Group5__2016__Group5_Syria_and_the_Iranian_Connection_-_The_Citizen_Lab.pdf
ID: 92e71a23-9fa0-4eb2-904e-af76424ad29a
STIX ID: report--92e71a23-9fa0-4eb2-904e-af76424ad29a
Threat Score
75/100
Uploaded: 2026-08-15
Published Date: 2016-08-03
Last Modified Date: 2016-08-03
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
## Executive summary
Citizen Lab identified and analyzed "Group5," a targeted malware operation that used watering-hole websites and spear-phishing PPSX attachments to deliver Windows RATs (NanoCore, njRAT) and an Android RAT (DroidJack) against Syrian opposition figures. The report documents malware staging and delivery, C2 infrastructure (88.198.222.163), unpacking/decryption and PDB artefacts linking a PAC Crypter and the alias “mr.tekide,” and presents circumstantial evidence of an Iranian nexus while stopping short of definitive government attribution.
