Uptime Hamster: 10d 8h 5mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza Group5

Group5

1 incidentes 1 paises 0 sectores apt IR Ultimo: 2026-05-25
Aliases: G0043, eraleig ransomware, APT GROUP5
Ver en IntelTracker → APTTrail →
Group5 is a state-linked threat actor that first emerged in late 2015, known for consistently focusing its cyber espionage operations on individuals affiliated with the Syrian opposition. The group is assessed with moderate confidence to be tied to Iran, leveraging Iranian infrastructure, language tools, and domestic hosting services, and its activities align with Iranian geopolitical interests. Despite initial observations of lower technical sophistication, the group distinguishes itself through effective social engineering tactics that involve mimicking opposition narratives to ensnare targets. It was named Group5 by Citizen Lab researchers, noting it as the fifth distinct actor observed targeting this specific demographic, and is also tracked by MITRE ATT&CK as G0043.

Aliases del actor

G0043eraleig ransomwareAPT GROUP5

Actores similares

apt-group5actor · 1apt-45actor · 2apt-c-27actor · 2apt-c-01actor · 2apt-c-12actor · 1apt-18actor · 1apt-1877teamactor · 1apt-27actor · 1apt-30actor · 1apt-38actor · 1

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
Webunknowncitizenlab.caAPT GROUP5 indicators and references
Repositoriounknowngithub.comAPT GROUP5 indicators and references
Webunknownraw.githubusercontent.comAPT GROUP5 indicators and references
Motivacion