless experience. International arrivals and seaplanes will continue to operate through the dedicated Air Taxi Terminal, ensuring smooth connectivity for visitors from around the world.

Every arrival into RSI brings guests closer to the natural beauty and distinctive experiences of The Red Sea. Whether visiting for leisure, adventure, or business, travellers can expect a journey that reflects the destination’s focus on innovation and hospitality.

Located 90 km south of Al Wajh on Saudi Arabia’s west coast, RSI is positioned within three hours’ flying time for 250 million people and within eight hours for 85 per cent of the global population. More than a transport hub, RSI is designed to embody the vision of The Red Sea destination, offering a world-class passenger experience inspired by desert, oasis, and sea.

With its main terminal set to be fully operational by the end of the year and more flight connections planned, RSI is preparing to become a gateway to one of the world’s most unique tourism destinations, with a target to serve one million guests annually by 2030.

From pit lane to mainframe: Globant’s Federico Pienovi on how AI is redefining F1

Each F1 car churns out 400GB of data per race, virtually enough to outpace the computing demands of an entire small business in a weekend

Federico Pienovi
Federico Pienovi

12 August, 2025

From pit lane to mainframe: Globant’s Federico Pienovi on how AI is redefining F1
Image: Supplied

TT

16

Few arenas combine raw human grit with technological brilliance quite like Formula 1. The roar of engines, precision manoeuvres, and split-second decisions have long been the hallmarks of this sport. But as the 2025 season charges ahead, a quiet shift is unfolding. Formula 1 (F1) isn’t just a battle of horsepower and courage anymore. It’s turning into a silent war waged with algorithms, neural networks, and cloud computing. With 1.5 terabytes of data generated per car per race weekend, the smartest team, not just the fastest, holds the edge. Welcome to F1’s new era: the code-driven arms race.

Let’s put this transformation into perspective. Each F1 car churns out 400GB of data per race, virtually enough to outpace the computing demands of an entire small business in a weekend. These raw metrics include telemetry, essentially the heart and pulse of the car’s performance, driver behavior analysis, tire pressure readings, and even real-time fuel consumption models.

The deeper truth? Cars today produce over one million data points per second during races. With teams crunching these numbers mid-race, decisions on vital elements like pit stops, tire changes, and fuel consumption are no longer instinctive, they’re informed by cutting-edge technology. When milliseconds dictate outcomes, precision is key, and AI has taken the wheel.

Gone are the days when a race engineer relied solely on experience and intuition to plan pit stops. Today’s AI systems evaluate over 150 parameters—from braking consistency and tire wear patterns to more nuanced metrics like driver stress responses to optimise each split-second maneuver.

It’s this obsessive command of data that allowed George Russell to squeeze out 97 per cent tire efficiency from medium compounds in 2023. In contrast, Lewis Hamilton achieved a still-impressive 94 per cent, highlighting how AI-guided insights are even differentiating performance among teammates.

Predictive analytics have transformed pit lane strategy. Through simulations and real-time learning, AI effectively answers questions before humans have thought to ask them: When is the exact moment to pit for maximum tire balance? How do fuel consumption rates shift as track temperatures climb? Which corner profile triggers driver fatigue? It’s a high-speed game of peering into the future playing out in milliseconds.

Racing simulations beyond the track

Step aside, traditional simulators; digital twins are in the game. These hyper-accurate simulations recreate cars and drivers down to their molecular behaviour, allowing teams to test countless strategies without ever setting a tire on the asphalt. The beauty of digital twins lies in their predictive value. By modelling whole car systems based on environmental inputs – humidity, track temperature, or even wind resistance – teams can anticipate performance shifts before they occur.

In many ways, digital twins embody F1’s transformation into not just a sport but a cutting-edge laboratory. The physical car becomes a manifestation of its virtual twin’s relentless experimentation. Could this mean the end of the once-revered gut instincts of drivers and engineers? Some followers of the “old F1” might argue so.

The silent race engineer

Edge computing has emerged as a game-changer in the pit lane. Teams can extract actionable insights with minimal latency by processing data locally during the race, without waiting for cloud-based solutions, teams can extract actionable insights with minimal latency.

Think of it this way: when you’re hurtling around a corner at 200 miles per hour, the difference between a half-second delay and instant feedback from the car can mean the difference between pole position and disaster.

As a key player in F1’s digital transformation, Globant’s Pitwall solution serves one crucial purpose: faster, more refined data delivery. Spectators can tap into real-time feeds of the analytics driving every lap, a digital experience as exciting as the race itself. Our collaboration with Formula 1 mirrors our work in other sports, such as FIFA and the LA Clippers. But our commitment to advancing AI-driven technologies within F1 sets us apart, highlighting how brands are becoming vital to the sport’s evolution.

The fan experience is also undergoing a transformation, thanks to augmented reality, predictive analytics, and interactive race streaming. Augmented reality overlays now provide intricate breakdowns of tire degradation and driver stress levels, all in real time.

Fans can witness firsthand the algorithms behind pit decisions, understanding in vivid detail why a driver switches from soft tires to mediums at a critical juncture.

F1 is no longer confined to the track, it’s flowing through the screens of millions worldwide.

Code versus courage: Losing the human element?

In this age of endless innovation, a simmering question remains: As Formula 1 becomes increasingly bespoke to AI, is the sport losing its human soul? Purists argue the sport’s essence lies not just in technology but in raw courage, the ability to take intuitive risks, to feel the vibrations of the car beneath you, to believe in a gut-driven moment that AI can’t quantify.

Yet, others counter this nostalgia by pointing to F1’s core appeal: competition. And if competition demands a smarter car rather than just a faster one, this evolution is simply logical. After all, making the driver-machine relationship stronger doesn’t dilute the sport, it enhances it.

F1 of the 2025 season is no longer just a race, it’s a high-speed chess match played between cloud infrastructure and edge computing, coded intuition and physical skill.

The millisecond decisions that once belonged solely to drivers and engineers now live within neural networks and predictive models. As the sun rises on this data-driven era, the car that wins isn’t just fast, it’s smart.

The CEO of New Markets at Globant

Bahrain and Qatar take diverging paths on data sovereignty: what businesses must know

Bahrain and Qatar are both actively building the region’s digital future but they do so from different starting points

Rajiv Pillai
Rajiv Pillai

12 August, 2025

Bahrain and Qatar take diverging paths on data sovereignty: what businesses must know
Gareth Mills, partner at Charles Russell Speechlys/Image: Supplied

TT

16

As Gulf states race to become digital hubs, two neighbours are carving very different approaches to data governance. Bahrain has invested in cloud and data-centre capacity and adopted a pragmatic, adequacy-style model for cross-border flows. Qatar is pursuing a centralised, sovereignty-first playbook—backed by a GDPR-style law, a state-led cloud framework and big infrastructure bets. Both trajectories create real commercial opportunities, but they also reshape compliance, cloud strategy and operational resilience for any firm doing business in the region.

That is the succinct read from Gareth Mills, partner at Charles Russell Speechlys, who has been advising clients on data, cloud outsourcing and cross-border transfers across the Gulf. “Qatar is positioning itself as a leader in digital sovereignty and regulatory readiness through a deliberate, top-down strategy,” he says. “This is primarily driven by the Qatar National Vision 2030 and the National Digital Agenda 2030 (NDA2030).”

Below is a practical, B2B guide to what Mills told us — why the two countries differ, where the enforcement risks lie, how banks and telcos should think about hosting and cloud, and what firms should do now to stay compliant and resilient.

Two contrasting strategies: centralised control vs. cloud enablement

Qatar is building a centrally governed digital stack. The state has layered a GDPR-style statute (the QPDPPL / Law No. 13 of 2016), guidance from the National Data Privacy Office, a Cloud Policy Framework that emphasises security (rather than blanket localisation) and investments in hyper-computing and national digital identity. Mills points to the coordinated, top-down nature of policy: the Ministry of Communications and Information Technology is playing a leading role, and the overall programme is designed to create both legal certainty and sovereign control over strategic digital assets.

Bahrain’s posture is different. As Mills explains, Bahrain “recognises the importance of data sovereignty but does not impose stringent data localisation requirements,” and it has sought to build local hosting capacity alongside a rules-based cross-border regime. The kingdom has actively attracted cloud and hyperscaler investment — AWS operates a regional data centre there — and private projects such as BEYON’s $700m “Digital City” further expand hosting and connectivity options. Bahrain’s Cloud Law also contains novel mechanisms — including “data embassy” arrangements that allow data stored in Bahrain to remain governed by the rules of another jurisdiction — boosting both flexibility and investor comfort.

The practical takeaway: Qatar is designing for sovereign control while enabling controlled openness; Bahrain is building cloud and data infrastructure and using an adequacy model to facilitate cross-border flows. Both are attractive, but your legal and technical strategy should match which regime applies to your licence and operations.

PDPL (Bahrain) vs QPDPPL (Qatar): the headline differences

Both laws share privacy fundamentals, but their operational shape is very different.

  • Data localisation and transfers. As Mills notes, “Bahrain’s PDPL does not impose strict localisation mandates; there is no general requirement compelling organisations to store personal data within Bahraini territory.” Instead Bahrain relies on an adequacy list: only transfers to jurisdictions on that list (currently 83 countries) proceed without additional approval; other countries need PDPA authorisation or are managed via contractual safeguards. Qatar’s onshore statute, by contrast, “adopts a markedly permissive stance” — transfers may flow freely unless they would cause “serious damage” to data subjects, placing the burden on the exporter to assess and document risks.
  • Enforcement approach. Bahrain’s PDPA has strong investigatory powers and a willingness to impose penalties, including fines and criminal sanctions for grave breaches. Qatar’s National Data Privacy Office historically took an education and guidance first approach, but Mills flags a change: since late 2024 regulators in Qatar have been taking a firmer enforcement stance, issuing binding decisions to correct material compliance gaps. The QFC (Qatar Financial Centre) meanwhile applies GDPR-style rules with clearer adequacy lists and contract-based transfer mechanisms.
  • Practical consequence. In Bahrain expect prescriptive controls and active supervisory action; in Qatar expect a risk-assessment, documentation and DPIA-heavy model on the mainland, and a stricter, GDPR-aligned model inside the QFC. Organisations operating across both need a dual compliance track and consistent internal safeguards.

Licensing and registration: what businesses must do on day one

Mills highlights that obligations vary widely depending on the licence and the regulator:

  • Qatar (dual system). Mainland entities governed by the QPDPPL must implement internal governance (a Personal Data Management System), maintain Records of Processing Activities and perform DPIAs for high-risk processing. There is no universal public register, but prior authorisation is required for processing “personal data of a special nature” (health, religion, children, criminal records). Entities in the QFC follow QFC DPR rules and the QFC DPO’s processes, which are closer to GDPR norms.
  • Bahrain. Data controllers must register with the PDPA and notify processing activities. Data processors may also have registration duties depending on their role. Transfers to non-adequate jurisdictions require PDPA approval.

In practice: before you process any sensitive categories in either jurisdiction, map your licence (mainland vs free zone), compile RoPAs, embed DPIAs in project lifecycles and ensure you have documented approvals where required.

Sensitive personal data: sector implications

Both jurisdictions regard certain categories of data as especially high risk, but definitions and routes to lawful processing differ:

  • Qatar (mainland and QFC divergence). Onshore Qatar defines “personal data of a special nature” to include health, religious beliefs, ethnic origin, criminal records and children; the QFC’s list broadens further to include political opinions and biometric data. Mills stresses the operational impact: “Healthcare: This sector faces the most stringent controls. Patient health information is sensitive under both regimes, mandating explicit consent and regulatory pre-approval … Telecoms: Operators must obtain explicit, opt-in consent for direct marketing …”.
  • Bahrain. Processing sensitive data is generally prohibited without consent, except for enumerated exceptions (healthcare provision, public interest, legal claims, etc.). Financial services and telecoms must therefore build explicit consent mechanisms, robust security and carefully justified processing bases.

For regulated sectors such as healthcare, financial services and telcos, that means: pre-approval workflows (where required), enhanced technical protections, and rigorous consent and access controls.

Read: Data breach costs in Middle East drop 18% as AI adoption grows

Cross-border transfers: pick the right tool for the job

Mechanisms differ by jurisdiction and by licence:

  • Qatar (mainland). There are no fixed standard contractual clauses mandated; instead exporters must document DPIAs and draft bespoke contractual protections. For particularly sensitive transfers, prior regulatory approval may be required.
  • Qatar (QFC). Mirroring the EU model, the QFC recognises a list of “adequate” jurisdictions (EEA, UK, Canada, Japan, South Korea, Switzerland, Uruguay and California), and provides official SCCs and the option of BCRs.
  • Bahrain. The PDPA’s adequacy list (83 countries) simplifies flows to those jurisdictions. Transfers to non-listed countries require PDPA authorisation and submission of contracts.

Mills’ practical rule: adopt a dual-track approach. Use DPIAs and tailored contract clauses for mainland Qatar flows; rely on QFC / PDPA adequacy mechanisms or SCCs/BCRs when operating under those regimes. Where feasible, align your internal policy to the stricter of the two frameworks — that simplifies governance and reduces legal friction.

Financial services and telecoms: local rules matter more than you think

Sector regulators impose additional constraints that often trump general data law:

  • Qatar Central Bank (QCB). Retail banks and insurers face stringent localisation for customer data and tight cloud outsourcing rules. Material cloud outsourcing requires prior QCB approval and contractual terms that preserve supervisory access.
  • QFC regulator (QFCRA). Wholesale firms may outsource to global cloud providers, subject to safeguards that preserve regulatory oversight and adequacy protections.
  • Bahrain (CBB). The Central Bank of Bahrain mandates cloud and security standards for financial firms, which steers hosting choices toward providers with onshore capability.

Telcos in both jurisdictions must meet opt-in rules for marketing and special protections for children’s data. The upshot: cloud strategy must be sector-aware — a bank cannot rely on the same sourcing model as a non-regulated e-commerce operator.

Operational resilience and cloud contracts: the non-negotiables

Mills highlights the operational checklist regulators expect to see:

  • ISO-level security (ISO 27001), encryption in transit and at rest, role-based access controls and multi-tenancy protections.
  • Audit rights, SLAs with measurable recovery time objectives, and executable exit and portability plans to prevent vendor lock-in.
  • Disaster recovery and business continuity plans that are demonstrable to the regulator.

For Qatari onshore entities, the regulator expects documented risk assessments for every cross-border transfer and active monitoring of third-party controls. For Bahrain, while operational resilience rules are still maturing, expectations are moving in the same direction. Practically: get your contracts right now (with audit and termination rights), and test failover plans periodically.

Law-enforcement access: prepare policies and playbooks

Both countries allow authorities to requisition data under national security and criminal law — often with wide discretion. As Mills summarises: “Qatar’s Cybercrime Law (2014), Telecom Law (2006), and Criminal Procedure Code empower national security and law enforcement agencies to access or intercept data, often without judicial oversight in security cases.” Bahrain likewise provides mechanisms for authorised inspectors to exercise law-enforcement powers.

Recommendation: establish a formal disclosure playbook — verification steps, proportionality checks, secure transfer controls and a rigorous logging regime. Limit disclosures to legal requirements, keep careful records, and train front-line staff to escalate any unusual requests.

Cross-border M&A, outsourcing and dispute readiness

Mills emphasises a commercial lens: data governance is now a deal and risk variable. Buyers will insist on strong RoPAs, evidence of DPIAs, encryption posture, and contractual remedies. Vendors must be able to show regulatory licences, approvals for sensitive processing, and tested incident response playbooks. For cross-border M&A and large outsourcing deals, the ability to demonstrate continuous compliance — not just a point-in-time audit — materially affects valuations.

Looking ahead

Mills believes that looking ahead, legal experts anticipate that GCC data governance frameworks will evolve rapidly, particularly in response to digital transformation and the rise of AI. Laws are likely to address ethical and privacy considerations around data usage and algorithm transparency, while cybersecurity regulations will tighten — potentially mandating minimum standards for firewalls, intrusion detection, encryption, and secure access controls, with sector-specific variations. For long-term resilience, businesses should invest in robust cybersecurity infrastructure, deploy technology solutions that support compliance, such as encryption and data management platforms, train employees regularly on data protection practices, and conduct periodic audits to identify gaps and vulnerabilities before regulators do.

Bottom line

Bahrain and Qatar are both actively building the region’s digital future but they do so from different starting points. Bahrain has doubled down on cloud capacity and an adequacy-style transfer model; Qatar is centralising governance, investing in sovereign digital infrastructure, and moving toward more assertive enforcement. For businesses that operate across the Gulf, that means designing compliance programs that are jurisdiction-aware, sector-sensitive and operationally hardened.

“Businesses should stay informed about these developments to ensure compliance,” Mills says. His practical advice is clear: treat data governance as a core part of commercial strategy, not a legal afterthought. Do that, and your cloud, outsourcing and cross-border plans will be ready for the next wave of Gulf digitalisation.

Definitions

JurisdictionFull TermAcronymNotes
Qatar (Mainland)The Personal Data Privacy Protection Law (No. 13 of 2016)QPDPPLThe primary data protection law governing onshore Qatar.
The National Cyber Security AgencyNCSAThe regulatory authority responsible for the QPDPPL.
The National Data Privacy OfficeNDPOThe specific office within the NCSA that handles data privacy matters and enforcement.
The Communications Regulatory AuthorityCRARegulates the telecommunications sector and authored the Cloud Policy Framework.
The Qatar Central BankQCBRegulates financial institutions and imposes data localisation rules.
Qatar (QFC)The Qatar Financial CentreQFCA separate economic zone with its own legal and regulatory framework.
The QFC Data Protection Regulations 2021QFC DPRThe GDPR-aligned data protection law applicable within the QFC.
The QFC Regulatory AuthorityQFCRAThe financial regulator for entities licensed within the QFC.
The QFC Data Protection OfficeQFC DPOThe data protection regulator within the QFC.
BahrainPersonal Data Protection Law (No. 30 of 2018)PDPLThe primary data protection law for Bahrain.
The Personal Data Protection AuthorityPDPAThe data protection regulator in Bahrain.
The Central Bank of BahrainCBBThe financial regulator in Bahrain.
General TermsPersonal Data of a Special NatureN/ATerm used in the QPDPPL (Qatar Mainland) for sensitive data categories.
Sensitive Personal DataN/ATerm used in the QFC DPR and Bahrain PDPL for sensitive data categories.
Data Protection Impact AssessmentDPIAA risk assessment required for high-risk processing or transfers under the QPDPPL.
Standard Contractual ClausesSCCsA mechanism for legitimising cross-border data transfers, officially adopted by the QFC.

MENA IPOs raise $2.5 bn in Q2, Saudi Arabia dominates listings: EY

The UAE saw a single listing, Dubai Residential REIT, which raised $584m on the Dubai Financial Market

Neesha Salian
Neesha Salian

12 August, 2025

MENA IPOs raise $2.5 bn in Q2, Saudi Arabia dominates listings: EY
Image: Getty Images/ For illustrative purposes

TT

16

Initial public offerings (IPOs) in the Middle East and North Africa (MENA) raised $2.5bn in Q2 2025, up 4 per cent from the previous quarter, driven largely by Saudi Arabia’s market activity, EY said in its latest MENA IPO Eye report.

Saudi Arabia accounted for 13 of the quarter’s 14 listings, raising a total of $1.9bn across sectors including transportation and healthcare.

Low-cost carrier flynas led proceeds, contributing 44 per cent of the quarter’s total, followed by Specialized Medical Company with $500m and United Carton Industries Company with $160m.

The UAE saw a single listing, Dubai Residential REIT, which raised $584m on the Dubai Financial Market. It became the largest real estate investment trust by market capitalisation in the Gulf Cooperation Council and the first pure-play residential leasing REIT in the region.

MENA region is a dynamic market for IPOs

“The second quarter of this year has reinforced the MENA region’s position as a resilient and dynamic IPO market,” said Brad Watson, MENA EY-Parthenon leader. “The diversity of sectors represented, along with milestone listings such as Dubai Residential REIT, highlights the depth of opportunities across the region.”

While 10 of the quarter’s IPOs closed below their offer price on debut, five recorded gains. EY noted issuers were increasingly strategic about timing, with 64.3 per cent of IPOs in Q2 being secondary listings, up from 35.7 pe cent in Q1.

“Saudi Arabia continues to set the pace for IPO activity in the MENA region, attracting strong interest across multiple sectors,” said Gregory Hughes, MENA EY-Parthenon IPO leader.

The Boursa Kuwait Premier Market Index led regional equity gains in Q2, up 17.2 per cent, while other markets posted mixed results.

The pipeline for Q2includes 14 expected listings, 10 from Saudi Arabia, with others planned in Egypt, Tunisia and Morocco.

UAE authority intensifies efforts: Dhs357m collected in taxes, fines

In a statement issued on August 11, the FTA revealed that its inspection teams carried out 85,500 field visits during the first half of the year

Gulf Business
Gulf Business

11 August, 2025

UAE authority intensifies efforts: Dhs357m collected in taxes, fines
Image credit: WAM/Website

TT

16

The Federal Tax Authority (FTA) in UAE has significantly ramped up its oversight and inspection efforts in 2025, conducting record-breaking field visits to ensure tax compliance across UAE markets.

Read-UAE firms must register for corporate tax by July 31 to avoid Dhs10,000 penalty

In a statement issued on August 11, the FTA revealed that its inspection teams carried out 85,500 field visits during the first half of the year. This represents a 110.7 per cent increase compared to the same period in 2024, when 40,580 inspections were conducted, a WAM report said.

The authority said these campaigns aim to enhance compliance, protect consumer rights, and combat tax evasion in collaboration with relevant government bodies.

Sharp rise in collected taxes and fines

As a result of these inspections, the FTA reported that it had collected a total of Dhs357.22m in taxes and fines, an 86.29 per cent increase compared to Dhs191.75m collected during the same period in 2024.

The inspections were carried out across various markets and sectors, focusing on detecting violations of tax laws, particularly in the excise tax segment.

Surge in seized non-compliant products

One of the most striking outcomes of the campaign was the seizure of over 17.6 million non-compliant excise goods, up 144.44 per cent from 7.2 million items confiscated in the first half of 2024.

Among these were 11.52 million packs of non-compliant tobacco products, which lacked Digital Tax Stamps and were not registered in the FTA’s electronic system. This figure more than doubled compared to 5.52 million packs seized during the same period last year, an increase of 108.7 per cent.

Additionally, the FTA seized 6.1 million non-compliant goods such as soft drinks, energy drinks, and sweetened beverages. That number was more than 3.5 times the 1.74 million such goods seized in H1 2024, marking an increase of over 250 per cent.

Technology-driven oversight

Sara AlHabshi, Executive Director of Tax Compliance in the Tax Affairs Sector at the FTA, highlighted the Authority’s expanded efforts in enforcing tax legislation.

“Our intensified inspections are a critical part of our strategy to combat tax evasion and protect consumers from non-compliant products that fail to meet market standards,” AlHabshi said.

She noted that the FTA is leveraging advanced digital technologies to boost the effectiveness and efficiency of its inspection operations.

“These technologies are essential in identifying and tracking smuggled goods that do not meet the UAE’s tax requirements. They allow us to respond quickly and thoroughly to violations,” she added.

Continued market oversight

AlHabshi also emphasised the FTA’s commitment to maintaining ongoing inspection campaigns in partnership with strategic government entities across the UAE.

“Our goal is to strengthen market control mechanisms and ensure transparency and governance across all tax procedures,” she said. “This helps prevent the sale, storage, or distribution of products that violate tax laws.”

The Authority confirmed that such inspections will remain a core component of its regulatory mandate throughout the remainder of 2025.

Kaspersky warns of rising Efimer trojan attacks on crypto users

Kaspersky recommends implementing strong security measures to prevent unauthorised access

Rajiv Pillai
Rajiv Pillai

11 August, 2025

Kaspersky warns of rising Efimer trojan attacks on crypto users
Image: Getty Images

TT

16

Kaspersky Security Network has reported that between October 2024 and July 2025, more than 5,000 users — including both individuals and organisations — were targeted by the Efimer trojan, a malicious program designed to steal and replace cryptocurrency wallet addresses. The campaign was particularly damaging in Brazil, which saw approximately 1,500 victims, but also impacted users in India, Spain, Russia, Italy, and Germany.

Initially detected in October 2024, early versions of Efimer were spread through compromised WordPress websites. By June 2025, attackers had expanded their methods, distributing the malware via phishing emails. These emails, disguised as correspondence from a legal firm, threatened recipients with lawsuits over alleged domain name patent violations to pressure them into downloading malicious files.

“This Trojan is notable for its dual approach to spreading — targeting both individual users and corporate environments with different tactics. For private users, attackers use torrent files pretending to be popular movies to lure victims, while in corporate settings, they rely on fraudulent emails containing legal threats. Crucially, in both cases, compromise only occurs if the user actively downloads and executes the malicious file,” explained Artyom Ushkov, threat researcher at Kaspersky.

Read: New Kaspersky module targets voice phishing

Kaspersky advises both corporate and individual users to avoid downloading torrent files from unverified sources, verify the legitimacy of email senders, and keep antivirus databases up to date. Users should also refrain from clicking on links or opening attachments in unsolicited emails, ensure software is regularly updated, enforce strong passwords and two-factor authentication, and continuously monitor for potential compromises. Installing a trusted security solution and following its recommendations can automatically mitigate most threats.

For developers and website administrators, Kaspersky recommends implementing strong security measures to prevent unauthorised access and stop malware from propagating through their infrastructure.

The full report is available on Securelist.com.

More news in transport