Iranian-Linked Group5 Targets Syrian Opposition with Multi-Platform Malware
- Actor Motivations: Espionage,Exfiltration
- Attack Vectors: Vulnerability Exploitation,RAT,Spyware,Spear Phishing
- Attack Complexity: Medium
- Threat Risk: High Impact/Low Probability
Threat Overview
Citizen Lab researchers identified Group5, a threat actor with probable Iranian ties, conducting a multi-platform surveillance campaign against members of the Syrian political opposition. The operation began in October 2015 when Noura Al-Ameer, a senior Syrian National Council official, received a spearphishing email carrying a malicious PowerPoint slideshow (PPSX) designed to look like Iranian human-rights documentation. The attackers also set up a watering hole site — assadcrimes[.]info — that distributed both Windows and Android malware. On the Windows side, Group5 deployed njRAT and NanoCore RAT, both obfuscated with a Persian-language crypter called PAC Crypt. One of the PowerPoint files exploited CVE-2014-4114 to silently install the RAT. On Android, a fake Adobe Flash Player update delivered DroidJack, granting the operator remote access to calls, messages, contacts, camera, and microphone. Website logs left publicly accessible revealed the operators accessing the site from Iranian IP space, including addresses belonging to Rightel, an Iranian mobile carrier, pointing to an Iranian operational nexus.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Case | Noura Al-Ameer Noura Al-Ameer, former SNC Vice President and a target of the operation. Noura Al-Ameer has been targeted by Group5 as the main target. | Verified |
| Case | Syrian National Council (SNC) Noura Al-Ameer was former Vice President of the SNC; the campaign used her name in the fake domain registration and she was the first named target of the spearphishing operation. The Syrian National Council (SNC) was a Syrian opposition political group established in 2011 during the Syrian civil war. It served as the main external opposition body representing various Syrian opposition factions against the Assad regime. Syrian National Council (SNC) has been targeted by Group5 as the main target. | High |
| Sector | Dissident None | Verified |
| Sector | Human Rights | Verified |
| Sector | Pro-Democracy None | High |
| Region | Syria | Verified |
Exploited Vulnerabilities
Extracted IOCs
- assadcrimes[.]info
- server22.rayanegarco[.]com
- office@assadcrimes[.]info
- 2fc276e1c06c3c78c6d7b66a141213be
- 30bb678db3ad0140fc33acd9803385c3
- 366908f6c5c4f4329478d60586eca5bc
- 494bab7fd0b42b0b14051ed9abbd651f
- 5c4ec3d93a664e4bfa1ce6286ccf0249
- 6161083021b695814434450c1882f9f3
- 76f8142b4e52c671871b3df87f10c30c
- 7d898530d2e77f15f5badce8d7df215e
- 8ebeb3f91cda8e985a9c61beb8cdde9d
- a4f1f4921bb11ff9d22fad89b19b155d
- b4121c3a1892332402000ef0d587c0ee
- dd5bedd915967c5efe00733cf7478cb4
- f1f84ea3229dca0ccacb7381a2f49f99
- 1a287331e2bfb4df9cfe2dab1b77c9b5522e923e52998a2b1934ed8a8e52f3a8
- a9db5a548ea17d6606bfbdb20306a3a08b38dbfe720f9f709f4d3369288be104
- c19bc1ff5f8472fb7ba64f33c2168b42ea881a6ae6e134a1cc142e984fb6647f
- d72676bbf8de82486c3cebfdad2961cc68a6b564a43f9f987c95320fcd6a330a
- d81ec563387e2ea47bc8ed50fd36e1de955cb2331d6eaae9f966b5d7ab094806
- 212[.]7.195.171
- 88[.]198.222.163
Tip: 23 related IOCs (2 IP, 2 domain, 0 URL, 1 email, 18 file hash) to this threat have been found.
FAQs
Frequently Asked Questions about Group5's Campaign Against Syrian Opposition
A threat actor known as Group5 ran a targeted surveillance campaign against members of the Syrian political opposition starting in October 2015. The attackers sent spearphishing emails carrying malicious PowerPoint files and set up a fake website — assadcrimes[.]info — that automatically downloaded malware onto visitors' devices. Victims' Windows computers were infected with remote access trojans (RATs), and their Android phones were targeted with spyware disguised as an Adobe Flash Player update. Citizen Lab researchers uncovered and documented the operation, publishing their findings in August 2016.
A threat actor known as Group5 ran a targeted surveillance campaign against members of the Syrian political opposition starting in October 2015. The attackers sent spearphishing emails carrying malicious PowerPoint files and set up a fake website — assadcrimes[.]info — that automatically downloaded malware onto visitors' devices. Victims' Windows computers were infected with remote access trojans, and their Android phones were targeted with spyware disguised as an Adobe Flash Player update. Citizen Lab researchers uncovered and documented the operation, publishing their findings in August 2016.
The operation was carried out by a group Citizen Lab named "Group5" — the fifth known threat actor targeting Syrian opposition networks. The group shows strong circumstantial links to Iran: operators accessed the watering hole site from Iranian IP addresses (including Rightel, an Iranian mobile carrier), used a Persian-language mailer and crypter (PAC Crypt), and PDB strings in the malware pointed to a developer known as "mr.tekide," an Iranian malware author. No definitive state sponsor was identified, though Iranian state interests were considered likely given the tooling and infrastructure.
The primary goal was surveillance and intelligence collection. Once installed on a victim's device, the malware could steal files, log keystrokes, capture screenshots, record audio and video through the microphone and webcam, and — on Android devices — access call logs, contacts, SMS messages, and location data. This type of access gives an attacker a detailed, real-time picture of a target's communications, plans, and contacts, which is directly useful for monitoring and disrupting opposition activities.
The campaign was narrow and deliberate. Citizen Lab identified only a handful of confirmed targets, with Noura Al-Ameer — a senior Syrian National Council official — being the first named victim. The low antivirus detection rate (only 2 of 16 file hashes flagged on VirusTotal) is consistent with a highly targeted operation designed to fly under the radar. The attackers appear to have been at an early stage of their campaign when discovered, meaning the full intended scope of targeting may have been broader but never fully deployed.
The campaign focused on members of the Syrian political opposition, particularly well-connected figures involved in diplomacy, advocacy, and armed resistance. Human rights defenders, political negotiators, and diaspora activists are the primary at-risk group. The bait content — politically themed slideshows about Iranian crimes and the Syrian conflict — was carefully tailored to appear credible to this audience, showing the attackers had good knowledge of the community they were targeting.
The attack unfolded in two main channels. First, targets received spearphishing emails containing politically themed PowerPoint slideshows; opening the file silently installed Windows malware either through an embedded OLE object triggered by the slideshow animation, or by exploiting CVE-2014-4114, a vulnerability in how Windows handles OLE packages. Second, the attackers maintained a fake website (assadcrimes[.]info) that automatically downloaded malware when visited. Android users who landed on the site were shown a fake Flash Player update prompt; installing it gave the attacker full remote access to their phone. All malware was obfuscated with PAC Crypt to reduce antivirus detection.
Syrian opposition figures hold sensitive strategic and operational intelligence that is highly valuable to state adversaries — information about political negotiations, internal group structures, donor networks, and the locations and plans of armed groups. For an actor with Iranian interests, monitoring the Syrian opposition provides direct insight into the activities of groups that oppose Iranian allies in the conflict, making these targets high-value from an intelligence perspective. The highly networked, socially active nature of the opposition community also means that compromising one device can yield contact lists and communications that enable further targeting.
Be extremely cautious with unsolicited PowerPoint or Office files, especially from unfamiliar senders — do not run embedded objects or enable macros. Ensure all Windows and Office software is fully patched, particularly for CVE-2014-4114. On Android, disable installation from unknown sources and only install apps from the official Google Play Store. Use end-to-end encrypted communications tools and enable two-factor authentication on all accounts. Human rights defenders and opposition activists should assume they are active targets and seek out digital security training from organizations such as Access Now or Frontline Defenders. Block the known IOCs: 88.198.222[.]163, 212.7.195[.]171, assadcrimes[.]info, and server22.rayanegarco[.]com.