Desert Falcons was described by Kaspersky in 2015 as the first known Arabic-speaking cyber-mercenary espionage group, targeting government, military, media and activists across the Middle East, with the vast majority of victims in Egypt, Palestine, Israel and Jordan.
Kaspersky publicly documented Desert Falcons in February 2015, calling it the first known Arabic group of cyber mercenaries to run full-scale cyber-espionage. Kaspersky reported the operation began building around 2011, achieved real infections from 2013, and peaked in early 2015, ultimately reaching 3,000+ victims across 50+ countries and exfiltrating over one million files.
Tradecraft relied on spear-phishing and social-engineering lures delivering the custom 'Falcon' backdoor (DHS/Trojan) for Windows plus early Android surveillance tooling, with heavy use of geopolitical bait themed around the Israeli-Palestinian conflict. Kaspersky assessed roughly 30 operators working in three teams based mainly in Palestine, Egypt and Turkey.
MENA targeting was the group's entire focus: military and government bodies (including anti-money-laundering, health and economic staff), leading media, research and education, energy providers, and political activists in Egypt, Palestine, Israel and Jordan.
Attribution note: MITRE ATT&CK lists 'Desert Falcon' as an alias of APT-C-23 / Arid Viper (G1028), and many analysts treat Desert Falcons as an earlier or overlapping name for the same Palestinian-nexus cluster. This profile is retained for the historical Kaspersky-defined campaign; confidence in the original 2015 activity is high, but its precise relationship to present-day Arid Viper operations is a medium-confidence assessment and there is no confirmed independent Desert-Falcons campaign in 2025-2026.
| Technique | Name | Tactic | Observed use |
|---|---|---|---|
| T1119 ↗ | Automated Collection | collection | Vendor report: attackers systematically "collect chats and screenshots" from infected systems. |
| T1113 ↗ | Screen Capture | collection | Vendor report: "Screenshots" capability explicitly listed as a feature in both the main Trojan and the DHS spyware variant's functionality. |
| T1056.001 ↗ | Input Capture: Keylogging | collection | Vendor report: "Keylogs" included in the backdoor feature set for both primary malware variants. |
| T1123 ↗ | Audio Capture | collection | Vendor report: the DHS spyware variant included "Audio recording" capability not present in earlier malware variants. |
| T1560 ↗ | Archive Collected Data | collection | Vendor report: "Files and screenshots collected by the backdoor are sent to the C&C in a password-protected archive." |
| T1071.001 ↗ | Application Layer Protocol: Web Protocols | command and control | Vendor report: "Backdoor communicates with C&C servers using HTTP requests with encrypted content." |
| T1555.003 ↗ | Credentials from Password Stores: Credentials from Web Browsers | credential access | Vendor report: malware had the ability to "steal passwords stored on the system registry (Internet Explorer and live Messenger)", described as "Password stealing" in the DHS variant. |
| T1036.005 ↗ | Masquerading: Match Legitimate Name or Location | defense evasion | Vendor report: malicious files stored in system directories under names like "skype.exe," "MSN.exe," and "msnn.dll" to blend with legitimate applications. |
| T1036.007 ↗ | Masquerading: Double File Extension | defense evasion | Vendor report: malicious files delivered using an extension override so that a file ending in .fdp.scr would appear to the victim as .rcs.pdf. |
| T1036.002 ↗ | Masquerading: Right-to-Left Override | defense evasion | Vendor report: attackers used "special characters in Unicode to reverse the order of characters in a file name, hiding the dangerous file extension in the file name and placing a harmless-looking fake file extension near the end." |
| T1564.001 ↗ | Hide Artifacts: Hidden Files and Directories | defense evasion | Vendor report: command sequence used "attrib c:\LA +h +s" to hide directories with hidden and system attributes. |
| T1083 ↗ | File and Directory Discovery | discovery | Vendor report: backdoor collects a "complete list of all files (especially XLS, DOC, JPG and WAV)" from victim machines for operator review, and "Information on all the .doc and .xls files on the victim's hard disk or connected USB devices." |
| T1204.002 ↗ | User Execution: Malicious File | execution | Vendor report: RAR archives containing shortcuts (LNK files) that executed complex command sequences including unpacking, file copying, and malware execution, avoiding the need for the victim to directly double-click an executable. |
| T1566.003 ↗ | Phishing: Spearphishing via Service | initial access | Vendor report: "Attackers created authentic Facebook accounts and then interacted with chosen victims through common Facebook pages until they had gained their trust. Then they sent them Trojan files in the chat hidden as an image." |
| T1566.001 ↗ | Phishing: Spearphishing Attachment | initial access | Vendor report: "Spear phishing e-mails that attempted to trick the victim into opening a malicious attachment" with carefully selected filenames targeting specific victims, particularly government and high-profile media. |