Dancing Salome is the Kaspersky codename for an APT actor with a primary focus on ministries of foreign affairs, think tanks, and Ukraine. What makes Dancing Salome interesting and relevant is the attacker’s penchant for leveraging HackingTeam RCS implants compiled after the public breach.
Executive Summary
Dancing Salome, a Kaspersky-named APT group, specializes in targeting Ukrainian ministries of foreign affairs, think tanks, and related entities. The actor leverages compromised HackingTeam RCS implants, likely obtained during the 2016 HackingTeam breach, to conduct espionage. This makes the group a significant threat to diplomatic and strategic intelligence operations in Ukraine.
Goals & Targeting
Dancing Salome appears to prioritize intelligence collection focused on Ukrainian foreign policy, defense strategy, and strategic think tank research. The targeting of ministries of foreign affairs and think tanks suggests an objective of gaining insights into diplomatic communications, geopolitical analysis, and national security planning. Ukraine’s geopolitical position as a focal point of regional conflict and its role in international policy likely drive the actor’s interest in this sector. The use of HackingTeam implants implies a focus on compromising sensitive communications infrastructure, potentially to access classified or confidential data.
Enhanced Description
Dancing Salome is a sophisticated, state-sponsored or highly organized APT group with a focus on geopolitical intelligence gathering. The group's use of HackingTeam RCS implants, compiled after the 2016 HackingTeam data breach, suggests an intent to exploit compromised surveillance tools for covert operations. This actor has demonstrated an ability to infiltrate high-value targets, including Ukrainian diplomatic institutions and think tanks, likely to extract sensitive information on foreign policy, defense strategies, and geopolitical initiatives. The reuse of compromised tools highlights the group's resourcefulness in leveraging publicly available exploits for stealthy operations, which may help evade detection by traditional security measures. The actor’s focus on this specific region and sector indicates a strategic interest in Ukraine’s diplomatic and intellectual capital.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Dancing Salome’s campaigns appear to be low-frequency but highly targeted, focusing on Ukrainian diplomatic and think tank entities. The actor’s reliance on HackingTeam tools suggests a strategic intent to maintain operational stealth by leveraging compromised, previously legitimate surveillance infrastructure. Campaigns likely involve multi-stage compromises, with initial access achieved through spear-phishing or compromised credentials, followed by lateral movement and data exfiltration. Notable past operations include the targeting of Ukrainian diplomatic networks and academic think tanks, with a focus on compromising communications infrastructure.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the actor’s targeting focus and use of HackingTeam implants is high, based on Kaspersky’s attribution and observed activity. However, detailed TTPs and campaign-specific IOCs remain limited, and the actor’s broader strategic goals remain partially obscured. Further analysis of network traffic and endpoint behavior could improve confidence in MITRE tactic and technique mappings.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics