Stealth Falcon

Threat Actor updated a month ago (2024-11-29T13:58:48.203Z)
Download STIX
Preview STIX
Stealth Falcon, also known as Project Raven or FruityArmor, is a notable threat actor that has been active since at least 2012. This group is known for its cyber espionage activities primarily in the Middle East, targeting political activists, journalists, and dissidents. The group gained significant attention in May 2016 when a new Stealth Falcon document was released. Their tactics include using unusual backdoors in their attacks on government entities, with one of the most recent examples being the novel sophisticated Deadglyph malware, as reported by The Hacker News in September 2023. There are two main hypotheses regarding the origins and sponsorship of Stealth Falcon. Hypothesis 1 suggests that Stealth Falcon is state-sponsored, with circumstantial evidence pointing towards a link between the group and the UAE government. This hypothesis is further supported by the group's consistent targeting of figures within the UAE. On the other hand, Hypothesis 2 posits that Stealth Falcon is not state-sponsored. Despite these contrasting views, there seems to be an overlapping pattern of targets and tactics between Stealth Falcon and another group called Project Raven, leading some to suggest that they might be the same entity. The connection between Stealth Falcon and Project Raven was made more explicit by Claudio Guarnieri and Amnesty International. They concluded in 2019 that Stealth Falcon and Project Raven are likely the same group, given their similar targeting and attack strategies. This conclusion was based on the observation that both groups targeted similar individuals and used similar methods, raising suspicions about their common origin. Regardless of the exact nature of their affiliation, it is clear that Stealth Falcon represents a significant and ongoing cyber threat, particularly to those in the Middle East.
Description last updated: 2024-05-04T17:12:30.458Z
What's your take? (Question 1 of 5)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at. Create a free account to see the source evidence for each alias, and help fix any errors.
Alias DescriptionVotes
Project Raven is a possible alias for Stealth Falcon. Project Raven, also known as Stealth Falcon or FruityArmor, is a threat actor linked to the United Arab Emirates (UAE), identified by cybersecurity researchers as being active since 2012. This group has been associated with state-sponsored cyber-espionage activities, primarily targeting political ac
2
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Backdoor
Espionage
UAE
Apt
Spyware
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Associated Malware
To see the evidence that has resulted in these malware associations, create a free account
Alias DescriptionAssociation TypeVotes
The Deadglyph Malware is associated with Stealth Falcon. Deadglyph is a sophisticated malware, or malicious software, discovered in September 2023 by ESET researchers. It was identified as a new backdoor used by the FruityArmor threat actor, also known as Stealth Falcon, primarily targeting Middle Eastern governments. The malware consists of a native x64 Unspecified
3
Source Document References
Information about the Stealth Falcon Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
BankInfoSecurity
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
InfoSecurity-magazine
a year ago
Securityaffairs
a year ago
Securityaffairs
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
MITRE
2 years ago