Dancing Salome
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Profile updated
- 2026-07-07 11:51:56
Targeted industries: government-and-public-sector education-and-nonprofits
Targeted regions: country_code:ua
Context
Dancing Salome is the Kaspersky codename for an APT actor with a primary focus on ministries of foreign affairs, think tanks, and Ukraine. What makes Dancing Salome interesting and relevant is the attacker’s penchant for leveraging HackingTeam RCS implants compiled after the public breach.
Reports & references
- media.kasperskycontenthub.com — Guerrero Saade Raiu Vb2017 (report)