The Desert Dexter Group is a cyber threat actor that emerged with activities traced back to September 2024 and was first publicly identified in February 2025. This group primarily targets individuals and organizations within the Middle East and North Africa (MENA) region. Assessed to be of Libyan origin with moderate confidence, given the significant victimology observed in Libya, their primary motivation is to conduct espionage operations and achieve financial gain through cryptocurrency theft. What distinguishes the group is its reliance on social engineering tactics, specifically exploiting social media platforms like Facebook and Telegram to create fake news groups and disseminate malicious links. They host malicious files on legitimate file-sharing services and specially created Telegram channels. The group is often referred to as Desert Dexter, named after one of its suspected authors.