Starry Addax
- Primary motivation
- ideology
- Sophistication
- intermediate
- Resource level
- team
- Actor type
- hacktivist
- Profile updated
- 2026-07-07 12:15:02
Targeted industries: education-and-nonprofits government-and-public-sector
Context
Starry Addax is a threat actor targeting human rights activists associated with the Sahrawi Arab Democratic Republic using a novel mobile malware called FlexStarling. They conduct phishing attacks to trick targets into installing malicious Android applications and serve credential-harvesting pages to Windows-based targets. Their infrastructure targets both Windows and Android users, with the campaign starting with spear-phishing emails containing requests to install specific mobile apps or related themes. The campaign is in its early stages, with potential for additional malware variants and infrastructure development.
Reports & references
- Cisco Talos — Starry Addax (report)