Pinstripe Lightning
Microsoft threat actor profile from the public naming mapping feed.
Pinstripe Lightning is a cyber espionage group targeting political and military entities in the Middle East.
Pinstripe Lightning is a threat actor tracked by Microsoft, also known under aliases such as NIOBIUM, RENEGADE JACKAL, Desert Falcons, Scimitar, and Arid Viper. This actor primarily targets political, military, and diplomatic entities in the Middle East region. Their TTPs include phishing, malicious macro documents, and custom Android and Windows trojans like FrozenCell and ViperRAT to establish persistence and steal sensitive data. Defenders should focus on email security, mobile device management, and monitoring for data exfiltration indicators.
Microsoft threat actor profile from the public naming mapping feed.
Pinstripe Lightning primarily targets political, military, and diplomatic entities in the Middle East region.
ViperRAT is one of the custom Android trojans used by Pinstripe Lightning.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.