Home/Threat Actor/Stealth Falcon
Threat Actor

Stealth Falcon

stealth_falcon · united_arab_emirates · active since 2012

Stealth Falcon (G0038, possibly identical to or sibling-adjacent with FruityArmor) is a suspected United Arab Emirates state- aligned cyber-espionage cluster active since 2012 and publicly disclosed by Citizen Lab in May 2016 with the foundational investigation of sustained multi-year spear-phishing targeting of UK-based journalist Rori Donaghy and other UAE-critical voices , one of the most clearly-documented publicly-tracked cases of state-sponsored surveillance of journalists and dissidents by their subject's home government, operating within the broader UAE state-cyber ecosystem documented in Reuters' January 2019 Project Raven investigative series and partially corroborated by the September 2021 US DOJ deferred prosecution agreement with former NSA employees Marc Baier, Ryan Adams, and Daniel Gericke for providing offensive cyber-operations services to UAE government on behalf of DarkMatter, defined operationally by the Win32/StealthFalcon Windows backdoor toolkit, the substantially- more-sophisticated Deadglyph implant disclosed by ESET in September 2023, the unresolved FruityArmor cluster-consolidation question (which if sustained would attribute sustained Windows zero-day capability with CVE-2016-4117, CVE-2017-8464, CVE-2018-8453, and CVE-2019-0859 to the cluster), and a sustained dissident-and-journalist-surveillance mission profile that has operated against UAE-critical voices in the UAE and in diaspora for more than a decade.

united_arab_emirates confidence: high 14 aliases MITRE ATT&CK G0038 ↗

Profile

Stealth Falcon (also tracked as FruityArmor in some vendor reporting, Project-Raven-adjacent, and MITRE ATT&CK G0038) is a suspected United Arab Emirates state-aligned cyber-espionage cluster active since at least 2012 and publicly disclosed by Citizen Lab in May 2016 ("Keep Calm and (Don't) Enable Macros: A New Threat Actor Targets UAE Dissidents"). The cluster's most operationally consequential foundational evidence is the Citizen Lab investigation's detailed documentation of sustained multi-year spear-phishing targeting of UK-based journalist Rori Donaghy in retaliation for his reporting critical of UAE government practices, alongside parallel targeting of numerous other UAE-critical voices including human-rights activists, lawyers, academics, and opposition political figures. The Citizen Lab investigation established Stealth Falcon as one of the most clearly-documented publicly-tracked state-sponsored-surveillance cases of journalists and dissidents by their subject's home government and contributed substantially to broader policy attention to UAE state-cyber operations.

The cluster operates within the broader UAE state-cyber ecosystem documented in Reuters' January 30, 2019 investigative series "Inside the UAE's secret hacking team of American mercenaries" describing Project Raven, a UAE-state-funded offensive cyber operation operated by DarkMatter (an Abu Dhabi-based UAE-state- affiliated contractor) and staffed in part by former US National Security Agency personnel. The September 14, 2021 US Department of Justice deferred prosecution agreement with three former NSA employees (Marc Baier, Ryan Adams, Daniel Gericke) for providing offensive cyber-operations services to UAE government on behalf of DarkMatter, requiring USD 1.685 million in penalties and prohibiting future US security-clearance work, represented formal US-government corroboration of the Project Raven UAE-state- cyber operations. While the DPA did not specifically name Stealth Falcon, the broader ecosystem attribution and Citizen Lab's specific Stealth Falcon evidence combine to make the UAE-state- aligned framing high-confidence by research-and-investigative- reporting standards.

A defining operational consideration is the unresolved cluster- identity question between Stealth Falcon and FruityArmor. Microsoft Security Response Center and ESET have published a series of disclosures across 2016-2018 documenting FruityArmor, a cluster operating with sustained Windows zero-day exploit capability against a small number of Middle Eastern targets, using CVE-2016-4117 (Adobe Flash), CVE-2017-8464 (Windows LNK Shortcut), CVE-2018-8453 (Windows Win32k privilege escalation), and CVE-2019-0859 (Windows ALEO privilege escalation). Whether FruityArmor is identical to Stealth Falcon, a closely-adjacent sibling cluster within the same UAE state-cyber ecosystem, or a separate cluster has been analytically open across vendor reporting.

This record treats FruityArmor as a possible alias / adjacent cluster but acknowledges the unresolved consolidation question. The sustained Windows 0day capability, uncommon among publicly-tracked state-aligned clusters at this tier, would represent substantial cluster sophistication if the FruityArmor attribution is sustained. Operationally Stealth Falcon's signature toolkit centers on the Win32/StealthFalcon Windows backdoor (analyzed in detail by Bitdefender in April 2019) and the substantially-more-sophisticated Deadglyph implant disclosed by ESET in September 2023.

Deadglyph represents a meaningful escalation in cluster tradecraft sophistication, with extensive anti-analysis tradecraft (deep obfuscation, custom code-execution flow, modular plugin architecture, native registration as a Component Object Model shell extension for persistence). The Deadglyph disclosure demonstrates continued operational tempo through 2023 and continued investment in capability development despite the September 2021 DOJ action on adjacent Project Raven operations. Initial-access tradecraft is predominantly spear-phishing with weaponized Office documents (macros, CVE exploitation alongside 0day capability for high-value targets), credential-phishing landing pages mimicking Microsoft, Google, and UAE-specific services, and fake-account social engineering.

The cluster operates with comparatively low-volume target selection, a small number of high-value dissident, journalist, and activist targets rather than broad scattershot campaigns, reflecting the targeted-surveillance mission profile. A handful of operational notes: First, the cluster is ecosystem-adjacent to but operationally distinct from Windshift (separately covered as windshift.yaml, also UAE-state-aligned suspected, also Project-Raven-adjacent, but with a distinct toolkit anchored on macOS-targeting Windtail/Windtape implants and a 2017-onward shorter operational history). The two clusters appear to operate within the same UAE state-cyber ecosystem but represent separate operational identities.

Second, the cluster is operationally distinct from Bahamut (already covered as bahamut.yaml, private mercenary with multiple suspected state clients including UAE). Bahamut's signature fake-news watering-hole infrastructure and Google- Play-Store Android implant distribution contrast with Stealth Falcon's spear-phishing-and-Windows-implant tradecraft. Third, UAE state-cyber operations encompass both custom-implant clusters (Stealth Falcon, Windshift) and commercial mobile- surveillance product use (NSO Pegasus, Intellexa Predator).

The two operational streams are distinct but share state sponsorship and target categories. Fourth, attribution to specifically the UAE state, though dominant in vendor and Citizen Lab reporting and corroborated by the September 2021 DOJ DPA on adjacent Project Raven operations , has not been confirmed by formal state attribution naming Stealth Falcon specifically. Treat the UAE-state-aligned framing as suspected at the cluster level even though the broader Project Raven ecosystem is formally documented.

Fifth, the FruityArmor consolidation question (above) should be treated as analytically open. If FruityArmor and Stealth Falcon are confirmed as the same cluster, the cluster's assessed sophistication tier increases substantially due to the sustained Windows 0day capability documented under the FruityArmor naming.

Aliases

14
stealth falconstealth_falconstealthfalconfruityarmorfruity armorfruity_armorfruity ferretfruity_ferretproject raven adjacencyproject_raven_adjacencydarkmatter overlapg0038atk 24atk24

Notable Campaigns

8
2023-2025Continued Operations (2023-2025)
2023ESET: Stealth Falcon Preying with a Deadglyph (September 22, 2023)
2021DOJ Deferred Prosecution Agreement (September 14, 2021), Ecosystem Context
2019Bitdefender: Win32/StealthFalcon Backdoor Analysis (April 2019)
2019Reuters: Project Raven Investigation (January 30, 2019), Ecosystem Context
2016-2018FruityArmor 0day Disclosures (Microsoft + ESET, 2016-2018)
2016Citizen Lab: Keep Calm and (Don't) Enable Macros, Stealth Falcon Targets UAE Dissidents (May 29, 2016)
2012-2016Sustained Rori Donaghy Targeting (2012-2016)

Attribution & Reporting

Attributed by
Citizen Lab (University of Toronto)ReutersESETMicrosoftMicrosoft Security Response CenterBitdefenderMandiantCisco TalosKasperskySentinelOneTrend MicroAmnesty International Security LabAccess NowFront Line DefendersCluster25Cyfirma
Key reporting
reportCitizen Lab: Keep Calm and (Don't) Enable Macros, A New Threat Actor Targets UAE Dissidents (May 29, 2016), seminal cluster disclosure
reportBitdefender: Win32/StealthFalcon Backdoor Analysis (April 2019)
reportReuters: Inside the UAE's Secret Hacking Team of American Mercenaries (January 30, 2019), ecosystem context
reportUS DOJ: Three Former US Intelligence Community and Military Personnel Agree to Pay More Than $1.68 Million to Resolve Charges of Providing Hacking-Related Services to UAE (September 14, 2021), ecosystem corroboration
reportMicrosoft Security Response Center: FruityArmor 0day Disclosures (2016-2018, multiple)
reportESET: Stealth Falcon Preying with a Deadglyph (September 22, 2023), seminal Deadglyph implant disclosure
reportESET: Backdoor.Win32.StealthFalcon Group (September 2019)
reportCitizen Lab: Sustained UAE Dissident-Surveillance Tracking (multiple years)
reportAmnesty International Security Lab: UAE Cyber-Surveillance Tracking (multiple years)
reportFront Line Defenders: UAE Activist Surveillance Documentation
reportCluster25: Stealth Falcon UAE Operational Profile
reportCyfirma: Stealth Falcon UAE Tracking (multiple years)
reportMalpedia Actor Profile: Stealth Falcon
reportMITRE ATT&CK Group G0038, Stealth Falcon

Operational

State sponsor

Suspected United Arab Emirates state-aligned cyber-espionage cluster. Attribution is grounded in Citizen Lab's seminal May 2016 disclosure "Keep Calm and (Don't) Enable Macros: A New Threat Actor Targets UAE Dissidents," which documented sustained spear-phishing operations against UAE-domestic-dissident journalist Rori Donaghy and other UAE political activists since 2012, with operational indicators (infrastructure registration patterns, language artifacts, target selection, operational hours) consistent with UAE state interest. The cluster operates within the broader UAE state-cyber ecosystem documented in Reuters' January 2019 "Project Raven" investigative series describing UAE-state-funded offensive cyber operations operated by DarkMatter (an Abu Dhabi- based UAE-state-affiliated contractor) and staffed in part by former US NSA personnel. The September 14, 2021 US Department of Justice deferred prosecution agreement with three former NSA employees (Marc Baier, Ryan Adams, Daniel Gericke) for providing offensive cyber-operations services to UAE government on behalf of DarkMatter represented formal US-government confirmation of the Project Raven UAE-state-cyber operations. While the DPA did not specifically name Stealth Falcon, the broader ecosystem attribution and Citizen Lab's specific Stealth Falcon evidence combine to make the UAE-state-aligned framing high-confidence by research-and-investigative-reporting standards. No formal US, UK, or EU government attribution to a specific UAE state entity has been published naming Stealth Falcon. The cluster is ecosystem- adjacent to but operationally distinct from Windshift (separately covered as windshift.yaml). Some vendor reporting (notably ESET and Microsoft) has treated FruityArmor, an exploit-development- heavy cluster known for sustained Windows 0day use, as either identical to Stealth Falcon or as a closely-adjacent sibling cluster within the same UAE state-cyber ecosystem.

the consolidation question remains analytically open.

Motivations
espionage, intelligence_gathering, dissident_surveillance, journalist_surveillance, human_rights_activist_surveillance, opposition_surveillance, geopolitical_collection
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)57/60 · 95%
Analytics (MITRE CAR)27/60 · 45%
Runtime / container (Falco)8/60 · 13%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)16/60 · 26%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

2 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
MACROS WEAPONIZED OFFICEMSHTASTEALTHFALCON BACKDOORSTEALTH FALCON BACKDOOR
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin