ATT&CKGroupsStealth Falcon

Stealth Falcon

G0038

Threat group.View on attack.mitre.org

About this group

Stealth Falcon is a threat group that has conducted targeted spyware attacks against Emirati journalists, activists, and dissidents since at least 2012. Circumstantial evidence suggests there could be a link between this group and the United Arab Emirates (UAE) government, but that has not been confirmed.

Techniques used16

Procedure examples16

TechniqueProcedure example
T1005
Data from Local System

Stealth Falcon malware gathers data from the local victim system.

T1012
Query Registry

Stealth Falcon malware attempts to determine the installed version of .NET by querying the Registry.

T1016
System Network Configuration Discovery

Stealth Falcon malware gathers the Address Resolution Protocol (ARP) table from the victim.

T1033
System Owner/User Discovery

Stealth Falcon malware gathers the registered user and primary owner name via WMI.

T1041
Exfiltration Over C2 Channel

After data is collected by Stealth Falcon malware, it is exfiltrated over the existing C2 channel.

T1047
Windows Management Instrumentation

Stealth Falcon malware gathers system information via Windows Management Instrumentation (WMI).

T1053.005
Scheduled Task

Stealth Falcon malware creates a scheduled task entitled “IE Web Cache” to execute a malicious file hourly.

T1057
Process Discovery

Stealth Falcon malware gathers a list of running processes.

T1059
Command and Scripting Interpreter

Stealth Falcon malware uses WMI to script data collection and command execution on the victim.

T1059.001
PowerShell

Stealth Falcon malware uses PowerShell commands to perform various functions, including gathering system information via WMI and executing commands from its C2 server.

T1071.001
Web Protocols

Stealth Falcon malware communicates with its C2 server via HTTPS.

T1082
System Information Discovery

Stealth Falcon malware gathers system information via WMI, including the system directory, build number, serial number, version, manufacturer, model, and total physical memory.

T1555
Credentials from Password Stores

Stealth Falcon malware gathers passwords from multiple sources, including Windows Credential Vault and Outlook.

T1555.003
Credentials from Web Browsers

Stealth Falcon malware gathers passwords from multiple sources, including Internet Explorer, Firefox, and Chrome.

T1555.004
Windows Credential Manager

Stealth Falcon malware gathers passwords from the Windows Credential Vault.

View all 16 procedure examples

Software0

None recorded.

Campaigns0

None recorded.

References1

  1. Citizen Lab Stealth Falcon May 2016 Open source
    Marczak, B. and Scott-Railton, J.. (2016, May 29). Keep Calm and (Don’t) Enable Macros: A New Threat Actor Targets UAE Dissidents. Retrieved June 8, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.