Group5

MITRE ATT&CK: G0043 View on attack.mitre.org

Aliases: Group5

Primary motivation
espionage
Sophistication
intermediate
Resource level
team
Actor type
nation-state
Profile updated
2026-07-07 11:57:22

Targeted industries: government-and-public-sector

Targeted regions: country_code:sy country_code:ir

Context

Group5 is a threat group with a suspected Iranian nexus, though this attribution is not definite. The group has targeted individuals connected to the Syrian opposition via spearphishing and watering holes, normally using Syrian and Iranian themes. Group5 has used two commonly available remote access tools (RATs), njRAT and NanoCore, as well as an Android RAT, DroidJack.

Detection coverage

  • 10 YARA rules
  • 25 Sigma rules

Malware & tools used

  • Keylogging (attack-pattern)
  • Screen Capture (attack-pattern)
  • File Deletion (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • NanoCore (malware)
  • njRAT (malware)

Reports & references

  • securityweek.com — Iranian Actor Group5 Targeting Syrian Opposition (report)
  • MITRE ATT&CK — G0043 (report)
  • citizenlab.ca — Group5 Syria (report)

External references