Israel, Turkey (MENA subset of a wider campaign; source also lists Austria, India, Italy, and US/Europe victims)
Sectors
Cross-sector
Why it mattersState-sponsored / APT actor, medium confidence, documented targeting Israel, Turkey (MENA subset of a wider campaign; source also lists Austria, India (Cross-sector sector).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.
No open hunts or recent alerts tracked against this actor right now.
The four features of this adversary's intrusions under the Diamond Model — adversary, capability, infrastructure, victim — assembled from tracked data; pivot from any vertex to the others.
Adversary5
Who is behind the activity — operator vs. customer.
Tradecraft, techniques, and tooling the adversary employs.
8 ATT&CK techniquesCommand and ControlPersistenceDefense EvasionExecution
Infrastructure
Physical/logical infrastructure used to deliver capability (C2, domains, relays).
No infrastructure indicators correlated in Radar yet.
Victim6
Targeting — sectors and geographies in scope.
Cross-sectorIsraelTurkey (MENA subset of a wider campaign; source also lists AustriaIndiaItalyand US/Europe victims)
Social-political (intent)Espionage
Operator ↔ CustomerOperator (intrusion crew) acting for a Customer (sponsoring interest) — attribution separates the two.
Honesty note
Attribution ≠ confirmation. BellaCiao operators (Charming Kitten-linked) is linked here via TTP overlap and shared infrastructure — not confirmed by original-source reporting. Treat this as a working hypothesis, not a settled fact.
Useful?
→
Gather Victim Host Informationtechnique
ATT&CK mapping
→Data EncodingtechniqueATT&CK mapping
→Server Software Component: Web ShelltechniqueATT&CK mapping
→Impair Defenses: Disable or Modify ToolstechniqueATT&CK mapping
→Protocol TunnelingtechniqueATT&CK mapping
→Create or Modify System Process: Windows ServicetechniqueATT&CK mapping
The actor's techniques grouped into kill-chain phases — a partial order across phases; techniques within a phase are co-occurring, not sequenced. Export opens in CTID's Attack Flow Builder.
8 techniques across 4 of 7 stages · 4 of 6 pre-objective stages show known tradecraft — each a chance to break the chain before Actions on Objectives.
1Reconnaissance1
T1592
2Weaponization
3Delivery
4Exploitation1
T1059.001
5Installation3
T1562.001T1505.003T1543.003
6Command & Control3
T1071.004T1132T1572
7Actions on Objectives
Honesty note
Phase groupings reflect ATT&CK tactic classification, not a confirmed operational timeline for BellaCiao operators (Charming Kitten-linked) — see the competing-hypotheses breakdown for how confident this attribution really is.