DarkMatter is an Abu Dhabi-based UAE cyberintelligence and hacking firm, also described in the content as a UAE cyber unit. The content states that DarkMatter employed former U.S. National Security Agency (NSA) hackers for offensive operations targeting foreign officials and journalists. It is also linked in the content to the ToTok surveillance operation: technical analysis and reporting cited in the content indicate that Breej Holding, the company behind the ToTok chat and VoIP application, was most likely a front company affiliated with DarkMatter. In that operation, ToTok is described as a legitimate-looking communications app used for mass surveillance by the UAE government, collecting data such as contacts, microphone access, location, calendar, photos, camera data, and other user information, with data transmitted to UAE-controlled infrastructure. Based on the provided content, DarkMatter is associated with UAE state-linked offensive cyber and intelligence collection activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
19 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
UAE cyber unit conducting offensive operations targeting foreign officials and journalists.
DarkMatter is known for conducting cyberintelligence and surveillance operations on behalf of the United Arab Emirates, including the development and deployment of surveillance tools such as the ToTok app to monitor users' communications, contacts, and locations.
DarkMatter Group
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.