G0043

Group5Group5

Also known as: G0043 · Group5

Known aliases
2

Profile

A threat actor using Iranian-language tools, Iranian hosting companies, operating from the Iranian IP space at times was observed targeting the Syrian opposition in an elaborately staged malware operation, Citizen Lab researchers reveal. The operation was first noticed in late 2015, when a member of the Syrian opposition flagged a suspicious email containing a PowerPoint slideshow, which led researchers to a watering hole website with malicious programs, malicious PowerPoint files, and Android malware. The threat actor was targeting Windows and Android devices of well-connected individuals in the Syrian opposition, researchers discovered. They called the actor Group5, because it targets Syrian opposition after regime-linked malware groups, the Syrian Electronic Army, ISIS (also known as the Islamic State or ISIL), and a group linked to Lebanon did the same in the past

Aliases· 2

Group5
G0043

MITRE ATT&CK Group crosswalk

G0043

References

  1. https://www.securityweek.com/iranian-actor-group5-targeting-syrian-opposition
  2. https://attack.mitre.org/groups/G0043/

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
TA455
Group
POLONIUM
Actor
APT35
Actor
Sima
Group
OilRig
Actor
Infy
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.