Skip to content

Threat actor

Root Networks

Last fetched

Root Networks is a threat actor tracked in WhisperGraph's MITRE ATT&CK corpus, observed using 0 techniques.

Description

Root Networks (RN) is an Israeli company that developed systems capable of infiltrating local area networks (LANs) and intercepting communications without requiring cooperation from telecom operators. This capability enables intelligence services to conduct long-term surveillance and execute Man-in-the-Middle attacks to access encrypted communications. Captured data is redirected via VPN tunnels for detailed analysis. RN's technology exploits vulnerabilities in router firmware to gain remote access. By mapping and infiltrating vulnerable routers, the company establishes its own interception network, independent of traditional operators. This network allows RN to monitor target devices, such as smartphones and computers, and deploy spyware for further surveillance. Root Networks was founded by Avi Yarim, a former Rayzone Group specialist, and was led by CTO Shahar Mor, an ex-cybersecurity researcher at Verint. The company shares investors with Rayzone Group, including prominent figures like Yohai Ben-Zakai, a former deputy commander of Unit 8200, and businessman Eran Reshef.

Techniques by tactic

No ATT&CK techniques are recorded for Root Networks in WhisperGraph.

Attributed infrastructure

None published. WhisperGraph carries no ATTRIBUTED_TO edge to Root Networks today — this states the absence of a published link, not that Root Networks has no infrastructure.

References

© The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.

Related pages

Pivot from Root Networks into its techniques, tactics and any attributed infrastructure.

Queries

Resolves the slug to this actor, merging every duplicate node sharing the same name.


MATCH (a:ACTOR)
WHERE a.name =~ $pattern OR any(x IN a.aliases WHERE x =~ $pattern)
RETURN a.id AS id, a.name AS name, a.aliases AS aliases, a.description AS description,
       a.references AS references, a.campaigns AS campaigns
LIMIT 25
Run yourself →

Techniques this actor uses, grouped by the tactic each one serves.


MATCH (a:ACTOR {name: $name})-[:USES_TECHNIQUE]->(t:ATTACK_PATTERN)
OPTIONAL MATCH (t)-[:USES_TACTIC]->(tac:ATTACK_PATTERN)
RETURN t.id AS techniqueId, t.name AS techniqueName, tac.id AS tacticId, tac.name AS tacticName
LIMIT 1000
Run yourself →

Infrastructure publicly attributed to this actor.


MATCH (n)-[:ATTRIBUTED_TO]->(a:ACTOR {name: $name})
RETURN labels(n)[0] AS kind, n.name AS name
LIMIT 25
Run yourself →

Or query Whisper from your own LLM workflow via the Whisper MCP server.