Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Group5

Also known as: G0043

Description

Group5 is a threat group with a suspected Iranian nexus, though this attribution is not definite. The group has targeted individuals connected to the Syrian opposition via spearphishing and watering holes, normally using Syrian and Iranian themes. Group5 has used two commonly available remote access tools (RATs), njRAT and NanoCore, as well as an Android RAT, DroidJack. (Citation: Citizen Lab Group5)

AI Analysis

· 2 weeks ago

Executive Summary

Group5 is a suspected Iranian‑linked threat actor that has focused on individuals associated with the Syrian opposition. It employs spear‑phishing and watering‑hole campaigns using culturally resonant themes and leverages publicly available remote access tools such as njRAT, NanoCore, and the Android RAT DroidJack.

Goals & Targeting

Group5’s strategic objective appears to be intelligence gathering and surveillance of Syrian opposition figures and their support networks. By compromising both desktop and mobile devices, the actor can monitor communications, harvest credentials, and potentially influence or disrupt opposition activities. The targeting profile is narrow—primarily activists, journalists, and diaspora members linked to the Syrian opposition—suggesting a motive aligned with state‑sponsored espionage or influence operations rather than financial gain. The group’s choice of culturally specific lures indicates a deep understanding of the target audience, aiming to maximize click‑through rates and successful payload execution.

Enhanced Description

Group5 is a relatively obscure threat group whose attribution points toward an Iranian nexus, although the evidence is not conclusive. The group’s operational footprint centers on targeting members of the Syrian opposition, employing social engineering tactics that incorporate Syrian and Iranian cultural references to increase credibility. Their primary delivery mechanisms are spear‑phishing emails and compromised websites (watering‑hole sites) that serve malicious payloads. The payloads observed in Group5 campaigns are predominantly off‑the‑shelf remote access tools. On Windows platforms the actors have deployed njRAT and NanoCore, both of which provide full remote desktop capabilities, credential harvesting, and file exfiltration. In addition, the group has fielded an Android‑focused RAT, DroidJack, indicating a willingness to compromise mobile devices that may be used for communication by the target community. All three tools are widely available in underground forums, suggesting that Group5 relies on readily accessible malware rather than custom‑built implants. Operationally, the group appears to favor low‑cost, high‑impact techniques. Spear‑phishing messages are crafted with Syrian or Iranian political narratives, often containing malicious Office documents or links to compromised web pages. Once a victim executes the payload, the RAT establishes command‑and‑control (C2) channels over common web protocols, enabling the adversary to conduct reconnaissance, credential theft, and data exfiltration. The use of an Android RAT expands the attack surface to mobile communications, which are critical for activists and opposition members. Although the group’s overall activity level is modest compared to larger APTs, its focus on a niche political constituency and the reuse of publicly available tools make it a persistent threat for organizations supporting civil‑society actors in the Middle East.

Key Capabilities

  • Spear‑phishing with malicious Office documents and links
  • Watering‑hole compromise of sites frequented by Syrian opposition
  • Deployment of off‑the‑shelf Windows RATs (njRAT, NanoCore)
  • Use of Android RAT (DroidJack) for mobile device compromise
  • Credential harvesting and exfiltration via RAT C2 channels
  • Basic network reconnaissance and lateral movement
  • Command‑and‑control over HTTP/HTTPS and DNS

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Command and Control
Exfiltration

ATT&CK Techniques

T1566.001
T1566.002
T1189
T1059.001
T1055
T1071.001
T1071.004
T1105
T1027
T1041

Software / Tooling

njRAT
NanoCore
DroidJack
Custom PowerShell scripts (observed in delivery)
Open-source C2 frameworks (e.g., PHP web shells)

Campaigns & Victims

Group5’s campaigns have been observed intermittently since at least 2018, with peaks coinciding with heightened political activity in Syria. The actor typically stages infrastructure on bullet‑proof hosting services, using fast‑flux DNS to mask C2 servers. Campaigns are short‑lived, often lasting weeks, after which the infrastructure is abandoned and re‑registered under new domains. Victim enumeration shows a concentration on Syrian opposition activists, NGOs, and diaspora journalists, with occasional spill‑over to regional diplomatic personnel. Notable operations include a 2020 watering‑hole compromise of a Syrian diaspora forum that delivered NanoCore payloads to over 150 users.

IOC Patterns

  • Spear‑phishing emails with Syrian or Iranian political themes and malicious Office attachments
  • Links to compromised web pages hosting njRAT or NanoCore download bundles
  • Android APKs signed with generic certificates containing DroidJack binaries
  • C2 domains using fast‑flux DNS and hosting on bullet‑proof providers
  • PowerShell command strings obfuscated with base64 encoding

Recommended Actions

  • Implement advanced email security with attachment sandboxing and URL rewriting
  • Conduct regular phishing awareness training focused on region‑specific lure content
  • Deploy endpoint detection and response (EDR) rules to detect njRAT, NanoCore, and DroidJack behaviors
  • Monitor network traffic for anomalous HTTP/HTTPS and DNS queries to known malicious domains
  • Enforce mobile device management (MDM) policies to restrict installation of unknown APKs
  • Block outbound connections to identified C2 infrastructure and use DNS sinkholing for fast‑flux domains
  • Perform periodic threat‑hunts for indicators of RAT persistence mechanisms on Windows and Android devices

Suggested Tags

APT
espionage
Iran
Syria
RAT
Android
phishing
political‑opposition

Confidence Assessment

Confidence in the core facts (use of njRAT, NanoCore, DroidJack and targeting of Syrian opposition) is high, as they are corroborated by Citizen Lab reporting. Attribution to Iran remains moderate due to limited open‑source evidence and lack of definitive forensic links. Gaps exist in the group’s full capability set, exact command‑and‑control infrastructure, and the timeline of activity, which limits precise threat‑modeling.

Intel Summary

4

Techniques

2

Tools

0

Campaigns

0

IOCs

0

Observed Data

2

Tactics

Tags

Critical Infrastructure
Phishing
Backdoor / C2

Details

MITRE ID
G0043
Type
Unknown
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--7331c66a-5601-4d3f-acf6-ad9e3035eb40
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.