← All actors Recent activity

Group5 G0043

GROUP5

Indicators
4
Source reports
1
Activity span
not dated
Newest indicator
unknown
Upstream change
2026-01-02

Overview 4 indicators

Group5 is a threat group with a suspected Iranian nexus, though this attribution is not definite. The group has targeted individuals connected to the Syrian opposition via spearphishing and watering holes, normally using Syrian and Iranian themes. Group5 has used two commonly available remote access tools (RATs), njRAT and NanoCore, as well as an Android RAT, DroidJack.

domain4G0043-domain.txt

Techniques 4 ATT&CK

Open in ATT&CK Navigator → or download the layer (4 techniques, layer 4.5)

Software 2

Principal sources 1 reports

Ranked by how many of this actor's indicators each report brought in.

What the sources have in common — not a claim that these are the same actor. See the whole graph.

Timeline 4 indicators

Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.

  1. 4 domain8 yrs ago

    citizenlab.ca/2016/08/group5-syria

    assadcrimes.info
    crypter.ir
    crypting.org
    server22.rayanegarco.com

Further reading 2