Actors Insights|Latest update24/07/2026

Group5

Named by Citizen LabSuspected state sponsor: Islamic Republic of Iran

Group5 is a threat actor documented by Citizen Lab in August 2016, named to reflect its position as the fifth known malware group targeting the Syrian opposition. Active since at least late 2015, the group used Windows and Android malware delivered via malicious PowerPoint documents and a watering hole website to target well-connected members of the Syrian opposition. Citizen Lab found compelling circumstantial evidence of Iranian origin: the operators were comfortable with Iranian Persian dialect tools, used Iranian hosting infrastructure including the Hostnegar ISP, ran parts of the operation from Iranian IP space, and linked code artifacts to a known Iranian malware developer using the handle Mr. Tekide. Researchers also noted possible technical overlaps with the Infy Iranian APT cluster. Iran's active military engagement in Syria and its alignment with the Assad regime provided clear geopolitical motivation. The group's technical sophistication was assessed as relatively low, and public reporting on its activity ceased after 2016.

First Seen:Oct 2015
Last Seen:Aug 2016
Indexed Reports:1
Public IOCs:24
Cluster: UnclassifiedMitre: Group5Misp: Group5
also known as:
G0043 (Mitre)Group5 (Citizen Lab)

Targeted Regions

Syria
SY
Syria
Syria
Oct 2015 ~ Aug 2016
Oct 2015 ~ Aug 2016
Oct 2015 ~ Aug 2016
Jan 2015Jul 2026

Targeted Sectors

DissidentHuman RightsPro-Democracy

Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.