StealthFalcon is an espionage-focused threat actor associated with targeted operations in the Middle East, Africa, and South Asia. Reported activity shows the group exploiting CVE-2025-33053 as a zero-day against organizations in Turkey, Qatar, Egypt, Ethiopia, and Yemen. Additional reporting places StealthFalcon operations in Türkiye and Pakistan, consistent with a pattern of selective intelligence collection against regional governmental and organizational targets. The actor is tracked under the name StealthFalcon; a suspected similarity to a differently formatted alias has been noted but not confirmed. Observed tradecraft supports a mature intrusion capability centered on initial access through exploitation of previously unknown vulnerabilities, followed by post-compromise espionage activity. The available evidence directly supports zero-day exploitation and targeted intrusion operations, but does not provide high-confidence detail on malware families, persistence mechanisms, lateral movement, or exfiltration procedures specific to this actor. The dominant motivation is espionage.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
Tracked as CVE-2025-21042, this out-of-bounds write security flaw was discovered in Samsung's libimagecodec.quram.so library, allowing remote attackers to gain code execution on devices running Android 13 and later.
discovery of a zero-day exploited by StealthFalcon: CVE-2025-33053, a vulnerability used to target high-profile organizations in Turkey, Qatar, Egypt, Ethiopia and Yemen.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
PSOA-linked actor exploiting a zero-day (CVE-2025-33053) to target high-profile organizations across multiple Middle East/Africa countries.
PSOA-linked actor exploiting a zero-day (CVE-2025-33053) to target high-profile organizations across the Middle East and Africa.
Espionage-focused operations targeting Türkiye and Pakistan.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.