Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Starry Addax

Also known as: fast16, Asylum Ambuscade, Thallium, Black Banshee, Mythic Leopard, Transparent Tribe, 560048, the Western Sahara, cpyy, APT3, Gothic Panda, UPS Team, TG-0110, DeputyDog, Parastoo, Newscaster, APT28, Pawn Storm, Fancy Bear, Sednit, MiniDionis, Hammertoss, Chinastrats, Patchwork

Description

Starry Addax is a threat actor targeting human rights activists associated with the Sahrawi Arab Democratic Republic using a novel mobile malware called FlexStarling. They conduct phishing attacks to trick targets into installing malicious Android applications and serve credential-harvesting pages to Windows-based targets. Their infrastructure targets both Windows and Android users, with the campaign starting with spear-phishing emails containing requests to install specific mobile apps or related themes. The campaign is in its early stages, with potential for additional malware variants and infrastructure development.

Goals & Targeting

Targeted Sectors

Government
Non profit
Financial services
Defense
Telecommunications
Education
Energy
Aerospace
Media
Healthcare
Manufacturing
Mining
Information technology
Maritime
Think tank
Critical infrastructure
Aviation
Pharmaceutical
Food agriculture
Chemical
Legal services
Utilities
Oil gas
Hospitality
Nuclear
Entertainment

Targeted Countries / Regions

US
CN
IN
GB
JP
DE
UA
KR
PL
RU
TW
IR
KZ
TR
IL
SA
VN
FR
CA
BR
MX
AU
PK
NL
AZ
AE
SG
ES
IQ
BY
KP
IT
SY
RO
EG

AI Analysis

· 1 week ago

Executive Summary

Starry Addax is a threat actor targeting human rights activists associated with the Sahrawi Arab Democratic Republic using novel mobile malware (FlexStarling). Their primary methods include phishing attacks and credential-harvesting campaigns, leveraging both Windows and Android platforms. The campaign is in its early stages, indicating potential growth and expanding threat vectors.

Goals & Targeting

Starry Addax targets human rights activists in the Sahrawi Arab Democratic Republic, likely seeking to gather sensitive information or disrupt activities. Their focus on political dissidents indicates a strategic goal aligning with surveillance or suppression of dissent, potentially linked to geopolitical interests.

Enhanced Description

Starry Addax employs a sophisticated approach to target human rights activists through mobile malware (FlexStarling) and phishing campaigns. They use spear-phishing emails to distribute malicious Android applications and Windows-based credential-harvesting pages. This dual-platform targeting demonstrates technical capability and adaptability. The campaign's early stage suggests possible evolution, with potential for additional malware variants and refined attack techniques.

Key Capabilities

  • Mobile malware development
  • Phishing campaigns
  • Credential-harvesting techniques
  • Dual-platform targeting

MITRE ATT&CK Tactics

Phishing
Exploitation for Impact

ATT&CK Techniques

T1566.001

Software / Tooling

FlexStarling malware

Campaigns & Victims

Campaigns involve early-stage attacks, leveraging spear-phishing emails with Android app requests and Windows-based credential pages. Targets are specific to human rights activists in the Sahrawi Arab Democratic Republic; potential expansion and diversification of attack methods may occur.

IOC Patterns

  • Spear-phishing emails
  • Malicious Android application distribution
  • Windows credential-harvesting pages
  • C2 communication infrastructure

Recommended Actions

  • Enhance phishing detection mechanisms
  • Monitor for new mobile malware variants
  • Strengthen mobile device security policies
  • Educate employees on threat recognition

Suggested Tags

Mobile Threat
Geopolitical Espionage
Human Rights Sector

Confidence Assessment

Low confidence due to limited data. The operational scope, exact motivation beyond targeting human rights activists, and full range of attack techniques remain unclear.

ATT&CK Techniques

No techniques linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. blog.talosintelligence.com — Cited by web research for: Asylum Ambuscade
  2. blog.talosintelligence.com — Cited by web research for: Thallium
  3. www.cyfirma.com — Cited by web research for: 560048
  4. therecord.media — Cited by web research for: the Western Sahara
  5. misp-galaxy.org — Cited by web research for: cpyy
  6. news.risky.biz — Cited by web research for: CVE-2024-26234

Intel Summary

0

Techniques

40

Tools

0

Campaigns

4

IOCs

0

Observed Data

0

Tactics

Tags

Phishing
Mobile Threat
Geopolitical Espionage
Human Rights Sector

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.