Stealth Falcon
Also reported as FruityArmor, Project Raven, Daffodil Gust and Fruity Armor. Linked to United Arab Emirates by four sources.
Reports per quarter
Techniques seen in the last two years
- T1005 2 reports in ATT&CK
- T1027 2 reports reports only
- T1041 2 reports in ATT&CK
- T1106 2 reports reports only
- T1112 2 reports reports only
- T1140 2 reports reports only
- T1007 1 report reports only
- T1008 1 report reports only
- T1012 1 report in ATT&CK
- T1016 1 report in ATT&CK
Show all 46 techniques Show fewer
- T1020 1 report reports only
- T1033 1 report in ATT&CK
- T1036 1 report reports only
- T1047 1 report in ATT&CK
- T1053 1 report reports only
- T1057 1 report in ATT&CK
- T1059 1 report in ATT&CK
- T1059.003 1 report reports only
- T1070.004 1 report reports only
- T1071.001 1 report in ATT&CK
- T1074 1 report reports only
- T1082 1 report in ATT&CK
- T1090 1 report reports only
- T1091 1 report reports only
- T1105 1 report reports only
- T1134 1 report reports only
- T1190 1 report reports only
- T1195 1 report reports only
- T1197 1 report reports only
- T1204.002 1 report reports only
- T1218.011 1 report reports only
- T1480.001 1 report reports only
- T1518 1 report reports only
- T1518.001 1 report reports only
- T1546.003 1 report reports only
- T1557 1 report reports only
- T1566.001 1 report reports only
- T1566.002 1 report reports only
- T1566.003 1 report reports only
- T1573.001 1 report in ATT&CK
- T1583.001 1 report reports only
- T1583.003 1 report reports only
- T1587.001 1 report reports only
- T1588.003 1 report reports only
- T1620 1 report reports only
- T1659 1 report reports only
Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.
Also listed by ATT&CK
CVEs named in reports
- CVE-2010-3333 KEV
- CVE-2013-3660 KEV
- CVE-2014-4113 KEV
- CVE-2015-0057
- CVE-2015-1701 KEV ransomware
- CVE-2016-0165 KEV
- CVE-2016-1010 KEV
- CVE-2016-3393 KEV
- CVE-2016-4171 KEV
- CVE-2016-4655 KEV
- CVE-2016-4656 KEV
- CVE-2016-4657 KEV
Show all 80 CVEs Show fewer
- CVE-2016-5195 KEV
- CVE-2016-7255 KEV ransomware
- CVE-2017-0199 KEV ransomware
- CVE-2017-0263 KEV
- CVE-2017-10271 KEV ransomware
- CVE-2017-11882 KEV ransomware
- CVE-2017-12824
- CVE-2017-8570 KEV
- CVE-2018-13379 KEV ransomware
- CVE-2018-15982 KEV ransomware
- CVE-2018-20250 KEV ransomware
- CVE-2018-4878 KEV ransomware
- CVE-2018-6055
- CVE-2018-8242
- CVE-2018-8373 KEV
- CVE-2018-8414 KEV
- CVE-2018-8440 KEV ransomware
- CVE-2018-8453 KEV ransomware
- CVE-2018-8589 KEV
- CVE-2018-8611 KEV
- CVE-2019-0708 KEV ransomware
- CVE-2019-0797 KEV
- CVE-2019-0808 KEV
- CVE-2019-0859 KEV ransomware
- CVE-2019-10149 KEV
- CVE-2019-1069 KEV ransomware
- CVE-2019-1132 KEV
- CVE-2019-11510 KEV ransomware
- CVE-2019-11707 KEV
- CVE-2019-11708 KEV
- CVE-2019-1367 KEV ransomware
- CVE-2019-13720 KEV
- CVE-2019-1458 KEV ransomware
- CVE-2019-1652 KEV
- CVE-2019-1653 KEV
- CVE-2019-19781 KEV ransomware
- CVE-2019-2215 KEV
- CVE-2019-3568 KEV
- CVE-2019-5786 KEV
- CVE-2019-6225
- CVE-2019-7286 KEV
- CVE-2019-7287 KEV
- CVE-2019-8518
- CVE-2019-8641
- CVE-2019-9670 KEV
- CVE-2020-0787 KEV ransomware
- CVE-2020-0796 KEV ransomware
- CVE-2020-0986 KEV
- CVE-2020-10189 KEV
- CVE-2020-5902 KEV ransomware
- CVE-2021-21166 KEV
- CVE-2021-26605
- CVE-2021-28310 KEV
- CVE-2021-30551 KEV
- CVE-2021-30858 KEV
- CVE-2021-31979 KEV
- CVE-2021-33742 KEV
- CVE-2021-33771 KEV
- CVE-2021-34523 KEV ransomware
- CVE-2023-36884 KEV ransomware
- CVE-2024-11182 KEV
- CVE-2024-49039 KEV ransomware
- CVE-2024-9680 KEV ransomware
- CVE-2025-21042 KEV
- CVE-2025-21043 KEV
- CVE-2025-33053 KEV
- CVE-2025-43300 KEV
- CVE-2025-55177 KEV
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
Stealth Falcon, FruityArmor - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Stealth Falcon, FruityArmor - Threat Group Cards: A Threat Actor Encyclopedia
Show all 35 reports Show fewer
-
Exploit archaeology: a forensic history of in-the-wild NSO Group exploits
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Exploit archaeology: a forensic history of in-the-wild NSO Group exploits
-
Mercenary APTs – An Exploration
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Mercenary APTs – An Exploration
-
Hooking Candiru Another Mercenary Spyware Vendor Comes into Focus
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Hooking Candiru Another Mercenary Spyware Vendor Comes into Focus
-
Running in Circles Uncovering the Clients of Cyberespionage Firm Circles
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Running in Circles Uncovering the Clients of Cyberespionage Firm Circles
-
Group-IB_Hi-Tech_Crime_Trends_2020-2021_en
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Group-IB_Hi-Tech_Crime_Trends_2020-2021_en
-
Exploit Developer Spotlight- The Story of PlayBit
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Exploit Developer Spotlight- The Story of PlayBit
-
2020.02.22_APT_threat_report_2019_CN_version
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 2020.02.22_APT_threat_report_2019_CN_version
-
APT_trends_report_Q1_2019_Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT_trends_report_Q1_2019_Securelist
-
The fourth horseman- CVE-2019-0797 vulnerability
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The fourth horseman- CVE-2019-0797 vulnerability
-
2018 APT Summary Report CN version
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 2018 APT Summary Report CN version
-
Zero-day in Windows Kernel Transaction Manager (CVE-2018-8611)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Zero-day in Windows Kernel Transaction Manager (CVE-2018-8611)
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The Million Dollar Dissident: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender - The Citizen Lab
-
Keep Calm and (Don’t) Enable Macros- A New Threat Actor Targets UAE Dissidents
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Keep Calm and (Don’t) Enable Macros- A New Threat Actor Targets UAE Dissidents
-
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Stealth Falcon
Newest first. Details opens the report in Explore.