Uptime Hamster: 10d 9h 47mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza Sphinx

Sphinx

0 incidentes 0 paises 0 sectores apt EG Ultimo: -
Aliases: este grupo se destaca por su enfoque en la clasificación
Ver en IntelTracker → APTTrail →
Sphinx, also identified as APT-C-15, is a cyber espionage threat actor assessed to originate from the Middle East, primarily motivated by the acquisition and exfiltration of sensitive data from specific targets. The group’s activity was observed through malware timestamps as early as 2011, with a significant campaign identified between June 2014 and November 2015 that targeted PC users in the Middle East. A notable shift in their operational model occurred around 2017, when Sphinx expanded its focus to mobile cyber espionage, leveraging the AnubisSpy malware to target Arabic-speaking users. A defining characteristic of Sphinx is its adaptive approach to targeting across different platforms, maintaining shared command-and-control infrastructure between its earlier PC-focused campaigns utilizing njRAT and its subsequent mobile operations with AnubisSpy. This group should not be conflated with the distinct Anubis ransomware operation, which used 'Sphinx' as an early development codename i

Aliases del actor

este grupo se destaca por su enfoque en la clasificación

Actores similares

dfir-reportactor · 10CS FQL: Qué significa cada cosa (columna por columna)actor · 1vapor-pandaactor · 1temporaryactor · 1Harvesterapt · 0BRONZE VAPORapt · 0
Motivacion