NEW: Group Profiler — instant APT intel lookup. Try it →

Stealth Falcon

G0038 Espionage MITRE ATT&CK →

Overview

Stealth Falcon is a threat group that has conducted targeted spyware attacks against Emirati journalists, activists, and dissidents since at least 2012. Circumstantial evidence suggests there could be a link between this group and the United Arab Emirates (UAE) government, but that has not been confirmed.

Naming & attribution

Stealth Falcon is tracked under 1 names across the industry. It uses 16 documented ATT&CK techniques — more than 45% of the 174 groups tracked here. Activity attributed since at least 2012.

Who calls this group what — MITRE lists each alias with the report that used it, but not which vendor coined it.
NameFirst reported by
Stealth FalconMarczak, B. and Scott-Railton, J.

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • Inception Russia — 7 shared techniques (23% overlap)
  • APT37 North Korea — 8 shared techniques (22% overlap)
  • Higaisa South Korea — 7 shared techniques (19% overlap)
  • Winter Vivern Russia — 7 shared techniques (19% overlap)
  • APT19 China — 6 shared techniques (19% overlap)
  • OilRig Iran — 14 shared techniques (18% overlap)

Targets

Activists · Civil society · Dissidents · Journalists

Regions

United Arab Emirates · United Kingdom

TTPs — 16 techniques across 6 tactics

Reporting (1)