Stealth Falcon
This threat actor targets civil society groups and Emirati journalists, activists, and dissidents.
UAE-origin nation-state actor known for WMI-based cyber espionage targeting activists and journalists.
Stealth Falcon (FruityArmor, G0038) is a nation-state threat actor originating from the United Arab Emirates. It targets civil society, activists, dissidents, and journalists, primarily in the UAE and UK. Key TTPs include execution via Windows Management Instrumentation (T1047) and Command and Scripting Interpreter (T1059), credential theft from web browsers (T1555.003) and Windows Credential Manager (T1555.004), and C2 communication over Web Protocols (T1071.001) with Symmetric Cryptography (T1573.001). Defenders should focus on detecting anomalous WMI and scripting activity, credential access attempts, and exfiltration over the C2 channel.
This threat actor targets civil society groups and Emirati journalists, activists, and dissidents.
Monitor Windows Management Instrumentation (WMI) and command/script interpreter events and investigate suspicious activities.
Detect and prevent suspicious activities related to extracting credentials from web browsers and Windows Credential Manager.
Monitor suspicious queries related to system network configuration and process discovery and take necessary actions.
Detect and prevent suspicious activities related to collecting data from the local system.
Monitor suspicious network activity using web protocols and inspect encrypted traffic using symmetric cryptography.
Detect and prevent suspicious activities related to exfiltrating data over the C2 channel.
Stealth Falcon primarily operates in the United Arab Emirates and the United Kingdom.
Stealth Falcon primarily targets civil society, activists, dissidents, and journalists, particularly Emirati journalists.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.