Dancing Salome

Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 11:51:56

Targeted industries: government-and-public-sector education-and-nonprofits

Targeted regions: country_code:ua

Context

Dancing Salome is the Kaspersky codename for an APT actor with a primary focus on ministries of foreign affairs, think tanks, and Ukraine. What makes Dancing Salome interesting and relevant is the attacker’s penchant for leveraging HackingTeam RCS implants compiled after the public breach.

Reports & references

  • media.kasperskycontenthub.com — Guerrero Saade Raiu Vb2017 (report)

External references