◇ SIGN IN
← all actors
apt

Desert Falcons (original 2015 cluster)

unknownhigh confidence
APT / State-sponsored
Desert FalconAPT-C-23Arid Viper (overlapping cluster)
Attribution
Arabic-speaking cyber-mercenary/espionage group; assessed Palestinian-nexus with operators reportedly in Palestine, Egypt and Turkey
Origin
Palestinian Territories / regional (assessed)
First seen
2015
Last active
Activity largely subsumed into the Arid Viper / APT-C-23 cluster; no confirmed standalone campaign since the late 2010s
Motivation
Espionage
Confidence
high
MENA targeting
Palestine, Egypt, Israel, Jordan; secondary: Saudi Arabia, UAE, Morocco, Qatar
Sectors
Government, critical infrastructure, oil & gas, defense, media
MITRE ATT&CK
Why it mattersState-sponsored / APT actor, high confidence, documented targeting Palestine, Egypt, Israel (Government, critical infrastructure, oil & gas sectors).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.

Desert Falcons was described by Kaspersky in 2015 as the first known Arabic-speaking cyber-mercenary espionage group, targeting government, military, media and activists across the Middle East, with the vast majority of victims in Egypt, Palestine, Israel and Jordan.

History

Kaspersky publicly documented Desert Falcons in February 2015, calling it the first known Arabic group of cyber mercenaries to run full-scale cyber-espionage. Kaspersky reported the operation began building around 2011, achieved real infections from 2013, and peaked in early 2015, ultimately reaching 3,000+ victims across 50+ countries and exfiltrating over one million files.

Tradecraft relied on spear-phishing and social-engineering lures delivering the custom 'Falcon' backdoor (DHS/Trojan) for Windows plus early Android surveillance tooling, with heavy use of geopolitical bait themed around the Israeli-Palestinian conflict. Kaspersky assessed roughly 30 operators working in three teams based mainly in Palestine, Egypt and Turkey.

MENA targeting was the group's entire focus: military and government bodies (including anti-money-laundering, health and economic staff), leading media, research and education, energy providers, and political activists in Egypt, Palestine, Israel and Jordan.

Attribution note: MITRE ATT&CK lists 'Desert Falcon' as an alias of APT-C-23 / Arid Viper (G1028), and many analysts treat Desert Falcons as an earlier or overlapping name for the same Palestinian-nexus cluster. This profile is retained for the historical Kaspersky-defined campaign; confidence in the original 2015 activity is high, but its precise relationship to present-day Arid Viper operations is a medium-confidence assessment and there is no confirmed independent Desert-Falcons campaign in 2025-2026.

Notable campaigns

2015
Hunting Desert Falcons
Kaspersky exposed the group's multi-year espionage operation using the Falcon backdoor against 3,000+ Middle Eastern victims.
2013
Falcon backdoor campaign
Spear-phishing with political lures delivered custom Windows and early mobile spyware to government and media targets in Egypt, Palestine, Israel and Jordan.

Observed ATT&CK techniques · 15

TechniqueNameTacticObserved use
T1119Automated CollectioncollectionVendor report: attackers systematically "collect chats and screenshots" from infected systems.
T1113Screen CapturecollectionVendor report: "Screenshots" capability explicitly listed as a feature in both the main Trojan and the DHS spyware variant's functionality.
T1056.001Input Capture: KeyloggingcollectionVendor report: "Keylogs" included in the backdoor feature set for both primary malware variants.
T1123Audio CapturecollectionVendor report: the DHS spyware variant included "Audio recording" capability not present in earlier malware variants.
T1560Archive Collected DatacollectionVendor report: "Files and screenshots collected by the backdoor are sent to the C&C in a password-protected archive."
T1071.001Application Layer Protocol: Web Protocolscommand and controlVendor report: "Backdoor communicates with C&C servers using HTTP requests with encrypted content."
T1555.003Credentials from Password Stores: Credentials from Web Browserscredential accessVendor report: malware had the ability to "steal passwords stored on the system registry (Internet Explorer and live Messenger)", described as "Password stealing" in the DHS variant.
T1036.005Masquerading: Match Legitimate Name or Locationdefense evasionVendor report: malicious files stored in system directories under names like "skype.exe," "MSN.exe," and "msnn.dll" to blend with legitimate applications.
T1036.007Masquerading: Double File Extensiondefense evasionVendor report: malicious files delivered using an extension override so that a file ending in .fdp.scr would appear to the victim as .rcs.pdf.
T1036.002Masquerading: Right-to-Left Overridedefense evasionVendor report: attackers used "special characters in Unicode to reverse the order of characters in a file name, hiding the dangerous file extension in the file name and placing a harmless-looking fake file extension near the end."
T1564.001Hide Artifacts: Hidden Files and Directoriesdefense evasionVendor report: command sequence used "attrib c:\LA +h +s" to hide directories with hidden and system attributes.
T1083File and Directory DiscoverydiscoveryVendor report: backdoor collects a "complete list of all files (especially XLS, DOC, JPG and WAV)" from victim machines for operator review, and "Information on all the .doc and .xls files on the victim's hard disk or connected USB devices."
T1204.002User Execution: Malicious FileexecutionVendor report: RAR archives containing shortcuts (LNK files) that executed complex command sequences including unpacking, file copying, and malware execution, avoiding the need for the victim to directly double-click an executable.
T1566.003Phishing: Spearphishing via Serviceinitial accessVendor report: "Attackers created authentic Facebook accounts and then interacted with chosen victims through common Facebook pages until they had gained their trust. Then they sent them Trojan files in the chat hidden as an image."
T1566.001Phishing: Spearphishing Attachmentinitial accessVendor report: "Spear phishing e-mails that attempted to trick the victim into opening a malicious attachment" with carefully selected filenames targeting specific victims, particularly government and high-profile media.