logo

Group5: Syria and the Iranian Connection

ID: 9437e71c-2e34-4b16-bff9-978d5aebeec1

STIX ID: report--9437e71c-2e34-4b16-bff9-978d5aebeec1

Threat Score

78/100

Uploaded: 2026-08-15

Published Date: 2016-09-14

Last Modified Date: 2016-09-14

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
**Executive Summary:** Citizen Lab documents an elaborately staged targeted cyber-espionage campaign dubbed "Group5" that used socially engineered PPSX droppers (including a CVE-2014-4114 vector), a watering-hole site (assadcrimes.info), and an Android fake-Flash APK to deploy njRAT, NanoCore and DroidJack backdoors to a Hetzner-hosted C2 (88.198.222.163); PDB strings, Persian-language tools, Iranian hosting and access logs form a circumstantial Iranian nexus though attribution is not definitive.