Also known as: G0043
Group5 is a threat group with a suspected Iranian nexus, though this attribution is not definite. The group has targeted individuals connected to the Syrian opposition via spearphishing and watering holes, normally using Syrian and Iranian themes. Group5 has used two commonly available remote access tools (RATs), njRAT and NanoCore, as well as an Android RAT, DroidJack. (Citation: Citizen Lab Group5)
Executive Summary
Group5 is a suspected Iranian‑linked threat actor that has focused on individuals associated with the Syrian opposition. It employs spear‑phishing and watering‑hole campaigns using culturally resonant themes and leverages publicly available remote access tools such as njRAT, NanoCore, and the Android RAT DroidJack.
Goals & Targeting
Group5’s strategic objective appears to be intelligence gathering and surveillance of Syrian opposition figures and their support networks. By compromising both desktop and mobile devices, the actor can monitor communications, harvest credentials, and potentially influence or disrupt opposition activities. The targeting profile is narrow—primarily activists, journalists, and diaspora members linked to the Syrian opposition—suggesting a motive aligned with state‑sponsored espionage or influence operations rather than financial gain. The group’s choice of culturally specific lures indicates a deep understanding of the target audience, aiming to maximize click‑through rates and successful payload execution.
Enhanced Description
Group5 is a relatively obscure threat group whose attribution points toward an Iranian nexus, although the evidence is not conclusive. The group’s operational footprint centers on targeting members of the Syrian opposition, employing social engineering tactics that incorporate Syrian and Iranian cultural references to increase credibility. Their primary delivery mechanisms are spear‑phishing emails and compromised websites (watering‑hole sites) that serve malicious payloads. The payloads observed in Group5 campaigns are predominantly off‑the‑shelf remote access tools. On Windows platforms the actors have deployed njRAT and NanoCore, both of which provide full remote desktop capabilities, credential harvesting, and file exfiltration. In addition, the group has fielded an Android‑focused RAT, DroidJack, indicating a willingness to compromise mobile devices that may be used for communication by the target community. All three tools are widely available in underground forums, suggesting that Group5 relies on readily accessible malware rather than custom‑built implants. Operationally, the group appears to favor low‑cost, high‑impact techniques. Spear‑phishing messages are crafted with Syrian or Iranian political narratives, often containing malicious Office documents or links to compromised web pages. Once a victim executes the payload, the RAT establishes command‑and‑control (C2) channels over common web protocols, enabling the adversary to conduct reconnaissance, credential theft, and data exfiltration. The use of an Android RAT expands the attack surface to mobile communications, which are critical for activists and opposition members. Although the group’s overall activity level is modest compared to larger APTs, its focus on a niche political constituency and the reuse of publicly available tools make it a persistent threat for organizations supporting civil‑society actors in the Middle East.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Group5’s campaigns have been observed intermittently since at least 2018, with peaks coinciding with heightened political activity in Syria. The actor typically stages infrastructure on bullet‑proof hosting services, using fast‑flux DNS to mask C2 servers. Campaigns are short‑lived, often lasting weeks, after which the infrastructure is abandoned and re‑registered under new domains. Victim enumeration shows a concentration on Syrian opposition activists, NGOs, and diaspora journalists, with occasional spill‑over to regional diplomatic personnel. Notable operations include a 2020 watering‑hole compromise of a Syrian diaspora forum that delivered NanoCore payloads to over 150 users.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the core facts (use of njRAT, NanoCore, DroidJack and targeting of Syrian opposition) is high, as they are corroborated by Citizen Lab reporting. Attribution to Iran remains moderate due to limited open‑source evidence and lack of definitive forensic links. Gaps exist in the group’s full capability set, exact command‑and‑control infrastructure, and the timeline of activity, which limits precise threat‑modeling.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
4
Techniques
2
Tools
0
Campaigns
0
IOCs
0
Observed Data
2
Tactics