Members of the Syrian opposition were lured by hackers into participating in Skype with a person posing as a “Femme Fatale,” a beautiful woman who declares support for their cause.

Deceiving them into exchanging photos, the hackers send a self-extracting RAR that has been renamed and given the extension PIF (Program Information File). This type of file is not executable, but will run the data inside it.
Once opened, the photo of the "fatal woman" will "run" along with the malware included in the file.
Security researchers at FireEye have found that hackers used the DarkComet RAT (Remote Access Trojan) to gain full access to systems. They observed that the malware was delivered through a custom tool (BLACKSTAR), which makes it more difficult to detect.
It appears that the data captured amounts to approximately 7.7GB, including 64 Skype account databases, 31,107 conversations, 12,356 contacts, and 240,381 messages.
The hackers were very careful with what they stole and only in a few cases did they take data that was not relevant to their purpose.
The stolen information relates to military activities (satellite imagery and battle plans were found), political strategies and humanitarian needs assessments. The data also contained personal details about refugees, as well as documents and strategy elements from media briefings, situation reports and casualty lists.
FireEye a media activist. In all cases, they played a significant role in the organization.
Under the guise of “Femme Fatale,” hackers would gain valuable information about targets.
"Personal questions apparently helped hackers systematically gather information about their targets. Hackers sometimes returned to chat with victims after a period of inactivity to gather additional information," FireEye said in a report.
Researchers claim that the hacking group likely gathered a large amount of information by compromising a small number of systems, due to the fact that the Syrian opposition shares computers with satellite access to the Internet.
It appears that the hackers used a command and control server outside of Syria.
