Group5
1 incidentes
1 paises
0 sectores
apt IR Ultimo: 2026-05-25
Aliases: G0043, eraleig ransomware, APT GROUP5
Group5 is a state-linked threat actor that first emerged in late 2015, known for consistently focusing its cyber espionage operations on individuals affiliated with the Syrian opposition. The group is assessed with moderate confidence to be tied to Iran, leveraging Iranian infrastructure, language tools, and domestic hosting services, and its activities align with Iranian geopolitical interests. Despite initial observations of lower technical sophistication, the group distinguishes itself through effective social engineering tactics that involve mimicking opposition narratives to ensnare targets. It was named Group5 by Citizen Lab researchers, noting it as the fifth distinct actor observed targeting this specific demographic, and is also tracked by MITRE ATT&CK as G0043.
Canales, DLS e infraestructura asociada
Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.
| Tipo | Estado | Host / enlace | Title / ultimo titulo |
| Web | unknown | citizenlab.ca | APT GROUP5 indicators and references |
| Repositorio | unknown | github.com | APT GROUP5 indicators and references |
| Web | unknown | raw.githubusercontent.com | APT GROUP5 indicators and references |