Group5
MITRE ATT&CK: G0043 View on attack.mitre.org
Aliases: Group5
- Primary motivation
- espionage
- Sophistication
- intermediate
- Resource level
- team
- Actor type
- nation-state
- Profile updated
- 2026-07-07 11:57:22
Targeted industries: government-and-public-sector
Targeted regions: country_code:sy country_code:ir
Context
Group5 is a threat group with a suspected Iranian nexus, though this attribution is not definite. The group has targeted individuals connected to the Syrian opposition via spearphishing and watering holes, normally using Syrian and Iranian themes. Group5 has used two commonly available remote access tools (RATs), njRAT and NanoCore, as well as an Android RAT, DroidJack.
Detection coverage
- 10 YARA rules
- 25 Sigma rules
Malware & tools used
Reports & references
- securityweek.com — Iranian Actor Group5 Targeting Syrian Opposition (report)
- MITRE ATT&CK — G0043 (report)
- citizenlab.ca — Group5 Syria (report)