logo

Group5__2016__Group5_Syria_and_the_Iranian_Connection_-_The_Citizen_Lab.pdf

ID: 92e71a23-9fa0-4eb2-904e-af76424ad29a

STIX ID: report--92e71a23-9fa0-4eb2-904e-af76424ad29a

Threat Score

75/100

Uploaded: 2026-08-15

Published Date: 2016-08-03

Last Modified Date: 2016-08-03

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
## Executive summary Citizen Lab identified and analyzed "Group5," a targeted malware operation that used watering-hole websites and spear-phishing PPSX attachments to deliver Windows RATs (NanoCore, njRAT) and an Android RAT (DroidJack) against Syrian opposition figures. The report documents malware staging and delivery, C2 infrastructure (88.198.222.163), unpacking/decryption and PDB artefacts linking a PAC Crypter and the alias “mr.tekide,” and presents circumstantial evidence of an Iranian nexus while stopping short of definitive government attribution.