Group5 is known for conducting stealthy cyber operations targeting the Syrian opposition since 2015.
Analyst brief
Group5 is a threat actor observed since late 2015 conducting targeted cyber operations against the Syrian opposition. This actor primarily targets well-connected individuals within Syrian opposition groups. Key TTPs include stealth tactics like Encrypted/Encoded File and File Deletion, combined with collection methods such as keylogging and screen capture, using tools like njRAT and NanoCore. Defenders should focus on watering hole attacks, malicious PowerPoint files, Android malware, and traffic from Iranian hosting companies or IP space.
Group5
G0043
unknown
A threat actor using Iranian-language tools, Iranian hosting companies, operating from the Iranian IP space at times was observed targeting the Syrian opposition in an elaborately staged malware operation, Citizen Lab researchers reveal.
The operation was first noticed in late 2015, when a member of the Syrian opposition flagged a suspicious email containing a PowerPoint slideshow, which led researchers to a watering hole website with malicious programs, malicious PowerPoint files, and Android malware.
The threat actor was targeting Windows and Android devices of well-connected individuals in the Syrian opposition, researchers discovered. They called the actor Group5, because it targets Syrian opposition after regime-linked malware groups, the Syrian Electronic Army, ISIS (also known as the Islamic State or ISIL), and a group linked to Lebanon did the same in the past
Monitor for and restrict applications that can capture keyboard input or screen content, and enforce strict access controls to mitigate keylogging and screen capture.
FAQ2
Who does Group5 primarily target?+
Group5 primarily targets well-connected individuals within Syrian opposition groups.
What malicious tools does Group5 use in its operations?+