This document summarizes a report by Kaspersky Lab on evolving malware attacks originating in Syria. Malicious actors are using social engineering techniques like Skype messages, Facebook posts, and YouTube videos to distribute malware disguised as security programs. The malware payloads identified include remote access Trojans (RATs) like ShadowTech RAT and Dark Comet RAT. Over 100 malware samples have been found targeting activists and others in Syria, Lebanon, Turkey and other countries. The actors operate from locations including Syria, Russia, and Lebanon, and are constantly evolving their methods.