Stealth Falcon
G00381 reportsaliases · Stealth Falcon
1
Reports
12
Techniques
8
Tactics
5
Countries
34%
Hunt coverage
1
Aliases
Analyst assessment — key judgments
- Signature techniques: T1053.005 (Scheduled Task), T1560.001 (Archive via Utility), T1113 (Screen Capture).
- Primary targeting: US, RU, MX, DE.
- Currently dormant: 0 report(s) in last 30d vs 0 prior (+0%).
- Hunt coverage 34% of 50 observed techniques (33 gap(s)).
- Assessment confidence: medium (60).
Activity & trend
DormantLast 30d: 0 vs 0 prior (+0%)· first reported 2026-07-20 · last 2026-07-20
0
7d
0
30d
1
90d
1
All
0.1
Rpts/wk
Reporting timeline · 12 months
Vulnerabilities in this actor's reporting · 3
- CVE-2025-24054KEV1 rpt
- CVE-2025-33053KEV1 rpt
- CVE-2026-21513KEV1 rpt
Overview
Analyst triage
Intelligence summary
Stealth Falcon is a threat group that has conducted targeted spyware attacks against Emirati journalists, activists, and dissidents since at least 2012. Circumstantial evidence suggests there could be a link between this group and the United Arab Emirates (UAE) government, but that has not been confirmed. (Citation: Citizen Lab Stealth Falcon May 2016)
Top co-occurring indicators
Aliases & naming
Targeting · countries
Targeting · named victims
ATT&CK technique matrix
Coverage vs hunt library:
—
Hunt-coverage gaps — prioritized
Top techniques by observation
- T1053.005 · Scheduled Taskconf 601
- T1560.001 · Archive via Utilityconf 601
- T1113 · Screen Captureconf 601
- T1056.001 · Keyloggingconf 601
- T1027.013 · Encrypted/Encoded Fileconf 601
- T1590.005 · IP Addressesconf 601
- T1059.007 · JavaScriptconf 601
- T1539 · Steal Web Session Cookieconf 601
- T1036.007 · Double File Extensionconf 601
- T1548.002 · Bypass User Account Controlconf 601
- T1204.002 · Malicious Fileconf 601
- T1218.004 · InstallUtilconf 601
Threat catalogue · engineering roadmap
Flagged detection-engineering queue
Uncovered techniques you flagged for hunt / detection build-out, aggregated across every actor you visit. Stored locally in your browser.
Infrastructure
IOC type mix
Tooling / malware families
Relationships
Activity
30-day mention timeline
Recent reporting
| Title | Source | Severity | Collected |
|---|