Threat actor
Almenta
Last fetched
Almenta is a threat actor tracked in WhisperGraph's MITRE ATT&CK corpus, observed using 0 techniques.
Description
Almenta is a surveillance firm based in Bulgaria and run by Israeli operators, including CEO Ari Covitz. It develops Wi-Fi-based hacking tools, which it showcased at the Milipol homeland security conference. The company offers a product called WiNA-P, which enables a variety of attacks on smartphones by exploiting Wi-Fi networks. These attacks include delivering malware to extract data from apps like WhatsApp, Telegram, Facebook, and Skype, as well as phishing capabilities to steal login credentials through fake landing pages. Almenta also advertises an "Account Grabber" feature to identify iCloud or Android accounts by sending deceptive messages to targets. Alongside WiNA-P, Almenta promotes a product called “Observer,” which offers “worldwide geo location,” as described in a blurb on Milipol’s website. A brochure for “Observer” reveals that, with only a target’s mobile phone number, the device’s location can be pinpointed and displayed on a Google Maps interface. The company claims its tools can operate from up to 500 meters away and target as many as 50 devices simultaneously. Almenta's technology reportedly relies on tools from other Israeli surveillance firms, such as WiSpear and Jenovice, with costs for such systems starting at $1 million.
Techniques by tactic
No ATT&CK techniques are recorded for Almenta in WhisperGraph.
Attributed infrastructure
None published. WhisperGraph carries no ATTRIBUTED_TO edge to Almenta today — this states the absence of a published link, not that Almenta has no infrastructure.
References
- https://www.thedailybeast.com/the-companies-that-will-track-any-phone-on-the-planet/
- https://www.forbes.com/sites/thomasbrewster/2017/12/04/whatsapp-hacks-with-wifi-trojans-almenta-wispear-jenovice/
- https://www.intelligenceonline.com/surveillance--interception/2022/01/18/us-interception-specialist-almenta-still-has-strong-grip-on-asian-market,109717518-art
- https://www.documentcloud.org/documents/3956251-Almenta-Group-Observer-Brochure/#document/p1/a371598
- https://www.intelligenceonline.com/surveillance--interception/2024/10/18/sofia-israeli-cyber-specialists--trusted-european-base,110328942-eve
© The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.
Related pages
Pivot from Almenta into its techniques, tactics and any attributed infrastructure.
Queries
Resolves the slug to this actor, merging every duplicate node sharing the same name.
MATCH (a:ACTOR)
WHERE a.name =~ $pattern OR any(x IN a.aliases WHERE x =~ $pattern)
RETURN a.id AS id, a.name AS name, a.aliases AS aliases, a.description AS description,
a.references AS references, a.campaigns AS campaigns
LIMIT 25Run yourself →Techniques this actor uses, grouped by the tactic each one serves.
MATCH (a:ACTOR {name: $name})-[:USES_TECHNIQUE]->(t:ATTACK_PATTERN)
OPTIONAL MATCH (t)-[:USES_TACTIC]->(tac:ATTACK_PATTERN)
RETURN t.id AS techniqueId, t.name AS techniqueName, tac.id AS tacticId, tac.name AS tacticName
LIMIT 1000Run yourself →Infrastructure publicly attributed to this actor.
MATCH (n)-[:ATTRIBUTED_TO]->(a:ACTOR {name: $name})
RETURN labels(n)[0] AS kind, n.name AS name
LIMIT 25Run yourself →Or query Whisper from your own LLM workflow via the Whisper MCP server.