Houthi/Yemen-Based Disinformation & Influence Campaign Targeting Israel and the Gulf States (ClearSky)
Houthi/Yemen-Based Disinformation & Influence Campaign (TL-2026-0760), also tracked as Yemen-Based Disinformation Campaign Distributing Fake News in Israel and the Arab World, is a medium-severity tracked intrusion set, first published 2026-06-10. It is linked to a Yemen-nexus actor with medium confidence, affects Israel Israeli public / media information space, maps to 9 MITRE ATT&CK techniques (T1566, T1583, T1585), and is covered by 9 detection rules and 30 indicators of compromise.
Key facts for TL-2026-0760
- Threat ID
- TL-2026-0760
- Also known as
- Yemen-Based Disinformation Campaign Distributing Fake News in Israel and the Arab World, Houthi Influence Campaign
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- THREAT_INTEL
- First published
- 2026-06-10
- Last reviewed
- 2026-06-10
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Yemen
- Motivation
- HACKTIVISM
- Target sectors
- media, government, general public, civil society
- Target regions
- Israel, Saudi Arabia, United Arab Emirates, Arabian Peninsula, Middle East
- Detection rules
- 9
- Indicators of compromise
- 30
A persistent Yemeni/Houthi-aligned influence operation, active since 2016 and first exposed by ClearSky in 2019, that runs tens of fake media-outlet websites plus fake Facebook/Twitter personas to push fabricated news against Israel and the Gulf. After concentrating on Saudi Arabia and the UAE through 2019-2022, it refocused on Israel from late 2024 and remained active as of April 2025.
How Houthi/Yemen-Based Disinformation & Influence Campaign works
ClearSky Cyber Security has tracked a large-scale, Yemen-based disinformation and influence operation that it assesses is connected to the Houthi (Ansar Allah) movement, an Iran-aligned actor. The infrastructure was established in 2016, publicly exposed in July 2019, and was found still operating in early April 2025 using the same methodology.
The operation is built around several dozen fake media outlets that impersonate legitimate Arab news brands from the Gulf and the Arabian Peninsula. Domains follow a consistent naming convention - the fake outlet name with a hyphen and a 'news' or 'press' token (e.g. nashr-news[.]com, dubai-press[.]com, gulf-press[.]net, noor-press[.]com, gulfecho[.]net). Article content is copied and lightly modified from the Arabic editions of RT and Sputnik, mirroring the tradecraft of the Iranian Global Disinformation Operation (GDO) that ClearSky exposed in November 2018.
Distribution relies on fake social-media personas - frequently impersonating attractive young women - that post links to the fake outlets on the Facebook pages of legitimate Israeli media and in marginal Israeli social-media groups. In the most prominent July 25, 2019 incident, accounts spread fabricated death reports for Israeli actor Yona Elian and singer Roni Dalumi; one persona, handle 'Eilat Takrit' ('Eilat Incident'), seeded the rumor on the official page of the Israeli public broadcaster Kan. Operational-security failures tied several personas to adult men in Yemen (e.g. a profile claiming employment at a Tarim, Yemen business), supporting Yemeni attribution.
Several Arabic-language fake sites also carried out-of-place Hebrew content - copied and translated celebrity, rape and murder stories - indicating dedicated personnel with at least some Hebrew proficiency. Hosting clustered on a small set of European bulletproof-style servers: Online SAS/Scaleway (62.210.102[.]63 / 163.172.232[.]163, poneytelecom.eu / dedibox.fr) and Hetzner (138.201.160[.]9 and 138.201.160[.]2, your-server.de), with shared nameservers and overlapping WHOIS records pointing to Yemen. ClearSky rates the technological link to the Iranian GDO at low-medium certainty while attributing the operation itself to Yemen/Houthi operators.
This is an information-operation threat, not a software vulnerability: there is no CVE, malware family or exploit. The risk is reputational and societal - viral fabricated news, impersonation of trusted media brands, and erosion of public trust during periods of regional conflict.
MITRE ATT&CK techniques used in TL-2026-0760
Initial Access
Resource Development
T1583 Acquire Infrastructure; T1585 Establish Accounts; T1586 Compromise Accounts; T1608 Stage Capabilities
Reconnaissance
T1589 Gather Victim Identity Information; T1591 Gather Victim Org Information; T1593 Search Open Websites/Domains
stealth
Affected products and versions in Houthi/Yemen-Based Disinformation & Influence Campaign
- Israel — Israeli public / media information space
Vulnerable versions: Israeli media outlet Facebook pages; Israeli social media groups; public broadcaster Kan audience - Saudi Arabia — Saudi public information space
Vulnerable versions: Saudi Arabia (primary 2019-2022 focus) - United Arab Emirates — UAE public information space
Vulnerable versions: UAE (2019-2022 focus)
Remediation for Houthi/Yemen-Based Disinformation & Influence Campaign
Immediate actions
- Block and sinkhole the known fake media-outlet domains and hosting IPs (62.210.102.63, 163.172.232.163, 138.201.160.9, 138.201.160.2) at web proxies and DNS resolvers
- Report impersonating Facebook pages, Twitter/X personas and fake outlet URLs to the respective platforms for takedown
- Issue rapid official denials through verified channels when fabricated stories (e.g. false celebrity death reports) go viral
Workarounds
- Pre-bunk and fact-check known recurring narratives (celebrity deaths, fabricated Gulf incidents)
- Verify breaking stories against primary outlet domains before amplification
Longer-term hardening
- Stand up a media-monitoring / brand-impersonation detection capability for trusted outlets and public figures
- Educate the public and newsroom social teams on the campaign's hyphenated 'news'/'press' domain pattern and copied RT/Sputnik content
- Coordinate with platform trust-and-safety and national CERTs on coordinated inauthentic behavior takedowns
Timeline of Houthi/Yemen-Based Disinformation & Influence Campaign
- Yemen-based disinformation infrastructure (fake media-outlet network) established, per WHOIS/passive-DNS records.
- ClearSky exposes the Iranian Global Disinformation Operation (GDO); the Yemeni campaign later mirrors its methodology and copied RT/Sputnik content.
- Fake personas spread fabricated death reports of Israeli actor Yona Elian and singer Roni Dalumi on Israeli media Facebook pages, including the 'Eilat Takrit' persona posting on the official Kan page.
- ClearSky publishes its report exposing the large-scale Yemen-based fake-news campaign and its IOCs.
- Through 2019-2022 the campaign concentrates on Gulf countries, most-covered being Saudi Arabia and Yemen, with UAE-themed outlets (e.g. dubai-press, asdaadubai).
- Foreign Policy documents Yemen's parallel war in cyberspace involving Houthi/Iran/Saudi information operations.
- From late 2024 the campaign refocuses targeting on Israel.
- ClearSky discovers in early April 2025 that the campaign is still operating against Israel, Saudi Arabia and the UAE using the same 2019 methodology.
- ClearSky publishes its 2025 'Houthi Influence Campaign' update confirming dedicated personnel, funding and Hebrew proficiency.
Sources cited for Houthi/Yemen-Based Disinformation & Influence Campaign
- Houthi Influence Campaign (2025 update)
- Yemen-Based Disinformation Campaign Distributing Fake News in Israel and the Arab World (full report w/ IOCs)
- ClearSky Cyber Security on X - Yemeni/Houthi influence campaign disclosure
- Global Iranian Disinformation Operation (GDO)
- Houthi Influence Campaign - malware.news mirror
- Yemen's Parallel War in Cyberspace
- Amid US conflict, Houthis leverage Western social media to spread their message (Kharon)
More in threat intel
- Microsoft Defender Antivirus Exclusion Abuse: Attackers Set and Hide Exclusions (HideExclusionsFromLocalAdmins) to Evade MDAV
- Attackers Abuse Microsoft Defender Exclusions with HideExclusionsFromLocalAdmins to Evade Antivirus Scans
- Insiders for Hire: Underground Market for Employee Access Expands Beyond Privileged IT Roles
- Agentic AI used for post-exploitation in breach of the Dutch Institute for Vulnerability Disclosure (DIVD)
- Hacker-for-Hire Economy: Cyber Mercenaries Offer Account Compromise, Surveillance, Doxxing and DDoS as a Service
Detection coverage for TL-2026-0760
As of 2026-06-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0760 across Splunk SPL, Microsoft KQL and Sigma, covering 30 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.