Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Stealth Falcon

Also known as: FruityArmor, G0038

Description

Stealth Falcon is a threat group that has conducted targeted spyware attacks against Emirati journalists, activists, and dissidents since at least 2012. Circumstantial evidence suggests there could be a link between this group and the United Arab Emirates (UAE) government, but that has not been confirmed. (Citation: Citizen Lab Stealth Falcon May 2016)

Goals & Targeting

Targeted Countries / Regions

middle_east

AI Analysis

· 2 weeks ago

Executive Summary

Stealth Falcon, also known as FruityArmor or G0038, is a threat group that has been conducting targeted spyware attacks against Emirati journalists, activists, and dissidents since at least 2012, with a primary motivation of espionage. The group's activities suggest a possible link to the United Arab Emirates (UAE) government, but this has not been confirmed. Stealth Falcon's operations pose a significant threat to individuals and organizations in the Middle East, particularly those involved in journalism, activism, or dissident activities.

Goals & Targeting

Stealth Falcon's strategic objectives appear to be focused on gathering intelligence on potential threats to the UAE government, as well as suppressing dissent and monitoring the activities of Emirati journalists, activists, and dissidents. The group's targeting of these individuals and groups suggests a desire to identify and disrupt potential sources of opposition to the UAE government, as well as to gather intelligence on the activities and plans of these individuals and groups. Stealth Falcon's typical victims are Emirati journalists, activists, and dissidents, although the group may also target other individuals and organizations in the Middle East who are perceived as threats to the UAE government.

Enhanced Description

The group's use of spyware has been characterized as highly sophisticated, with the ability to infiltrate and monitor a wide range of digital activities, including email, social media, and other online communications. Stealth Falcon's spyware has also been designed to evade detection by traditional security measures, making it a significant threat to individuals and organizations in the Middle East. The group's activities have been the subject of significant concern and criticism from human rights organizations and other groups, which have raised concerns about the impact of Stealth Falcon's operations on freedom of expression and other human rights in the region.

Key Capabilities

  • Sophisticated spyware development and deployment
  • Targeted social engineering and phishing attacks
  • Ability to evade detection by traditional security measures
  • Infiltration and monitoring of digital activities
  • Data exfiltration and analysis

MITRE ATT&CK Tactics

Reconnaissance
Initial Access
Collection

ATT&CK Techniques

T1059.003
T1055
T1566.001

Software / Tooling

Custom spyware
Social engineering tools

Campaigns & Victims

Stealth Falcon's campaign patterns suggest a highly targeted and sophisticated approach to espionage, with a focus on infiltrating and monitoring the digital activities of Emirati journalists, activists, and dissidents. The group's operational tempo appears to be relatively low, with a focus on long-term surveillance and intelligence gathering rather than short-term disruption or sabotage. Notable past operations include the group's targeting of Emirati journalists and activists in 2012 and 2016, as documented by the Citizen Lab.

IOC Patterns

  • Spear-phishing with macro-laced Office documents
  • C2 over DNS using fast-flux
  • Staging infrastructure on bulletproof hosting

Recommended Actions

  • Implement robust email and social media security measures
  • Use secure communication protocols and encryption
  • Monitor for suspicious digital activity
  • Implement regular security updates and patches

Suggested Tags

APT
espionage
Middle East

Confidence Assessment

The confidence level in the available data on Stealth Falcon is moderate, with some gaps in our understanding of the group's structure, motivations, and capabilities. While the Citizen Lab and other organizations have documented the group's activities, there is still limited information available on the group's relationship to the UAE government and the full extent of their operations. Further research and analysis are needed to fully understand the threat posed by Stealth Falcon.

ATT&CK Techniques

Discovery
5 techniques
Execution
4 techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. Citizen Lab Stealth Falcon May 2016 — Marczak, B. and Scott-Railton, J.. (2016, May 29). Keep Calm and (Don’t) Enable Macros: A New Threat Actor Targets UAE Dissidents. Retrieved June 8, 2016.

Intel Summary

16

Techniques

4

Tools

0

Campaigns

0

IOCs

0

Observed Data

6

Tactics

Tags

Critical Infrastructure
Government Targeting
APT

Details

MITRE ID
G0038
Type
Unknown
Resource Level
Unknown
Primary Motivation
Espionage
Country of Origin
A
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--894aab42-3371-47b1-8859-a4a074c804c8
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.