CSIDB logo
Threat actor

Project Raven

Attribution profile

Type
Nation State
Location
United Arab Emirates
Known incidents
3 incidents
Sources
1 source
First seen
2016-01-01
Last seen
2017-06-08
Updated
2026-07-31 20:55
Aliases
2 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor identified in the open‑source reporting is the United Arab Emirates government, which U.S. intelligence officials have described as orchestrating the hacking of Qatari government news and social media sites. The actor is not referred to by a specific alias in the sources, but the attribution is consistently tied to the UAE state apparatus, with officials noting that it remains unclear whether the operation was conducted directly by Emirati personnel or through contracted third parties. The actor’s known targeting is limited to the media and communications sector of Qatar, specifically its government‑run news outlets and social‑media platforms, indicating a regional focus on the Gulf state. The stated strategic objective, as described by the officials who disclosed the operation, was to sow discord and provoke regional upheaval by publishing incendiary false statements attributed to Qatar’s emir, Sheikh Tamim Bin Hamad al‑Thani, including false claims that he had praised Iran and Hamas. This objective aligns with an influence‑operations motive rather than financial gain, and the sources do not provide any insight into the actor’s size, funding, or technical sophistication.

The tactics, techniques, and procedures referenced in the reporting are limited to the posting of fabricated quotes on compromised government news and social‑media sites, which constitutes a form of defacement and disinformation rather than the deployment of specific malware families or exploit kits. No details are provided regarding initial‑access vectors, payload delivery mechanisms, or post‑exploitation tooling, so no TTPs beyond the content‑manipulation activity can be affirmed from the material. Attribution to a state actor is explicitly cited, with U.S. officials linking the planning and execution discussions to senior members of the UAE government in late May 2017.

The most notable publicly reported operation linked to this actor is the May 2017 intrusion into Qatari government news and social‑media platforms, during which false quotations were disseminated that contributed to the ensuing diplomatic crisis between Qatar and its neighboring states. This incident is presented as a representative example of the actor’s use of cyber capabilities to achieve geopolitical influence through the manipulation of information environments. No additional campaigns or malware families are described in the supplied sources, so the profile remains confined to the observed influence‑operation activity and its state‑backed attribution.

Incidents

Attributed incidents are available to members.

3 incidents

Sources

Sources available to members: 1 source.

CSIDB