Kaspersky reported that the Desert Falcons group carried out a targeted cyber-espionage campaign against victims in the Middle East, marking one of the first publicly documented Arabic-speaking threat actors conducting sustained regional operations. The campaign targeted individuals and organizations of intelligence interest, including political activists, military and government entities, media outlets, and other high-value targets.
The operation relied on malware and surveillance tooling designed to steal sensitive data from compromised systems and monitor victims over time. Securelist said the attackers used tailored intrusion techniques and espionage-focused implants to collect documents, communications, and other information from infected devices, underscoring a persistent threat aimed at long-term intelligence gathering rather than disruptive or destructive attacks.

TTPs, infrastructure, and targeting history in one profile.
1 event from the most recent confirmed update back to the earliest known activity.
Securelist published a report titled "The Desert Falcons targeted attacks," documenting the threat activity attributed to the Desert Falcons group. No additional event details are available from the provided reference content.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.