Group5: Syria and the Iranian Connection - The Citizen Lab
ID: 4fece465-17e6-4724-baf6-c3e2c3c5050e
STIX ID: report--4fece465-17e6-4724-baf6-c3e2c3c5050e
Threat Score
75/100
Uploaded: 2026-08-15
Published Date: 2016-08-03
Last Modified Date: 2016-08-03
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
## Executive Summary
This Citizen Lab report documents “Group5,” a targeted malware operation against Syrian opposition figures that used PowerPoint-based droppers, a watering-hole site (assadcrimes.info), and a fake Android Flash update to deliver Remote Access Trojans (NanoCore, njRAT, DroidJack). The analysis includes file hashes, C2 infrastructure (88.198.222.163 with distinct ports for each RAT), exploit usage (OLE animation and CVE-2014-4114), crypter artifacts (PAC Crypt with PDB strings linking to an alias “mr.tekide”), and host/log evidence suggesting an Iranian nexus, while stopping short of definitive state attribution.
