Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Dancing Salome

Description

Dancing Salome is the Kaspersky codename for an APT actor with a primary focus on ministries of foreign affairs, think tanks, and Ukraine. What makes Dancing Salome interesting and relevant is the attacker’s penchant for leveraging HackingTeam RCS implants compiled after the public breach.

AI Analysis

· 1 week ago

Executive Summary

Dancing Salome, a Kaspersky-named APT group, specializes in targeting Ukrainian ministries of foreign affairs, think tanks, and related entities. The actor leverages compromised HackingTeam RCS implants, likely obtained during the 2016 HackingTeam breach, to conduct espionage. This makes the group a significant threat to diplomatic and strategic intelligence operations in Ukraine.

Goals & Targeting

Dancing Salome appears to prioritize intelligence collection focused on Ukrainian foreign policy, defense strategy, and strategic think tank research. The targeting of ministries of foreign affairs and think tanks suggests an objective of gaining insights into diplomatic communications, geopolitical analysis, and national security planning. Ukraine’s geopolitical position as a focal point of regional conflict and its role in international policy likely drive the actor’s interest in this sector. The use of HackingTeam implants implies a focus on compromising sensitive communications infrastructure, potentially to access classified or confidential data.

Enhanced Description

Dancing Salome is a sophisticated, state-sponsored or highly organized APT group with a focus on geopolitical intelligence gathering. The group's use of HackingTeam RCS implants, compiled after the 2016 HackingTeam data breach, suggests an intent to exploit compromised surveillance tools for covert operations. This actor has demonstrated an ability to infiltrate high-value targets, including Ukrainian diplomatic institutions and think tanks, likely to extract sensitive information on foreign policy, defense strategies, and geopolitical initiatives. The reuse of compromised tools highlights the group's resourcefulness in leveraging publicly available exploits for stealthy operations, which may help evade detection by traditional security measures. The actor’s focus on this specific region and sector indicates a strategic interest in Ukraine’s diplomatic and intellectual capital.

Key Capabilities

  • Exploitation of compromised HackingTeam RCS implants for surveillance and data exfiltration
  • Targeted spear-phishing campaigns against diplomatic and think tank entities
  • Stealthy persistence mechanisms leveraging known, outdated surveillance tools for evasion
  • Focused intelligence collection on diplomatic communications and strategic documents

MITRE ATT&CK Tactics

Command and Control
Initial Access
Execution
Collection
Persistence
Discovery

ATT&CK Techniques

T1055 - Data Encoding
T1105 - Custom Command and Control
T1192 - Use of Valid Accounts
T1566.001 - Phishing
T1078 - Valid Accounts
T1059.003 - Remote Services - SSH

Software / Tooling

HackingTeam RCS (compromised implants)

Campaigns & Victims

Dancing Salome’s campaigns appear to be low-frequency but highly targeted, focusing on Ukrainian diplomatic and think tank entities. The actor’s reliance on HackingTeam tools suggests a strategic intent to maintain operational stealth by leveraging compromised, previously legitimate surveillance infrastructure. Campaigns likely involve multi-stage compromises, with initial access achieved through spear-phishing or compromised credentials, followed by lateral movement and data exfiltration. Notable past operations include the targeting of Ukrainian diplomatic networks and academic think tanks, with a focus on compromising communications infrastructure.

IOC Patterns

  • Spear-phishing emails with malicious Office documents embedded with HackingTeam RCS components
  • C2 traffic using domain names registered through bulletproof hosting providers
  • Use of legitimate SSH protocols for command-and-control communication
  • Compromised HackingTeam implant signatures in memory dumps or network traffic

Recommended Actions

  • Monitor for HackingTeam RCS implant signatures in network traffic and endpoint memory dumps
  • Implement advanced email filtering to detect malicious Office documents linked to known campaigns
  • Conduct regular audits of SSH and remote access protocols for anomalous C2 activity
  • Deploy threat intelligence feeds specific to Ukrainian diplomatic and think tank entities
  • Enhance detection capabilities for compromised surveillance tool usage

Suggested Tags

APT
Espionage
Ukraine-sector
Foreign-affairs
HackingTeam-compromised

Confidence Assessment

Confidence in the actor’s targeting focus and use of HackingTeam implants is high, based on Kaspersky’s attribution and observed activity. However, detailed TTPs and campaign-specific IOCs remain limited, and the actor’s broader strategic goals remain partially obscured. Further analysis of network traffic and endpoint behavior could improve confidence in MITRE tactic and technique mappings.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
Backdoor / C2
Espionage
Ukraine-sector
Foreign-affairs
HackingTeam-compromised

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.