Dancing Salome is an APT actor targeting diplomatic entities, known for using leaked HackingTeam RCS implants.
Analyst brief
Dancing Salome is an APT actor primarily targeting Ministries of Foreign Affairs, think tanks, and entities related to Ukraine. This group is notable for leveraging HackingTeam RCS implants that were compiled after the public breach of those tools. Defenders should prioritize monitoring for indicators of compromised HackingTeam tools and closely scrutinize systems connected to diplomatic networks for anomalies.
Dancing Salome
unknown
Dancing Salome is the Kaspersky codename for an APT actor with a primary focus on ministries of foreign affairs, think tanks, and Ukraine. What makes Dancing Salome interesting and relevant is the attacker’s penchant for leveraging HackingTeam RCS implants compiled after the public breach.