Starry Addax

Primary motivation
ideology
Sophistication
intermediate
Resource level
team
Actor type
hacktivist
Profile updated
2026-07-07 12:15:02

Targeted industries: education-and-nonprofits government-and-public-sector

Context

Starry Addax is a threat actor targeting human rights activists associated with the Sahrawi Arab Democratic Republic using a novel mobile malware called FlexStarling. They conduct phishing attacks to trick targets into installing malicious Android applications and serve credential-harvesting pages to Windows-based targets. Their infrastructure targets both Windows and Android users, with the campaign starting with spear-phishing emails containing requests to install specific mobile apps or related themes. The campaign is in its early stages, with potential for additional malware variants and infrastructure development.

Reports & references

  • Cisco Talos — Starry Addax (report)

External references