Home/Threat Actor/Windshift
Threat Actor

Windshift

windshift · united_arab_emirates · active since 2017

Windshift (G0112) is a suspected United Arab Emirates state-aligned cyber-espionage cluster active since 2017 and publicly disclosed by Palo Alto Networks Unit 42 in August 2018, ecosystem-adjacent to the broader UAE state-cyber operation documented as Project Raven in Reuters' January 2019 investigative series and partially corroborated by the September 2021 US DOJ deferred prosecution agreement with three former NSA employees (Marc Baier, Ryan Adams, Daniel Gericke) who admitted providing offensive cyber- operations services to UAE government on behalf of DarkMatter, responsible for sustained surveillance operations against UAE domestic dissidents, UAE dissidents in diaspora, Qatari and Yemeni adversary entities, regional journalists and human-rights activists, and broader Middle Eastern government targets, defined operationally by the signature Windtail and Windtape macOS backdoor toolkit (uncommon macOS focus among publicly-tracked state-aligned clusters at this tier, aligned with the Apple- device prevalence among Gulf-state targets) and by spear-phishing- and-credential-theft tradecraft against the dissident-and- journalist victim category.

united_arab_emirates confidence: medium 9 aliases MITRE ATT&CK G0112 ↗

Profile

Windshift (also known by partial-overlap aliases referencing the adjacent Project Raven / DarkMatter UAE state-cyber ecosystem) is a suspected United Arab Emirates state-aligned cyber-espionage cluster active since at least 2017 and publicly disclosed by Palo Alto Networks Unit 42 in August 2018 under the enduring "Windshift" name. The cluster is widely assessed by vendor research to operate in alignment with UAE state intelligence interests, most plausibly as part of the broader UAE state-cyber ecosystem documented in Reuters' January 30, 2019 investigative series "Inside the UAE's secret hacking team of American mercenaries", which described Project Raven, a UAE-state-funded offensive cyber operation operated by DarkMatter (an Abu Dhabi- based UAE-state-affiliated contractor) and staffed in part by former US National Security Agency personnel. The September 14, 2021 US Department of Justice deferred prosecution agreement with three former NSA employees (Marc Baier, Ryan Adams, Daniel Gericke), who admitted providing offensive cyber-operations services to UAE government on behalf of DarkMatter and paid more than USD 1.685 million in penalties, represented formal US-government confirmation of the Project Raven UAE-state-cyber operations described in the 2019 Reuters investigation. While the DPA did not specifically name Windshift, the broader ecosystem attribution strengthens the basis for assessing Windshift as UAE state-aligned. Whether Windshift is best understood as Project Raven itself, as a sibling cluster in the same ecosystem, or as a separate operation drawing on adjacent personnel and tooling remains analytically open in public reporting. Targeting focus is overwhelmingly directed at UAE domestic dissidents, UAE dissidents in diaspora, Qatari and Yemeni adversary entities (consistent with the 2017-2021 UAE-Qatar diplomatic crisis and the ongoing UAE involvement in the Yemen civil war), regional journalists and human-rights activists, lawyers and academics critical of UAE policy, broader Middle Eastern government and military targets, and selected European and North American diaspora targets. The dissident-and- journalist-surveillance focus aligns with extensively-documented UAE government practices of monitoring critical voices and with the broader Project Raven mission profile. A defining cluster tradecraft signature is sustained use of macOS-targeting implants, uncommon among publicly-tracked state-aligned clusters at this tier. The Windtail macOS backdoor (the cluster's signature implant, disclosed by Palo Alto Networks Unit 42 in 2018 and analyzed in subsequent ESET and Objective-See research) provides command execution, file collection, and exfiltration capability on macOS hosts. The Windtape sibling implant extends macOS coverage. The cluster's macOS focus aligns with the regional victimology, many Gulf-state government, academic, and journalism targets use Apple devices, and differentiates Windshift from peer Gulf-aligned clusters that operate predominantly Windows-targeting toolkits. Beyond Windtail and Windtape the cluster operates Windows- targeting implants including Karkoff (with attribution to Windshift contested.

some early reporting attributed Karkoff to DNSpionage / Iranian-aligned operations), credential-phishing kits, OAuth-application-consent phishing infrastructure, typosquatted-domain phishing, and standard living-off-the-land Windows tooling (PowerShell, mshta, rundll32, certutil) alongside Cobalt Strike Beacon. Initial access is predominantly via spear- phishing with weaponized Office documents and via credential- phishing landing pages mimicking Microsoft, Google, and UAE government services. A handful of operational notes: First, the cluster is ecosystem-adjacent to but operationally distinct from Stealth Falcon (separately covered as stealth_falcon.yaml, also UAE-state-aligned suspected, also Project-Raven-adjacent, but with a distinct toolkit and a longer-running 2012-onward operational history). The two clusters appear to operate within the same UAE state-cyber ecosystem but represent separate operational identities. Second, the cluster is ecosystem-adjacent to but distinct from Bahamut (already covered as bahamut.yaml, private mercenary with multiple suspected state clients including UAE). Bahamut's signature fake-news watering-hole infrastructure and Google- Play-Store Android implant distribution contrast with Windshift's spear-phishing-and-custom-macOS-implant tradecraft. The two clusters share partial victimology and shared-ecosystem adjacency but operate distinct toolkits and tradecraft. Third, the cluster is operationally distinct from Iranian-aligned clusters (APT33, APT34, APT35, APT39, MuddyWater, Imperial Kitten, Pioneer Kitten) which target some overlapping victim regions and use some overlapping CVE-exploitation tradecraft. The Iran ↔ UAE state-cyber dynamic is heavily asymmetric and the clusters operate against substantially different victim categories. Fourth, attribution to specifically the UAE state, though dominant in vendor reporting and corroborated by the September 2021 DOJ DPA on adjacent Project Raven operations, has not been confirmed by formal state attribution naming Windshift specifically. Treat the UAE-state-aligned framing as suspected at the cluster level even though the broader Project Raven ecosystem is formally documented. Fifth, the post-2021 reduced operational visibility of Windshift in public reporting may reflect either operational restructuring following the September 2021 DOJ action, or a shift in UAE state- cyber operations toward commercial mobile-surveillance products (Pegasus, Predator, others) rather than custom-implant development. Treat the cluster's contemporary status as analytically open.

Aliases

9
windshiftwind shiftwind_shiftkarkoff overlapdarkmatter overlapdark matter overlapproject raven adjacencyproject_raven_adjacencyg0112

MITRE ATT&CK aliases

1
Additional names MITRE lists for G0112.
Bahamut

Notable Campaigns

9
2023-2025Continued Operations (2023-2025)
2021DOJ Deferred Prosecution Agreement with Former NSA Personnel (September 14, 2021)
2019Reuters: Project Raven Investigation (January 30, 2019)
2019Karkoff / DNSpionage Attribution Confusion (2019)
2018-2024Bahamut Cluster-Adjacency Question (Ongoing)
2018-2022UAE Domestic and Diaspora Dissident Surveillance (2018-2022)
2018-2020macOS-Targeting Windtail Operations (2018-2020)
2018Palo Alto Networks Unit 42: Windshift Disclosure (August 2018)
2016-2024Pegasus Spyware Ecosystem Adjacency (Citizen Lab Research)

Attribution & Reporting

Attributed by
Palo Alto Networks Unit 42ReutersCitizen Lab (University of Toronto)Mandiant / FireEyeCisco TalosESETTrend MicroMicrosoftKasperskySentinelOneSymantecRecorded Future Insikt GroupVolexityAmnesty International Security LabAccess NowCluster25Cyfirma
Key reporting
reportPalo Alto Networks Unit 42: Windshift, Attacks Targeting the Middle East (August 2018), seminal cluster disclosure
reportReuters: Inside the UAE's Secret Hacking Team of American Mercenaries (January 30, 2019), foundational Project Raven investigation
reportReuters: Project Raven Series (2019-2020, multiple articles)
reportUS DOJ: Three Former US Intelligence Community and Military Personnel Agree to Pay More Than $1.68 Million to Resolve Charges of Providing Hacking-Related Services to UAE (September 14, 2021)
reportCitizen Lab: Stealth Falcon, Targeted Malware Attack Against UAE Dissidents (May 2016), adjacent cluster context
reportCitizen Lab: Sustained UAE Dissident-Surveillance Tracking (multiple years)
reportESET: WindTail macOS Backdoor Analysis
reportObjective-See: WindTail Technical Analysis (2018)
reportCisco Talos: DNSpionage / Karkoff Disclosure (April 2019), attribution-confusion adjacency
reportAmnesty International Security Lab: UAE Cyber-Surveillance Tracking (multiple years)
reportAccess Now: UAE Cyber-Surveillance Documentation
reportCluster25: Windshift UAE Operational Profile
reportMalpedia Actor Profile: Windshift
reportMITRE ATT&CK Group G0112, Windshift

Operational

State sponsor

Suspected United Arab Emirates state-aligned cyber-espionage cluster, widely assessed by vendor research (Palo Alto Networks Unit 42's seminal August 2018 disclosure, Citizen Lab, Reuters investigative reporting, ESET, Trend Micro, and others) to operate in alignment with UAE state intelligence interests, most plausibly as part of the broader UAE state-cyber ecosystem documented in Reuters' January 2019 "Project Raven" investigation. Project Raven was a UAE-state-funded offensive cyber operation operated by DarkMatter (a Abu Dhabi-based UAE-state-affiliated contractor) and staffed in part by former US National Security Agency personnel, conducting operations on behalf of UAE intelligence against UAE domestic dissidents, Qatari and Yemeni adversary entities, regional journalists, and US citizens including journalists critical of UAE policy. Whether Windshift is best understood as Project Raven-itself, as a sibling-cluster within the same UAE state- cyber ecosystem, or as a separate operation drawing on adjacent personnel and tooling remains analytically open in public reporting. No formal US, UK, or EU government attribution to a specific UAE state entity has been published.

the UAE-state-aligned framing rests on vendor research consensus and on Reuters' Project Raven investigative reporting. The cluster is operationally and attribution-wise adjacent to but distinct from Stealth Falcon (separately covered as stealth_falcon.yaml, also UAE-state-aligned suspected, also active within the Project Raven ecosystem) and from Bahamut (already covered as bahamut.yaml, private mercenary with multiple suspected clients including UAE)

Motivations
espionage, intelligence_gathering, dissident_surveillance, journalist_surveillance, human_rights_activist_surveillance, geopolitical_collection, regional_adversary_targeting
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)49/60 · 81%
Analytics (MITRE CAR)24/60 · 40%
Runtime / container (Falco)6/60 · 10%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)15/60 · 25%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

2 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
MSHTASAP IMPLANT
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin