STEALTH FALCON
G0038
UAE
APT
Threat IntelligenceAPTJanuary 21, 2026

Stealth Falcon Threat Profile

UAE-linked group conducting surveillance against dissidents, journalists, and activists using sophisticated spyware.

UAE-linked group conducting surveillance against dissidents, journalists, and activists using sophisticated spyware. This profile is mapped to MITRE ATT&CK G0038 and covers attribution, tooling, targeting, and defensive recommendations based on observed campaigns.

Overview & Attribution

Stealth Falcon (also tracked as None publicly documented) is a threat group attributed to UAE. The group primarily targets UAE dissidents, journalists, activists for intelligence collection and operational objectives aligned with state interests.

MITRE ATT&CK Reference

This group is tracked as G0038 in the MITRE ATT&CK framework. All techniques referenced in this report are mapped to ATT&CK for consistent threat modeling and detection engineering.

Arsenal & Tools

Known tools and malware associated with Stealth Falcon include:

Targeting & Operations

Stealth Falcon operations focus on UAE dissidents, journalists, activists. The group typically gains initial access through spear-phishing, exploitation of public-facing applications, or strategic web compromises before deploying custom implants for persistent access and data exfiltration.

Targeting Advisory

Organizations in the UAE dissidents sector should treat Stealth Falcon as a relevant threat and validate their detection coverage against the MITRE ATT&CK techniques listed below.

MITRE ATT&CK Mapping

Key techniques observed in Stealth Falcon operations:

Technique IDTechnique NameTactical Context
T1566.001T1566.001Observed in Stealth Falcon campaigns
T1059.001T1059.001Observed in Stealth Falcon campaigns
T1113T1113Observed in Stealth Falcon campaigns
T1056.001T1056.001Observed in Stealth Falcon campaigns

Full ATT&CK mapping: https://attack.mitre.org/groups/G0038/

Notable Campaigns

This threat group has been active in operations targeting UAE dissidents, journalists, activists. Security researchers have documented campaigns involving Win32/StealthFalcon backdoor and other tools deployed against organizations in multiple countries. Attribution confidence varies by campaign, but consistent infrastructure and TTP overlap links activity to UAE-nexus operations.

Detection & Defense

Recommended defensive measures against Stealth Falcon:

How Mjolnir Security Can Help

Defend Against Stealth Falcon

Mjolnir Security provides tailored threat intelligence, detection engineering, and incident response services to help organizations defend against UAE-nexus threat actors.

Threat Intelligence Detection Engineering Incident Response Red Team Assessment Threat Hunting

Contact us: mjolnirsecurity.com

Written by: Mjolnir Security  |  Published: January 21, 2026