Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Operation Parliament

Operation Parliament

TLP:CLEAR
Active

Description

This threat actor uses spear-phishing techniques to target parliaments, government ministries, academics, and media organizations, primarily in the Middle East, for the purpose of espionage. Based on our findings, we believe the attackers represent a previously unknown geopolitically motivated threat actor. The campaign started in 2017, with the attackers doing just enough to achieve their goals. They most likely have access to additional tools when needed and appear to have access to an elaborate database of contacts in sensitive organizations and personnel worldwide, especially of vulnerable and non-trained staff. The victim systems range from personal desktop or laptop systems to large servers with domain controller roles or similar. The nature of the targeted ministries varied, including those responsible for telecommunications, health, energy, justice, finance and so on. Operation Parliament appears to be another symptom of escalating tensions in the Middle East region. The attackers have taken great care to stay under the radar, imitating another attack group in the region. They have been particularly careful to verify victim devices before proceeding with the infection, safeguarding their command and control servers. The targeting seems to have slowed down since the beginning of 2018, probably winding down when the desired data or access was obtained. The targeting of specific victims is unlike previously seen behavior in regional campaigns by Gaza Cybergang or Desert Falcons and points to an elaborate information-gathering exercise that was carried out before the attacks (physical and/or digital). With deception and false flags increasingly being employed by threat actors, attribution is a hard and complicated task that requires solid evidence, especially in complex regions such as the Middle East.

Goals & Targeting

Targeted Sectors

Government

AI Analysis

· 1 week ago

Executive Summary

Operation Parliament is a nation-state cyber threat actor conducting targeted espionage campaigns primarily in the Middle East. They use sophisticated spear-phishing techniques to gain access to sensitive government and organizational data, with a focus on ministries related to critical infrastructure.

Goals & Targeting

Operation Parliament's primary goal is intelligence gathering for geopolitical purposes. They specifically target sectors such as telecommunications, energy, health, and finance in the Middle East, indicating a focus on gaining strategic advantages over adversaries involved in regional tensions. The group's targeting strategy suggests they have access to detailed information on organizational structures and personnel in sensitive roles, making them highly effective at compromising their targets.

Enhanced Description

Operation Parliament is a nation-state threat group known for its espionage activities targeting parliaments, government ministries, and academic institutions in the Middle East since 2017. The group primarily utilizes spear-phishing campaigns coupled with custom malware to infiltrate victim systems. Their operations are characterized by meticulous planning and careful analysis of target networks, ensuring they remain under the radar while achieving their objectives. Despite their cautious approach, they exhibit a high level of technical proficiency, leveraging sophisticated tools and techniques to compromise systems and exfiltrate sensitive information.

Key Capabilities

  • Spear-phishing with malware payloads
  • Custom-built backdoors for persistence
  • Network lateral movement techniques
  • Credential dumping operations
  • Data exfiltration via encrypted channels

MITRE ATT&CK Tactics

Initial Access
Execution
Lateral Movement
Credential Access
Exfiltration

ATT&CK Techniques

T1059.003 - Spear phishing Attachment
T1078 - Valid Accounts
T1003.001 - Keylogger
T1566.001 - Intercept Data
T1203 - Credential Access from Files

Software / Tooling

Custom phishing malware
Backdoors for persistence
Keylogging tools
C2 Infrastructure

Campaigns & Victims

Operation Parliament has demonstrated a patient and persistent approach in their campaigns, focusing on specific targets rather than broad撒布。他们的活动在2018年初逐渐放缓,可能表明他们已经达到了既定目标或改变了策略。该组织的战术手法显示出高度的专业性和对目标的深入研究,这与其 nation-state 份相符。

IOC Patterns

  • Spear-phishing emails with malicious attachments
  • C2 communication using encrypted protocols
  • Presence of custom malware related to the group's campaigns
  • Unusual network traffic during business hours

Recommended Actions

  • Implement advanced email filtering and phishing detection solutions.
  • Conduct regular employee training on identifying spear-phishing attempts.
  • Enhance network monitoring for异常流量 and lateral movement indicators.
  • Use MFA for critical systems and accounts to mitigate credential dumping risks
  • Regularly update and patch systems to defend against known vulnerabilities.

Suggested Tags

APT
espionage
government targeting
nation-state

Confidence Assessment

Overall confidence in the data is high based on the observed TTPs and pattern of activity. Further clarity would be beneficial regarding the specific nation-state actor responsible and their exact toolset, which remains elusive and attributed to plausible deniability.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
Critical Infrastructure
Phishing
Backdoor / C2
Government Targeting
Hacktivism
espionage
government targeting
nation-state

Details

Type
Nation-State
Confidence
50%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.