Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Molatori

Also known as: tracked as, services, other system resources, public key cryptography, one private, the file association, header, metamorphic, Gafgyt, the MSBlast, Lovesan worm, cryptojacking malware, consuming processing power, Downup, Downadup, Kido, Flamer, Skywiper, organizations, the Mydoom worm, Uroburos, the Induc virus, handler, Netshell, magic bytes, the IconEnvironmentDataBlock, mutating code

Description

Molatori is a shadowy threat actor group whose primary objective is financial fraud. According to Malwarebytes researchers, the actors use phishing emails that masquerade as official Social Security Administration notifications to entice victims into downloading an apparently legitimate ScreenConnect installer. The infected System runs a Remote Access Tool (RT‑RAT) such as AsyncRAT that provides full persistence and remote control capabilities. Once compromised, Molatori aggressively seeks to coerce the victim’s environment: it creates local, domain, and cloud provider accounts to strengthen footholds in Active Directory; it targets Office 365, Exchange, and Google Workspace servers for direct email access or data exfiltration via keyword searches with tools like MailSniper. In parallel, the group exploits vulnerable services—web, DNS, remote desktop—to lateral‑move and expand its reach. In addition to Remote Access Tool deployments, Molatori frequently hijacks legitimate Windows service binaries by abusing weak file permissions, allowing it to execute malware under the guise of system processes. The attackers also use compromised third‑party cloud accounts (Dropbox, OneDrive, AWS S3) as both exfiltration points and command‑and‑control channels. The actor’s operations are highly targeted: they prioritize high‑value sectors—financial services, media, defense, government, retail, non‑profits, energy, IT, healthcare, education—and geographically focus on the United States, Ukraine, Italy, and Iran. Their campaigns involve tailored social engineering assets (personalized personas, impersonation templates) and Endpoint Denial‑of‑Service attacks that temporarily degrade critical services.

Goals & Targeting

Targeted Sectors

Financial services
Media
Defense
Government
Retail
Non profit
Energy
Information technology
Healthcare
Education

Targeted Countries / Regions

US
IT
UA
IR

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 3 days ago

Executive Summary

Molatori is a financially motivated threat actor that employs sophisticated phishing campaigns to trick users into installing trojanized ScreenConnect installers, which then deploy Remote Access Tools such as AsyncRAT. The group leverages compromised third‑party cloud services for command‑and‑control and data exfiltration, while using local and domain accounts to maintain persistence across diverse sectors including finance, media, defense, and healthcare.

Goals & Targeting

Molatori’s overarching strategic goal is to harvest personally identifying information and financial data (bank account numbers, SSNs, credit card details) for subsequent identity theft or ransomware operations. The group focuses on high‑value target sectors where sensitive personal and corporate data abound. By infiltrating enterprise environments through deceptive phishing and then deploying Remote Access Tools, they can conduct extended reconnaissance, move laterally, hijack privileged accounts, exfiltrate data via compromised cloud services, and maintain long‑term persistence for future monetization. Their geographic focus includes the United States, Ukraine, Italy, and Iran, suggesting that operational convenience combined with high potential return drives their selection of victims.

Enhanced Description

Key Capabilities

  • Deploy Remote Access Tools (e.g., AsyncRAT) via trojanized ScreenConnect installers
  • Conduct phishing campaigns using fabricated official documents (e.g., fake Social Security statements)
  • Compromise third‑party web service accounts (GitHub, Google, Dropbox) and use them as command‑and‑control or exfiltration channels
  • Create local, domain, and cloud provider accounts to achieve persistence within victim environments
  • Target and exploit Office 365, Exchange, and Google Workspace servers for data exfiltration and direct email access
  • Use keyword searching tools such as MailSniper on mail services to locate valuable information
  • Execute Endpoint Denial‑of‑Service attacks against web, DNS, and HTTP services for disruption or cover
  • Exploit remote software vulnerabilities for lateral movement within compromised networks
  • Harvest detailed network trust and IP address information to refine targeting
  • Craft tailored social engineering content (personalized personas, impersonation templates)
  • Leverage improperly set file permissions to overwrite legitimate Windows service binaries and execute malicious payloads

MITRE ATT&CK Tactics

Command & Control
Exfiltration
Persistence
Privilege Escalation
Lateral Movement
Impact
Discovery
Execution

ATT&CK Techniques

T1071.003
T1048
T1566
T1499
T1210
T1021
T1098
T1482
T1046
T1547.004
T1602

Software / Tooling

AsyncRAT
ScreenConnect
MailSniper
PowerShell
netsh
Bashlite
BlackPOS
Cerber
Petya
Hook
Payload
MsBuild

Campaigns & Victims

Molatori’s known campaigns exhibit a modular approach that blends social engineering, Remote Access Tool deployment, and cloud‑service exploitation. They typically begin with phishing emails that deliver trojanized ScreenConnect installers, followed by installation of AsyncRAT. Once resident, the adversary constructs persistence layers through local/domain/cloud accounts, then expands visibility into the victim’s environment via automated discovery scripts (e.g., T1499). The group actively exfiltrates data over compromised cloud storage solutions while maintaining a low profile by using legitimate service endpoints for command‑and‑control traffic. Endpoint DoS attacks against DNS and web services are used both to cause disruption and to distract defenders during data staging or lateral movement phases. Molatori’s operations are highly opportunistic, targeting high‑value sectors across the US, UK, Italy, and Iran, often adjusting tactics based on the target’s defensive posture.

IOC Patterns

  • Phishing email with fabricated official documents
  • Trojanized legitimate installers (e.g., ScreenConnect)
  • Remote access tool payloads delivered via compromised installers
  • Compromised third‑party cloud or web service accounts used for C&C and exfiltration
  • Use of public cloud storage services (Dropbox, MEGA, OneDrive, AWS S3) to stage and move stolen data
  • Unauthorized local and domain account creation to maintain persistence
  • Endpoint Denial‑of‑Service attacks targeting web servers or DNS resources
  • Exploitation of vulnerable remote services on Exchange/O365/Google Workspace for lateral movement
  • Modification of Windows service binaries through file permission abuse

Recommended Actions

  • Verify authenticity of unsolicited documents before opening or executing them.
  • Educate employees about social engineering attempts, particularly counterfeit official communications.
  • Implement advanced email filtering and attachment scanning to block malicious downloads.
  • Detect and alert on installation of unauthorized remote access tools such as AsyncRAT or trojanized ScreenConnect executables.
  • Enforce strict multi‑factor authentication for all critical and third‑party service accounts.
  • Monitor Active Directory for anomalous local or domain account creation events.
  • Set up real‑time monitoring for abnormal outbound traffic to cloud storage services and web endpoints used for exfiltration.
  • Deploy network anomaly detection systems capable of spotting Endpoint DoS activity against DNS, HTTP, and other services.
  • Apply timely patching of known vulnerabilities in Exchange, Office 365, Google Workspace, and other remote services.
  • Configure granular access controls on service binaries directories to prevent unauthorized modifications.
  • Implement file integrity monitoring for critical system executables (e.g., svchost.exe, spoolsv.exe).
  • Map network trust relationships and enforce least‑privilege for partner and supply chain connections.
  • Conduct regular security awareness training focused on tailored social engineering tactics.

Suggested Tags

Phishing
Remote Access Tool
AsyncRAT
ScreenConnect
Social Engineering
Web Service Exploitation
Cloud Exfiltration
Account Persistence
Denial of Service
Privilege Escalation
Data Theft
Identity Theft
Financial Fraud

Confidence Assessment

The available intelligence provides a mid‑to‑high level of confidence in Molatori’s use of trojanized ScreenConnect installers, AsyncRAT deployments, and phishing campaigns targeting official documents. The linkage to compromised third‑party cloud accounts for C&C and exfiltration is corroborated by multiple sources but lacks granular visibility into the full command‑and‑control architecture. Detailed attack timelines, attribution certainty regarding specific state sponsors, and comprehensive coverage of all technical capabilities remain gaps that warrant further investigation.

ATT&CK Techniques

Privilege Escalation
1 technique
Reconnaissance
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. attack.mitre.org — Cited by web research for: services
  2. www.huntress.com — Cited by web research for: Gafgyt
  3. www.malwarebytes.com — Cited by web research for: Rootkit
  4. attack.mitre.org — Cited by web research for: Process Hollowing
  5. https://malpedia.caad.fkie.fraunhofer.de/details/win.asyncrat — Cited by AI analysis.
  6. https://malpedia.caad.fkie.fraunhofer.de/actor/molatori — Cited by AI analysis.

Intel Summary

50

Techniques

43

Tools

0

Campaigns

38

IOCs

0

Observed Data

14

Tactics

Tags

Financial Targeting
Critical Infrastructure
Phishing
Data Exfiltration
APT
financial-fraud
phishing
remote-access
Remote Access Tool
AsyncRAT
ScreenConnect
Social Engineering
Web Service Exploitation
Cloud Exfiltration
Account Persistence
Denial of Service
Privilege Escalation
Data Theft
Identity Theft
Financial Fraud

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
Ukraine (UA)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.