Group5 is a threat actor documented by Citizen Lab in 2016 that targeted the Syrian opposition using off-the-shelf RATs and phishing, with circumstantial indicators pointing to an Iranian nexus. Attribution and scope are uncertain — a single-source, low-medium-confidence entry.
Additional names this actor is known by across other vendors' naming schemes — cross-referenced from external crosswalk sources, not RaqibCTI's own curated aliases (shown at the top of this page). Each source is attributed to its own licence.
Group5 was named and documented by Citizen Lab in August 2016 ('Group5: Syria and the Iranian Connection'). The 'Group5' label reflects that it was the fifth distinct actor Citizen Lab had observed targeting the Syrian opposition. Attribution is explicitly tentative and rated low-medium confidence: circumstantial indicators (Iranian infrastructure, Persian-language artifacts, and Iranian hosting) suggested a possible Iranian nexus, but Citizen Lab stopped short of firm attribution, and the group has attracted little subsequent independent reporting and has no MITRE Group ID.
The group's tradecraft was low-sophistication but well-tailored to its targets: socially engineered spearphishing and decoy documents themed around Syrian opposition politics, delivering commodity remote-access trojans (including njRAT and NanoCore) and using droppers and obfuscation to evade basic defenses. The reliance on off-the-shelf tooling is consistent with a resource-modest but politically directed operation.
MENA relevance is the group's entire mission: it focused on members of the Syrian opposition and affiliated individuals, aiming to surveil communications and activities amid the Syrian civil war — an operation of interest to the Assad regime and, per the circumstantial indicators, possibly to Iranian backers supporting it.
No distinct Group5 activity has been reported since the 2016 Citizen Lab disclosure, so it is assessed as retired. It is included as a single-source Levantine-conflict surveillance historical entry, explicitly flagged low-medium confidence, `origin_country` left Unknown, and G-ID-less.