Stealth Falcon

πŸ”΄ High
Also known as: Daffodil Gust, Fruity Armor, FruityArmor, G0038, Project Raven, Stealth Falcon

Stealth Falcon is a threat group that has conducted targeted spyware attacks against Emirati journalists, activists, and dissidents since at least 2012. Circumstantial evidence suggests there could be a link between this group and the United Arab Emirates (UAE) government, but that has not been confirmed. Citizen Lab Stealth Falcon May 2016

🌍 Country United Arab Emirates
πŸ“… Activity 2016 β€” 2016
⚑ Risk Level High
🎯 Incident Type Espionage
🧭 ATT&CK G0038
Activists Dissidents Journalist Civil society
2016
2016

Introduction

Stealth Falcon is a threat group that has conducted targeted spyware attacks against Emirati journalists, activists, and dissidents since at least 2012. Circumstantial evidence suggests there could be a link between this group and the United Arab Emirates (UAE) government, but that has not been confirmed. Citizen Lab Stealth Falcon May 2016

Activities and Tactics

Targeted Sectors: Activists, Dissidents, Journalist, Civil society

Country of Origin: 🏳️ United Arab Emirates

Risk Level: High

First Seen: 2016

Last Activity: 2016

Incident Type: Espionage

Suspected Victims: United Arab Emirates, United Kingdom

Notable Campaigns

Information pending cataloguing.

Tactics, Techniques, and Procedures (TTPs)

ATT&CK technique IDs (denormalized)

Notable Indicators of Compromise (IOCs)

No atomic indicators are listed in this profile. The APTnotes snapshot indexes 1 public reports that may contain IOCs; see Source Attribution for dataset links.

Malware and Tools

  • MS16-120 / CVE-2016-3393 0day exploits:
  • 0day CVE-2018-8453:
  • PowerShell backdoor:
  • CVE-2018-8611:

Attribution and Evidence

Country of Origin: United Arab Emirates Additional attribution information pending cataloguing.

References

[1] mitre-attack [3] Citizen Lab Stealth Falcon May 2016 Marczak, B. and Scott-Railton, J.. (2016, May 29). Keep Calm and (Don’t) Enable Macros: A New Threat Actor Targets UAE Dissidents. Retrieved June 8, 2016.