Skip to main content
Mallory
9 malware families

aluminum_saratoga

Also known asaluminum_saratoga

ALUMINUM SARATOGA is a threat group that self-styles as the Gaza Hackers Team and is assessed with moderate confidence to be of Palestinian origin. The group has been active since at least 2011 and operates primarily against targets in the Middle East and North Africa. Public reporting tracks this actor as Molerats and Dusty Sky / Operation DustySky; additional aliases mentioned in the content include Gaza Cybergang, Extreme Jackal, TA402, APT-C-23, Arid Viper, and Desert Falcon. The group is associated with targeted spearphishing operations, as well as disruptive activity including DDoS attacks and website defacements. Reported tooling includes publicly available remote access tools and malware such as PoisonIvy, XtremeRAT, QuasarRAT, DarkComet, BlackShades, NimbleMamba, BrittleBush, LastConn, and Micropsia. A campaign spanning late 2021 to early 2022 used phishing lures delivered through actor-controlled infrastructure and Dropbox links and deployed NimbleMamba and BrittleBush.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal9

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.