Also known as: fast16, Asylum Ambuscade, Thallium, Black Banshee, Mythic Leopard, Transparent Tribe, 560048, the Western Sahara, cpyy, APT3, Gothic Panda, UPS Team, TG-0110, DeputyDog, Parastoo, Newscaster, APT28, Pawn Storm, Fancy Bear, Sednit, MiniDionis, Hammertoss, Chinastrats, Patchwork
Starry Addax is a threat actor targeting human rights activists associated with the Sahrawi Arab Democratic Republic using a novel mobile malware called FlexStarling. They conduct phishing attacks to trick targets into installing malicious Android applications and serve credential-harvesting pages to Windows-based targets. Their infrastructure targets both Windows and Android users, with the campaign starting with spear-phishing emails containing requests to install specific mobile apps or related themes. The campaign is in its early stages, with potential for additional malware variants and infrastructure development.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Starry Addax is a threat actor targeting human rights activists associated with the Sahrawi Arab Democratic Republic using novel mobile malware (FlexStarling). Their primary methods include phishing attacks and credential-harvesting campaigns, leveraging both Windows and Android platforms. The campaign is in its early stages, indicating potential growth and expanding threat vectors.
Goals & Targeting
Starry Addax targets human rights activists in the Sahrawi Arab Democratic Republic, likely seeking to gather sensitive information or disrupt activities. Their focus on political dissidents indicates a strategic goal aligning with surveillance or suppression of dissent, potentially linked to geopolitical interests.
Enhanced Description
Starry Addax employs a sophisticated approach to target human rights activists through mobile malware (FlexStarling) and phishing campaigns. They use spear-phishing emails to distribute malicious Android applications and Windows-based credential-harvesting pages. This dual-platform targeting demonstrates technical capability and adaptability. The campaign's early stage suggests possible evolution, with potential for additional malware variants and refined attack techniques.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Campaigns involve early-stage attacks, leveraging spear-phishing emails with Android app requests and Windows-based credential pages. Targets are specific to human rights activists in the Sahrawi Arab Democratic Republic; potential expansion and diversification of attack methods may occur.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Low confidence due to limited data. The operational scope, exact motivation beyond targeting human rights activists, and full range of attack techniques remain unclear.
No techniques linked yet.
No campaigns linked yet.
No observed data linked yet.
0
Techniques
40
Tools
0
Campaigns
4
IOCs
0
Observed Data
0
Tactics