Houthi/Yemen-Based Disinformation & Influence Campaign Targeting Israel and the Gulf States (ClearSky)

Houthi/Yemen-Based Disinformation & Influence Campaign (TL-2026-0760), also tracked as Yemen-Based Disinformation Campaign Distributing Fake News in Israel and the Arab World, is a medium-severity tracked intrusion set, first published 2026-06-10. It is linked to a Yemen-nexus actor with medium confidence, affects Israel Israeli public / media information space, maps to 9 MITRE ATT&CK techniques (T1566, T1583, T1585), and is covered by 9 detection rules and 30 indicators of compromise.

Key facts for TL-2026-0760

Threat ID
TL-2026-0760
Also known as
Yemen-Based Disinformation Campaign Distributing Fake News in Israel and the Arab World, Houthi Influence Campaign
Severity
MEDIUM
Status
ACTIVE
Category
THREAT_INTEL
First published
2026-06-10
Last reviewed
2026-06-10
Attribution confidence
MEDIUM
Nation-state nexus
Yemen
Motivation
HACKTIVISM
Target sectors
media, government, general public, civil society
Target regions
Israel, Saudi Arabia, United Arab Emirates, Arabian Peninsula, Middle East
Detection rules
9
Indicators of compromise
30

A persistent Yemeni/Houthi-aligned influence operation, active since 2016 and first exposed by ClearSky in 2019, that runs tens of fake media-outlet websites plus fake Facebook/Twitter personas to push fabricated news against Israel and the Gulf. After concentrating on Saudi Arabia and the UAE through 2019-2022, it refocused on Israel from late 2024 and remained active as of April 2025.

How Houthi/Yemen-Based Disinformation & Influence Campaign works

ClearSky Cyber Security has tracked a large-scale, Yemen-based disinformation and influence operation that it assesses is connected to the Houthi (Ansar Allah) movement, an Iran-aligned actor. The infrastructure was established in 2016, publicly exposed in July 2019, and was found still operating in early April 2025 using the same methodology.

The operation is built around several dozen fake media outlets that impersonate legitimate Arab news brands from the Gulf and the Arabian Peninsula. Domains follow a consistent naming convention - the fake outlet name with a hyphen and a 'news' or 'press' token (e.g. nashr-news[.]com, dubai-press[.]com, gulf-press[.]net, noor-press[.]com, gulfecho[.]net). Article content is copied and lightly modified from the Arabic editions of RT and Sputnik, mirroring the tradecraft of the Iranian Global Disinformation Operation (GDO) that ClearSky exposed in November 2018.

Distribution relies on fake social-media personas - frequently impersonating attractive young women - that post links to the fake outlets on the Facebook pages of legitimate Israeli media and in marginal Israeli social-media groups. In the most prominent July 25, 2019 incident, accounts spread fabricated death reports for Israeli actor Yona Elian and singer Roni Dalumi; one persona, handle 'Eilat Takrit' ('Eilat Incident'), seeded the rumor on the official page of the Israeli public broadcaster Kan. Operational-security failures tied several personas to adult men in Yemen (e.g. a profile claiming employment at a Tarim, Yemen business), supporting Yemeni attribution.

Several Arabic-language fake sites also carried out-of-place Hebrew content - copied and translated celebrity, rape and murder stories - indicating dedicated personnel with at least some Hebrew proficiency. Hosting clustered on a small set of European bulletproof-style servers: Online SAS/Scaleway (62.210.102[.]63 / 163.172.232[.]163, poneytelecom.eu / dedibox.fr) and Hetzner (138.201.160[.]9 and 138.201.160[.]2, your-server.de), with shared nameservers and overlapping WHOIS records pointing to Yemen. ClearSky rates the technological link to the Iranian GDO at low-medium certainty while attributing the operation itself to Yemen/Houthi operators.

This is an information-operation threat, not a software vulnerability: there is no CVE, malware family or exploit. The risk is reputational and societal - viral fabricated news, impersonation of trusted media brands, and erosion of public trust during periods of regional conflict.

MITRE ATT&CK techniques used in TL-2026-0760

Initial Access

T1566 Phishing

Resource Development

T1583 Acquire Infrastructure; T1585 Establish Accounts; T1586 Compromise Accounts; T1608 Stage Capabilities

Reconnaissance

T1589 Gather Victim Identity Information; T1591 Gather Victim Org Information; T1593 Search Open Websites/Domains

stealth

T1684.001 Impersonation

Affected products and versions in Houthi/Yemen-Based Disinformation & Influence Campaign

  • Israel — Israeli public / media information space
    Vulnerable versions: Israeli media outlet Facebook pages; Israeli social media groups; public broadcaster Kan audience
  • Saudi Arabia — Saudi public information space
    Vulnerable versions: Saudi Arabia (primary 2019-2022 focus)
  • United Arab Emirates — UAE public information space
    Vulnerable versions: UAE (2019-2022 focus)

Remediation for Houthi/Yemen-Based Disinformation & Influence Campaign

Immediate actions

  • Block and sinkhole the known fake media-outlet domains and hosting IPs (62.210.102.63, 163.172.232.163, 138.201.160.9, 138.201.160.2) at web proxies and DNS resolvers
  • Report impersonating Facebook pages, Twitter/X personas and fake outlet URLs to the respective platforms for takedown
  • Issue rapid official denials through verified channels when fabricated stories (e.g. false celebrity death reports) go viral

Workarounds

  • Pre-bunk and fact-check known recurring narratives (celebrity deaths, fabricated Gulf incidents)
  • Verify breaking stories against primary outlet domains before amplification

Longer-term hardening

  • Stand up a media-monitoring / brand-impersonation detection capability for trusted outlets and public figures
  • Educate the public and newsroom social teams on the campaign's hyphenated 'news'/'press' domain pattern and copied RT/Sputnik content
  • Coordinate with platform trust-and-safety and national CERTs on coordinated inauthentic behavior takedowns

Timeline of Houthi/Yemen-Based Disinformation & Influence Campaign

  • Yemen-based disinformation infrastructure (fake media-outlet network) established, per WHOIS/passive-DNS records.
  • ClearSky exposes the Iranian Global Disinformation Operation (GDO); the Yemeni campaign later mirrors its methodology and copied RT/Sputnik content.
  • Fake personas spread fabricated death reports of Israeli actor Yona Elian and singer Roni Dalumi on Israeli media Facebook pages, including the 'Eilat Takrit' persona posting on the official Kan page.
  • ClearSky publishes its report exposing the large-scale Yemen-based fake-news campaign and its IOCs.
  • Through 2019-2022 the campaign concentrates on Gulf countries, most-covered being Saudi Arabia and Yemen, with UAE-themed outlets (e.g. dubai-press, asdaadubai).
  • Foreign Policy documents Yemen's parallel war in cyberspace involving Houthi/Iran/Saudi information operations.
  • From late 2024 the campaign refocuses targeting on Israel.
  • ClearSky discovers in early April 2025 that the campaign is still operating against Israel, Saudi Arabia and the UAE using the same 2019 methodology.
  • ClearSky publishes its 2025 'Houthi Influence Campaign' update confirming dedicated personnel, funding and Hebrew proficiency.

Sources cited for Houthi/Yemen-Based Disinformation & Influence Campaign

More in threat intel

Detection coverage for TL-2026-0760

As of 2026-06-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0760 across Splunk SPL, Microsoft KQL and Sigma, covering 30 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats