Stealth Falcon is a suspected United Arab Emirates-linked espionage threat actor known for long-running surveillance operations against political activists, dissidents, journalists, and government-related targets in the Middle East and North Africa. The group is also tracked under aliases including FruityArmor, Fruity Armor, Project Raven, G0038, and Daffodil Gust. Reporting has associated the actor with highly targeted intrusion activity and advanced operational tradecraft focused on intelligence collection rather than disruptive or financially motivated objectives. Stealth Falcon has been observed targeting government and defense entities, including espionage activity against organizations in Egypt, and has historically been linked to surveillance of civil society and regional political targets. The actor’s operations commonly rely on tailored delivery chains, social engineering, and stealthy post-compromise collection. Public reporting has also connected Stealth Falcon-related activity to abuse of legitimate Windows components and trusted binaries to reduce detection. A notable tradecraft element associated with the group is abuse of WebDAV-based working-directory hijacking techniques involving Internet Shortcut files and signed Windows binaries, including activity tied to CVE-2025-33053. The actor has been linked to execution chains that leverage LOLBins and other native Windows functionality to stage or launch payloads while blending into normal system behavior. Stealth Falcon malware has also been associated with PowerShell- and WMI-based execution and collection, enabling command execution, host profiling, and scripted tasking on victim systems. Observed Stealth Falcon malware capabilities include extensive host reconnaissance and victim profiling. Reported behaviors include querying the Windows Registry to determine installed software components such as .NET versions; collecting system information through WMI, including operating system build and version details, hardware manufacturer and model, serial number, system directory, and physical memory; enumerating running processes; identifying registered user and primary owner information; gathering local network information such as the ARP table; collecting data from the local system; and exfiltrating stolen information over existing HTTPS command-and-control channels. The group has also been associated with credential theft from sources including Windows Credential Vault and Outlook. Stealth Falcon’s operational profile is consistent with a state-aligned cyber espionage actor: selective targeting, emphasis on persistence and stealth, use of legitimate administrative mechanisms, and collection priorities aligned with political, diplomatic, defense, and intelligence requirements. While individual malware families and delivery chains may evolve, the actor is consistently characterized by covert surveillance, careful victim selection, and use of trusted Windows features to support execution, discovery, collection, and exfiltration.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
52 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
10 malware families attributed to this actor across reporting.
5 additional families tracked in Mallory.
5 CVEs this actor has used in observed campaigns. 5 of them exploited in the wild.
The most developed test set focused on CVE-2025-33053 (CVSS 8.8, now in CISA's KEV catalog), the WebDAV working-directory hijack Check Point documented last year in its Stealth Falcon reporting. The operator appeared to be reproducing it.
"Tracked as CVE-2025-21042, the flaw let hackers embed malware into a DNG image file, possibly texted to the victim through WhatsApp. It appears that device infections didn't require user interaction... constituting what's known as a zero-click attack."
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
...we discovered a Windows zero-day, CVE-2016-3393, being used by a threat actor known as FruityArmor to mount targeted attacks.
This analytic detects Windchill MethodServer log4j events that contain the CVE-2026-4681 exploitation probe run?c=echo%20GW_READY_OK . PTC identifies GW_READY_OK and related run?c= activity as log indicators associated with Windchill and FlexPLM exploitation.
42 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as the threat actor associated with abuse of CVE-2025-33053 via .url files and iediagcmd.exe.
Referenced as the threat actor from prior reporting that documented the original CVE-2025-33053 WebDAV working-directory hijack technique that this operator appeared to be reproducing.
Referenced as the actor whose previously reported CVE-2025-33053 tradecraft the observed operator appeared to reproduce or adapt for WebDAV-based shortcut execution.
Listed as an associated threat actor in the detection annotation for exploitation of the public-facing PTC Windchill vulnerability CVE-2026-4681.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.