Syrian activists were hit by a sustained surveillance campaign that combined Facebook phishing with malware-laced files masquerading as revolutionary documents and other trusted content. Electronic Frontier Foundation reporting described attackers stealing account credentials through fake login pages and deploying remote-access trojans to monitor victims, with one later campaign using the commercially available BlackShades malware to capture data and maintain access to compromised systems.
A separate EFF report said Vietnamese activists also faced highly personalized malware operations, indicating that threat actors tailored lures and surveillance tools to specific individuals and their relationships. Taken together, the incidents showed politically motivated targeting of dissidents through social engineering, credential theft, and commodity as well as custom malware designed to spy on activists and their networks.

Get the infrastructure and lures behind it.
5 events from the most recent confirmed update back to the earliest known activity.
EFF documented a Vietnamese malware campaign that had become highly personalized, suggesting attackers were tailoring lures and targeting to specific individuals. The reporting highlighted a more intimate and deliberate form of surveillance against Vietnamese activists or dissidents.
EFF reported that malware targeting Syrian activists included the Blackshades remote access trojan, a commercially available surveillance tool. This revealed additional technical detail about the tooling used in the campaign.
EFF disclosed a trojan distributed inside fake revolutionary documents aimed at Syrian activists. The lures were crafted to appear relevant to the Syrian uprising, indicating continued refinement of social-engineering methods.
A new wave of Facebook phishing attacks was reported against Syrian activists, showing attackers were using credential theft alongside malware to gain access to accounts. The activity represented a distinct tactic in the broader targeting campaign.
EFF reported a campaign using surveillance malware to target Syrian activists, marking an escalation in digital attacks against opposition figures. The reporting indicated the malware was being used to monitor victims and compromise their communications.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
6 references tracked. Mallory keeps watching after this page renders.
web.archive.org
Open sourceeff.org
Open sourceeff.org
Open sourceeff.org
Open sourceeff.org
Open sourceeff.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.