Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →The group behind the 2015 report of thousands of victims across dozens of countries was Desert Falcons, a cyber-espionage operation identified by Kaspersky. Its campaign targeted politically and geopolitically sensitive organizations and individuals, using spear-phishing and malware for Windows and Android. The figures describe a historical operation disclosed in February 2015, not a current count of victims.
Who were the Desert Falcons?
Kaspersky described Desert Falcons as the first known Arabic group to develop and operate a full-scale cyber-espionage campaign. The researchers assessed that the operators appeared to be native Arabic speakers; that description does not establish who sponsored or controlled the group.
The campaign was built over several years. Kaspersky said it had been active for at least two years when disclosed in February 2015.
| Milestone | What Kaspersky reported |
|---|---|
| 2011 | Development of the campaign began. |
| 2013 | The first infections occurred. |
| February 2015 | Kaspersky disclosed the operation, which it said was then at least two years active and had peaked in early 2015. |
How many victims did the group attack?
In its 2015 disclosure, Kaspersky reported more than 3,000 victims in over 50 countries and more than one million files stolen. Researchers estimated that at least 30 operators worked across three teams. These are Kaspersky’s historical campaign findings; they should not be read as a live or independently updated victim tally.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minuteWho and where did Desert Falcons target?
The largest concentration of identified victims was in Egypt, Palestine, Israel, and Jordan. Kaspersky also identified victims in countries including Qatar, Saudi Arabia, the United Arab Emirates, Algeria, Lebanon, Norway, Turkey, Sweden, France, the United States, and Russia, as well as elsewhere.
#1 Best Overall
The targets spanned organizations and people likely to hold politically or geopolitically sensitive information:
- Military and government organizations
- Media, research, and education
- Energy and utilities
- Activists and political leaders
- Physical-security companies
This pattern supports describing the operation as politically oriented espionage and information collection. It does not, by itself, identify a state sponsor.
How did Desert Falcons spread its malware?
The main delivery method was spear-phishing: attackers sent tailored messages through email, social-network posts, or chat, using lures that looked like legitimate documents or applications. The approach depended on persuading a target to open or run a file.
Filename spoofing with a right-to-left override
One reported trick used a Unicode right-to-left extension override to make a filename appear to end in a harmless document extension even when the underlying file ended in an executable extension such as .exe or .scr. A displayed name alone could therefore misrepresent what would run when opened. The technique is a reason to verify unexpected attachments through a trusted channel and to pay attention to the actual file type, not just its visible name.
Rank #3
What could the malware do?
Kaspersky identified a main Desert Falcons Trojan and the DHS Backdoor, which it said appeared to have been developed from scratch and updated over time. The investigation identified more than 100 malware samples targeting Windows PCs and Android devices.
Windows capabilities
The reported tools could take screenshots, log keystrokes, upload and download files, collect Word and Excel documents from hard disks and connected USB devices, steal passwords stored in the system registry, and record audio.
Rank #4
Android capabilities
The Android backdoor could steal mobile-call and SMS logs. Together, the reported capabilities point to surveillance and data theft rather than a campaign whose defining purpose was destructive disruption.
Was Desert Falcons connected to a government?
The cited Kaspersky findings do not prove sponsorship by a named government. The defensible attribution is limited to the Desert Falcons threat-actor name and Kaspersky’s assessment that its operators appeared to be native Arabic speakers. Politically sensitive targeting is evidence about the campaign’s interests, not proof of who directed it.
Best Value
How should it be distinguished from later activity?
Later Arabic-language or Middle East-focused cyber activity is not automatically part of Desert Falcons. Reporting on WIRTE and on hack-for-hire cases investigated in 2023–2024 describes separate contexts; it does not establish that those actors were Desert Falcons or that the earlier campaign continued under another name.
Quick Recap
What the 2015 disclosure established
- Desert Falcons was the group named in Kaspersky’s account of a large Arabic-associated cyber-espionage campaign.
- The reported scale was more than 3,000 victims in over 50 countries and more than one million stolen files, according to Kaspersky in 2015.
- Spear-phishing and social engineering delivered malware, including through filenames that used a Unicode right-to-left override to disguise executable extensions.
- Windows and Android tools enabled surveillance, credential theft, and document collection.
- The largest victim concentration was in Egypt, Palestine, Israel, and Jordan, with additional victims across other regions.
- The cited account did not establish government sponsorship.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

