Stealth Falcon is malware associated with the Stealth Falcon intrusion activity that targeted UAE dissidents at home and abroad in a campaign spanning roughly 2012 to 2016. The activity is described as likely linked to a UAE government agency. Reported behavior includes gathering system information via Windows Management Instrumentation (WMI) and communicating with command-and-control infrastructure over HTTPS. In the described campaign, operators sent links using a fake URL shortener; the JavaScript behind those links profiled targets’ computers, checked which antivirus products were installed, and attempted to deanonymize users of Tor. High-confidence details in the provided content indicate targeting of dissidents, use of HTTPS C2, and host reconnaissance via WMI and browser-delivered profiling code.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes threat actors and malware using PowerShell commands/scripts to download, execute, load in memory, and run payloads, e.g., "APT28 downloads and executes PowerShell scripts" and "APT3 has used PowerShell on victim systems to download and run payloads after exploitation."
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Stealth Falcon is a threat actor and associated spyware toolkit used in targeted surveillance campaigns, primarily against UAE dissidents, journalists, and activists. It uses spearphishing, malicious documents, and custom spyware to profile and compromise targets.
Malware that communicates with C2 via HTTPS.
Malware that uses WMI for system information collection.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.