Group5: Syria and the Iranian Connection
ID: 9437e71c-2e34-4b16-bff9-978d5aebeec1
STIX ID: report--9437e71c-2e34-4b16-bff9-978d5aebeec1
Threat Score
78/100
Uploaded: 2026-08-15
Published Date: 2016-09-14
Last Modified Date: 2016-09-14
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
**Executive Summary:** Citizen Lab documents an elaborately staged targeted cyber-espionage campaign dubbed "Group5" that used socially engineered PPSX droppers (including a CVE-2014-4114 vector), a watering-hole site (assadcrimes.info), and an Android fake-Flash APK to deploy njRAT, NanoCore and DroidJack backdoors to a Hetzner-hosted C2 (88.198.222.163); PDB strings, Persian-language tools, Iranian hosting and access logs form a circumstantial Iranian nexus though attribution is not definitive.
