Media activists and humanitarian workers also were targeted. The Fire Eye researchers say the attacks they have investigated were not only aimed at seeking an information or propaganda edge but were taking place "in the heat of a conflict" and were providing "actionable military intelligence for an immediate battlefield advantage." The information being grabbed could "thwart a vital supply route, reveal a planned ambush, and identify and track key individuals." A leaked manual described the use of methods that were "eerily similar" to those being employed now, including the use of femme fatales to entrap opposition members and fighters on Facebook and Skype. Researcher Nart Villeneuve says Fire Eye is unable to identify precisely who is behind the tailored attacks, but adds: "We know that they used social media to infiltrate victims' machines and steal military information that would provide an advantage to President Assad's forces on the battlefield." The cyber threat company has focused its investigation on a series of attacks mounted between November 2013 and January 2014. The interest of researchers was piqued when they came across a cache of stolen rebel battle plans in mid-2013 for an operation to capture the town of Khirbet Ghazaleh near the city of Daraa.

The victims of the attacks were based in rebel-held areas in northern Syria but also elsewhere in Lebanon, Jordan and the Gulf.

Less sophisticated attacks have involved the sending out of mass emails urging recipients to click on a link to see the latest video showing the brutal tactics of the Syrian army or Assad loyalists.

Clicking on the link leads, in fact, to the installation of malware allowing pro-Assad hackers to log keystrokes and to snatch screenshots of the target’s computer, which is effectively put under their control.

