Executive Summary
InvisiMole is a modular Windows spyware framework that delivers two backdoor components (RC2FM & RC2CL) used by the InvisiMole Group for post‑exploitation, primarily against Ukrainian and Russian victims. The malware facilitates remote command execution, system discovery, and file manipulation, enabling persistent access and potential data exfiltration. Key capabilities include remote shell access, metadata harvesting, and modular payload deployment.
Enhanced Description
InvisiMole is a modular spyware framework that has operated as part of the InvisiMole Group’s campaign against primarily Ukrainian and Russian targets since at least 2013. The malware comprises two distinct back‑door components, RC2FM and RC2CL, which are delivered to compromised hosts via infrastructure also used by the Gamaredon group. Once executed, these modules perform a variety of post‑exploitation tasks that enable persistent access, reconnaissance, and data exfiltration within victim networks. RC2FM and RC2CL support remote command execution through a custom protocol, allowing adversaries to issue shell commands, manipulate files, and install additional payloads. The malware is also capable of collecting system and network metadata—such as usernames, installed software lists, and running processes—to facilitate further lateral movement. While detailed persistence mechanisms are not fully documented in the current public reports, the presence of a back‑door module implies use of typical Windows persistence techniques (e.g., registry run keys or scheduled tasks), combined with stealth tactics to evade detection. InvisioMole’s impact has been limited to a handful of victims, yet its modular nature and reuse of existing infrastructure make it more adaptable than many single-purpose spyware samples. The adversary group can extend the core by dropping additional modules that enable keylogging, credential harvesting, or remote desktop capabilities, allowing them to maintain long‑term espionage operations without significant changes to delivery channels. Overall, InvisiMole demonstrates a classic state‑sponsored tool designed for stealthy data collection and command control within targeted organizations.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in identified capabilities and overall threat context is moderate, given the reliance on two public reports from ESET describing the existence of backdoor modules and their use of Gamaredon infrastructure. Detailed information about persistence mechanisms, delivery methods, command‑and‑control protocols, or specific exfiltration tactics remains unreported, creating gaps that limit full risk quantification.
InvisiMole is a modular spyware program that has been used by the InvisiMole Group since at least 2013. InvisiMole has two backdoor modules called RC2FM and RC2CL that are used to perform post-exploitation activities. It has been discovered on compromised victims in the Ukraine and Russia. Gamaredon Group infrastructure has been used to download and execute InvisiMole against a small number of victims.(Citation: ESET InvisiMole June 2018)(Citation: ESET InvisiMole June 2020)