logo

Group5: Syria and the Iranian Connection - The Citizen Lab

ID: 4fece465-17e6-4724-baf6-c3e2c3c5050e

STIX ID: report--4fece465-17e6-4724-baf6-c3e2c3c5050e

Threat Score

75/100

Uploaded: 2026-08-15

Published Date: 2016-08-03

Last Modified Date: 2016-08-03

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
## Executive Summary This Citizen Lab report documents “Group5,” a targeted malware operation against Syrian opposition figures that used PowerPoint-based droppers, a watering-hole site (assadcrimes.info), and a fake Android Flash update to deliver Remote Access Trojans (NanoCore, njRAT, DroidJack). The analysis includes file hashes, C2 infrastructure (88.198.222.163 with distinct ports for each RAT), exploit usage (OLE animation and CVE-2014-4114), crypter artifacts (PAC Crypt with PDB strings linking to an alias “mr.tekide”), and host/log evidence suggesting an Iranian nexus, while stopping short of definitive state attribution.