Threat actor
Root Networks
Last fetched
Root Networks is a threat actor tracked in WhisperGraph's MITRE ATT&CK corpus, observed using 0 techniques.
Description
Root Networks (RN) is an Israeli company that developed systems capable of infiltrating local area networks (LANs) and intercepting communications without requiring cooperation from telecom operators. This capability enables intelligence services to conduct long-term surveillance and execute Man-in-the-Middle attacks to access encrypted communications. Captured data is redirected via VPN tunnels for detailed analysis. RN's technology exploits vulnerabilities in router firmware to gain remote access. By mapping and infiltrating vulnerable routers, the company establishes its own interception network, independent of traditional operators. This network allows RN to monitor target devices, such as smartphones and computers, and deploy spyware for further surveillance. Root Networks was founded by Avi Yarim, a former Rayzone Group specialist, and was led by CTO Shahar Mor, an ex-cybersecurity researcher at Verint. The company shares investors with Rayzone Group, including prominent figures like Yohai Ben-Zakai, a former deputy commander of Unit 8200, and businessman Eran Reshef.
Techniques by tactic
No ATT&CK techniques are recorded for Root Networks in WhisperGraph.
Attributed infrastructure
None published. WhisperGraph carries no ATTRIBUTED_TO edge to Root Networks today — this states the absence of a published link, not that Root Networks has no infrastructure.
References
- https://www.intelligenceonline.com/surveillance--interception/2019/06/05/root-networks-markets-operator-free-interceptions,108359989-art
- https://www.intelligenceonline.com/surveillance--interception/2021/01/21/rayzone-s-interception-modus-operandi-exposed-by-legal-cases,109636393-art
- https://finder.startupnationcentral.org/company_page/root-networks?section=team
© The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.
Related pages
Pivot from Root Networks into its techniques, tactics and any attributed infrastructure.
Queries
Resolves the slug to this actor, merging every duplicate node sharing the same name.
MATCH (a:ACTOR)
WHERE a.name =~ $pattern OR any(x IN a.aliases WHERE x =~ $pattern)
RETURN a.id AS id, a.name AS name, a.aliases AS aliases, a.description AS description,
a.references AS references, a.campaigns AS campaigns
LIMIT 25Run yourself →Techniques this actor uses, grouped by the tactic each one serves.
MATCH (a:ACTOR {name: $name})-[:USES_TECHNIQUE]->(t:ATTACK_PATTERN)
OPTIONAL MATCH (t)-[:USES_TACTIC]->(tac:ATTACK_PATTERN)
RETURN t.id AS techniqueId, t.name AS techniqueName, tac.id AS tacticId, tac.name AS tacticName
LIMIT 1000Run yourself →Infrastructure publicly attributed to this actor.
MATCH (n)-[:ATTRIBUTED_TO]->(a:ACTOR {name: $name})
RETURN labels(n)[0] AS kind, n.name AS name
LIMIT 25Run yourself →Or query Whisper from your own LLM workflow via the Whisper MCP server.