This threat actor uses spear-phishing techniques to target parliaments, government ministries, academics, and media organizations, primarily in the Middle East, for the purpose of espionage. Based on our findings, we believe the attackers represent a previously unknown geopolitically motivated threat actor. The campaign started in 2017, with the attackers doing just enough to achieve their goals. They most likely have access to additional tools when needed and appear to have access to an elaborate database of contacts in sensitive organizations and personnel worldwide, especially of vulnerable and non-trained staff. The victim systems range from personal desktop or laptop systems to large servers with domain controller roles or similar. The nature of the targeted ministries varied, including those responsible for telecommunications, health, energy, justice, finance and so on. Operation Parliament appears to be another symptom of escalating tensions in the Middle East region. The attackers have taken great care to stay under the radar, imitating another attack group in the region. They have been particularly careful to verify victim devices before proceeding with the infection, safeguarding their command and control servers. The targeting seems to have slowed down since the beginning of 2018, probably winding down when the desired data or access was obtained. The targeting of specific victims is unlike previously seen behavior in regional campaigns by Gaza Cybergang or Desert Falcons and points to an elaborate information-gathering exercise that was carried out before the attacks (physical and/or digital). With deception and false flags increasingly being employed by threat actors, attribution is a hard and complicated task that requires solid evidence, especially in complex regions such as the Middle East.
Targeted Sectors
Executive Summary
Operation Parliament is a nation-state cyber threat actor conducting targeted espionage campaigns primarily in the Middle East. They use sophisticated spear-phishing techniques to gain access to sensitive government and organizational data, with a focus on ministries related to critical infrastructure.
Goals & Targeting
Operation Parliament's primary goal is intelligence gathering for geopolitical purposes. They specifically target sectors such as telecommunications, energy, health, and finance in the Middle East, indicating a focus on gaining strategic advantages over adversaries involved in regional tensions. The group's targeting strategy suggests they have access to detailed information on organizational structures and personnel in sensitive roles, making them highly effective at compromising their targets.
Enhanced Description
Operation Parliament is a nation-state threat group known for its espionage activities targeting parliaments, government ministries, and academic institutions in the Middle East since 2017. The group primarily utilizes spear-phishing campaigns coupled with custom malware to infiltrate victim systems. Their operations are characterized by meticulous planning and careful analysis of target networks, ensuring they remain under the radar while achieving their objectives. Despite their cautious approach, they exhibit a high level of technical proficiency, leveraging sophisticated tools and techniques to compromise systems and exfiltrate sensitive information.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Operation Parliament has demonstrated a patient and persistent approach in their campaigns, focusing on specific targets rather than broad撒布。他们的活动在2018年初逐渐放缓,可能表明他们已经达到了既定目标或改变了策略。该组织的战术手法显示出高度的专业性和对目标的深入研究,这与其 nation-state 份相符。
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Overall confidence in the data is high based on the observed TTPs and pattern of activity. Further clarity would be beneficial regarding the specific nation-state actor responsible and their exact toolset, which remains elusive and attributed to plausible deniability.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics