logo

Stealth Falcon preying over Middle Eastern skies with Deadglyph

ID: 4265aaee-d37c-56ad-84fb-53d97d78c713

STIX ID: report--4265aaee-d37c-56ad-84fb-53d97d78c713

Feed Name: WeLiveSecurity (ESET Research)

Threat Score
90/100

Date Published: 2023-09-22

Date Updated: 2026-05-01

...
...

ESET Research discovered and analyzed Deadglyph, a sophisticated, modular backdoor attributed to the Stealth Falcon APT targeting a Middle Eastern government; the report describes a multistage registry-based loader, a native x64 Executor that hosts a .NET Orchestrator, module-based command delivery from C2, multiple evasion techniques (machine-specific keys, obfuscation, AMSI avoidance), associated multistage shellcode downloader, IoCs (file hashes, certificates, C2 addresses), and mapped MITRE ATT&CK techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.