Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware InvisiMole

InvisiMole

TLP:CLEAR
Family

AI Analysis

· 2 days ago

Executive Summary

InvisiMole is a modular Windows spyware framework that delivers two backdoor components (RC2FM & RC2CL) used by the InvisiMole Group for post‑exploitation, primarily against Ukrainian and Russian victims. The malware facilitates remote command execution, system discovery, and file manipulation, enabling persistent access and potential data exfiltration. Key capabilities include remote shell access, metadata harvesting, and modular payload deployment.

Enhanced Description

InvisiMole is a modular spyware framework that has operated as part of the InvisiMole Group’s campaign against primarily Ukrainian and Russian targets since at least 2013. The malware comprises two distinct back‑door components, RC2FM and RC2CL, which are delivered to compromised hosts via infrastructure also used by the Gamaredon group. Once executed, these modules perform a variety of post‑exploitation tasks that enable persistent access, reconnaissance, and data exfiltration within victim networks. RC2FM and RC2CL support remote command execution through a custom protocol, allowing adversaries to issue shell commands, manipulate files, and install additional payloads. The malware is also capable of collecting system and network metadata—such as usernames, installed software lists, and running processes—to facilitate further lateral movement. While detailed persistence mechanisms are not fully documented in the current public reports, the presence of a back‑door module implies use of typical Windows persistence techniques (e.g., registry run keys or scheduled tasks), combined with stealth tactics to evade detection. InvisioMole’s impact has been limited to a handful of victims, yet its modular nature and reuse of existing infrastructure make it more adaptable than many single-purpose spyware samples. The adversary group can extend the core by dropping additional modules that enable keylogging, credential harvesting, or remote desktop capabilities, allowing them to maintain long‑term espionage operations without significant changes to delivery channels. Overall, InvisiMole demonstrates a classic state‑sponsored tool designed for stealthy data collection and command control within targeted organizations.

Key Capabilities

  • Remote command execution via custom backdoor protocol
  • Discovery of user accounts, running processes, and installed software
  • File manipulation and installation of additional malicious modules
  • Potential for long‑term persistence using registry or scheduled tasks

ATT&CK Techniques

T1059
T1105
T1070
T1033

Recommended Actions

  • Deploy signature‑based detection for InvisiMole binaries and related backdoor artifacts (RC2FM/RC2CL).
  • Implement host‑based IDS rules to flag unknown command execution behavior and credential‑harvesting activity.
  • Enforce least privilege and disable remote administrative tools where possible.
  • Use application whitelisting to block execution of unknown Windows executables.
  • Monitor for unusual outbound RDP or SMB traffic that may carry custom backdoor communication.

Suggested Tags

spyware
backdoor
modular
RC2FM
RC2CL
InvisiMole Group
Gamaredon
Ukraine
Russia
ESET

Confidence Assessment

Confidence in identified capabilities and overall threat context is moderate, given the reliance on two public reports from ESET describing the existence of backdoor modules and their use of Gamaredon infrastructure. Detailed information about persistence mechanisms, delivery methods, command‑and‑control protocols, or specific exfiltration tactics remains unreported, creating gaps that limit full risk quantification.

Description

InvisiMole is a modular spyware program that has been used by the InvisiMole Group since at least 2013. InvisiMole has two backdoor modules called RC2FM and RC2CL that are used to perform post-exploitation activities. It has been discovered on compromised victims in the Ukraine and Russia. Gamaredon Group infrastructure has been used to download and execute InvisiMole against a small number of victims.(Citation: ESET InvisiMole June 2018)(Citation: ESET InvisiMole June 2020)

Details

Type
Malware
Platforms
Windows
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.