Stealth Falcon

Threat Actor updated 4 months ago (2024-05-04T17:17:48.700Z)
Download STIX
Preview STIX
Stealth Falcon, also known as Project Raven or FruityArmor, is a notable threat actor that has been active since at least 2012. This group is known for its cyber espionage activities primarily in the Middle East, targeting political activists, journalists, and dissidents. The group gained significant attention in May 2016 when a new Stealth Falcon document was released. Their tactics include using unusual backdoors in their attacks on government entities, with one of the most recent examples being the novel sophisticated Deadglyph malware, as reported by The Hacker News in September 2023. There are two main hypotheses regarding the origins and sponsorship of Stealth Falcon. Hypothesis 1 suggests that Stealth Falcon is state-sponsored, with circumstantial evidence pointing towards a link between the group and the UAE government. This hypothesis is further supported by the group's consistent targeting of figures within the UAE. On the other hand, Hypothesis 2 posits that Stealth Falcon is not state-sponsored. Despite these contrasting views, there seems to be an overlapping pattern of targets and tactics between Stealth Falcon and another group called Project Raven, leading some to suggest that they might be the same entity. The connection between Stealth Falcon and Project Raven was made more explicit by Claudio Guarnieri and Amnesty International. They concluded in 2019 that Stealth Falcon and Project Raven are likely the same group, given their similar targeting and attack strategies. This conclusion was based on the observation that both groups targeted similar individuals and used similar methods, raising suspicions about their common origin. Regardless of the exact nature of their affiliation, it is clear that Stealth Falcon represents a significant and ongoing cyber threat, particularly to those in the Middle East.
Description last updated: 2024-05-04T17:12:30.458Z
What's your take? (Question 1 of 5)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at.
IDVotesProfile Description
Project Raven
2
Project Raven, also known as Stealth Falcon or FruityArmor, is a threat actor linked to the United Arab Emirates (UAE), identified by cybersecurity researchers as being active since 2012. This group has been associated with state-sponsored cyber-espionage activities, primarily targeting political ac
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Backdoor
Espionage
UAE
Apt
Spyware
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Associated Malware
To see the evidence that has resulted in these malware associations, create a free account
IDTypeVotesProfile Description
DeadglyphUnspecified
3
Deadglyph is a sophisticated malware, named and detailed by ESET, used in cyberespionage attacks targeted at Middle Eastern governments. The malware is linked to the Stealth Falcon Advanced Persistent Threat (APT) group, also known as FruityArmor, which has been previously associated with the United
Source Document References
Information about the Stealth Falcon Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
CERT-EU
a year ago
Cyber Security Week in Review: September 29, 2023
CERT-EU
a year ago
DHS: US critical infrastructure facing malicious AI threat
CERT-EU
a year ago
UAE-Linked APT Targets Middle East Government With New 'Deadglyph' Backdoor
CERT-EU
a year ago
UAE-Linked APT Targets Middle East Government With New ‘Deadglyph’ Backdoor
BankInfoSecurity
a year ago
Deadglyph Backdoor Targeting Middle Eastern Government
CERT-EU
a year ago
New Deadglyph backdoor detailed
CERT-EU
a year ago
UAE-Linked 'Stealth Falcon' APT Mimics Microsoft in Homoglyph Attack
CERT-EU
a year ago
Stealth Falcon cyber spies use unusual backdoor in attacks on government entities in the Middle East
CERT-EU
a year ago
Deadglyph: A New Backdoor Linked to Stealth Falcon APT in the Middle East
CERT-EU
a year ago
Deadglyph: A New Backdoor Linked to Stealth Falcon APT in the Middle East
InfoSecurity-magazine
a year ago
Researchers Spot Novel “Deadglyph” Backdoor
Securityaffairs
a year ago
Deadglyph, a very sophisticated and unknown backdoor targets the Middle East
Securityaffairs
a year ago
Security Affairs newsletter Round 438 by Pierluigi Paganini
CERT-EU
a year ago
New stealthy and modular Deadglyph malware used in govt attacks
CERT-EU
a year ago
Deadglyph: New Advanced Backdoor with Distinctive Malware Tactics – GIXtools
CERT-EU
a year ago
ESET's cutting-edge threat research at LABScon – Week in security with Tony Anscombe
CERT-EU
a year ago
Stealth Falcon preying over Middle Eastern skies with Deadglyph
MITRE
2 years ago
Keep Calm and (Don’t) Enable Macros: A New Threat Actor Targets UAE Dissidents - The Citizen Lab