Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Hacking Team

Description

The many 0-days that had been collected by Hacking Team and which became publicly available during the breach of their organization in 2015, have been used by several APT groups since. Since being founded in 2003, the Italian spyware vendor Hacking Team gained notoriety for selling surveillance tools to governments and their agencies across the world. The capabilities of its flagship product, the Remote Control System (RCS), include extracting files from a targeted device, intercepting emails and instant messaging, as well as remotely activating a device’s webcam and microphone. The company has been criticized for selling these capabilities to authoritarian governments – an allegation it has consistently denied. When the tables turned in July 2015, with Hacking Team itself suffering a damaging hack, the reported use of RCS by oppressive regimes was confirmed. With 400GB of internal data – including the once-secret list of customers, internal communications, and spyware source code – leaked online, Hacking Team was forced to request its customers to suspend all use of RCS, and was left facing an uncertain future. Following the hack, the security community has been keeping a close eye on the company’s efforts to get back on its feet. The first reports suggesting Hacking Team’s resumed operations came six months later – a new sample of Hacking Team’s Mac spyware was apparently in the wild. A year after the breach, an investment by a company named Tablem Limited brought changes to Hacking Team’s shareholder structure, with Tablem Limited taking 20% of Hacking Team’s shareholding. Tablem Limited is officially based in Cyprus; however, recent news suggests it has ties to Saudi Arabia.

AI Analysis

· 1 week ago

Executive Summary

Hacking Team is a well-known Italian vendor of surveillance and espionage tools that has faced significant scrutiny due to its alleged sales of technology to authoritarian regimes. Following a major breach in 2015, which exposed sensitive data including customer lists, communications, and source code, the company has potentially returned to operations but with new investors linked to Saudi Arabia. The group's tools have been used by various APT actors globally, making it a significant concern for organizations targeted by these campaigns.

Goals & Targeting

Hacking Team primarily targeted governments and their agencies across the world to enable state-sponsored surveillance activities. Their products were sold to law enforcement and intelligence agencies as tools for monitoring suspect communications. Post-2015 breach, while not directly tied, APT groups have exploited the leaked information from Hacking Team's database, using the 0-days and source code to develop their own espionage campaigns. The targeting profile suggests a focus on authoritarian regimes and law enforcement entities but also extends to broader intelligence gathering activities.

Enhanced Description

Hacking Team was founded in 2003 and specializes in developing Remote Control System (RCS) spyware that enables governments to extract sensitive information from devices. The company's products include interception of emails, instant messages, activation of cameras, and microphones remotely. Hacking Team has faced criticism for selling these tools to authoritarian regimes. On July 2015, the company suffered a severe security breach where approximately 400GB of internal data was leaked online. This included detailed customer lists, internal communications, and software source code. The breach led to significant public scrutiny and forced Hacking Team to request their customers to halt use of RCS. Six months later, new samples of Hacking Team's Mac spyware were identified in the wild, suggesting a potential resurgence. In 2017, Tablem Limited, an investment company based in Cyprus with ties to Saudi Arabia, acquired a 20% stake in Hacking Team, signaling a shift in ownership and potentially indicating renewed efforts. Post-breach, the company has remained under surveillance by the cybersecurity community, with concerns about its potential re-entry into global markets.

Key Capabilities

  • Development of advanced spyware like Remote Control System (RCS)
  • Exfiltration of files, emails, and instant messages
  • Remote activation of device cameras and microphones for surveillance
  • Custom exploit development and distribution
  • Possession of a vast collection of 0-day vulnerabilities

MITRE ATT&CK Tactics

Espionage
Discovery
Credential Access

ATT&CK Techniques

T1078 - Valid Accounts
T1565.002 - Windows Management Service (WMS)
T1005 - spear_phishing_attachment
T1040.004 - Powershell Over HTTP
T1055.003 - Process Hollowing

Software / Tooling

Remote Control System (RCS)
Custom Exploits and Malware Frameworks
Hacking Team's Spyware Tools

Campaigns & Victims

Hacking Team's post-breach activities suggest a potential resurgence in the surveillance tools market, with new products or updates to existing software identified as early as 2015. The company's rebranding and acquisition by Tablem Limited may indicate efforts to re-establish itself in the global market under new leadership. APT groups are known to have used Hacking Team's leaked tools, leading to an increased number of espionage campaigns targeting government and private sector entities.

IOC Patterns

  • Spear-phishing emails with malicious attachments containing RCS components
  • Use of compromised legitimate domains for command-and-control (C2) communication
  • Indicators of web-based exploitation frameworks used in surveillance campaigns
  • Presence of RCS-related file hashes and signatures in network traffic

Recommended Actions

  • Monitor for suspicious activity related to known Hacking Team tools and their attack patterns.
  • Implement strict access controls on sensitive systems using the principle of least privilege.
  • Conduct regular vulnerability assessments to mitigate potential 0-day exploitation.
  • Enhance endpoint detection capabilities to identify RCS-like surveillance behaviors.

Suggested Tags

APT
Exploits
Espionage
Surveillance Tools

Confidence Assessment

High confidence in Hacking Team's historical activities and its role as a vendor of surveillance tools. However, there is limited direct evidence of Hacking Team resuming operations post-2015 breach, making it challenging to assess its current level of activity or intentions precisely.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
Zero-Day Exploitation
Government Targeting
Exploits
Espionage
Surveillance Tools

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.