Group5
Named by Citizen LabSuspected state sponsor: Islamic Republic of IranGroup5 is a threat actor documented by Citizen Lab in August 2016, named to reflect its position as the fifth known malware group targeting the Syrian opposition. Active since at least late 2015, the group used Windows and Android malware delivered via malicious PowerPoint documents and a watering hole website to target well-connected members of the Syrian opposition. Citizen Lab found compelling circumstantial evidence of Iranian origin: the operators were comfortable with Iranian Persian dialect tools, used Iranian hosting infrastructure including the Hostnegar ISP, ran parts of the operation from Iranian IP space, and linked code artifacts to a known Iranian malware developer using the handle Mr. Tekide. Researchers also noted possible technical overlaps with the Infy Iranian APT cluster. Iran's active military engagement in Syria and its alignment with the Assad regime provided clear geopolitical motivation. The group's technical sophistication was assessed as relatively low, and public reporting on its activity ceased after 2016.
Targeted Regions
SyriaSyria
Oct 2015 ~ Aug 2016
Oct 2015 ~ Aug 2016
Oct 2015 ~ Aug 2016
Targeted Sectors
Recent Indexed Reports
Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.