Also known as: tracked as, services, other system resources, public key cryptography, one private, the file association, header, metamorphic, Gafgyt, the MSBlast, Lovesan worm, cryptojacking malware, consuming processing power, Downup, Downadup, Kido, Flamer, Skywiper, organizations, the Mydoom worm, Uroburos, the Induc virus, handler, Netshell, magic bytes, the IconEnvironmentDataBlock, mutating code
Molatori is a shadowy threat actor group whose primary objective is financial fraud. According to Malwarebytes researchers, the actors use phishing emails that masquerade as official Social Security Administration notifications to entice victims into downloading an apparently legitimate ScreenConnect installer. The infected System runs a Remote Access Tool (RT‑RAT) such as AsyncRAT that provides full persistence and remote control capabilities. Once compromised, Molatori aggressively seeks to coerce the victim’s environment: it creates local, domain, and cloud provider accounts to strengthen footholds in Active Directory; it targets Office 365, Exchange, and Google Workspace servers for direct email access or data exfiltration via keyword searches with tools like MailSniper. In parallel, the group exploits vulnerable services—web, DNS, remote desktop—to lateral‑move and expand its reach. In addition to Remote Access Tool deployments, Molatori frequently hijacks legitimate Windows service binaries by abusing weak file permissions, allowing it to execute malware under the guise of system processes. The attackers also use compromised third‑party cloud accounts (Dropbox, OneDrive, AWS S3) as both exfiltration points and command‑and‑control channels. The actor’s operations are highly targeted: they prioritize high‑value sectors—financial services, media, defense, government, retail, non‑profits, energy, IT, healthcare, education—and geographically focus on the United States, Ukraine, Italy, and Iran. Their campaigns involve tailored social engineering assets (personalized personas, impersonation templates) and Endpoint Denial‑of‑Service attacks that temporarily degrade critical services.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Molatori is a financially motivated threat actor that employs sophisticated phishing campaigns to trick users into installing trojanized ScreenConnect installers, which then deploy Remote Access Tools such as AsyncRAT. The group leverages compromised third‑party cloud services for command‑and‑control and data exfiltration, while using local and domain accounts to maintain persistence across diverse sectors including finance, media, defense, and healthcare.
Goals & Targeting
Molatori’s overarching strategic goal is to harvest personally identifying information and financial data (bank account numbers, SSNs, credit card details) for subsequent identity theft or ransomware operations. The group focuses on high‑value target sectors where sensitive personal and corporate data abound. By infiltrating enterprise environments through deceptive phishing and then deploying Remote Access Tools, they can conduct extended reconnaissance, move laterally, hijack privileged accounts, exfiltrate data via compromised cloud services, and maintain long‑term persistence for future monetization. Their geographic focus includes the United States, Ukraine, Italy, and Iran, suggesting that operational convenience combined with high potential return drives their selection of victims.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Molatori’s known campaigns exhibit a modular approach that blends social engineering, Remote Access Tool deployment, and cloud‑service exploitation. They typically begin with phishing emails that deliver trojanized ScreenConnect installers, followed by installation of AsyncRAT. Once resident, the adversary constructs persistence layers through local/domain/cloud accounts, then expands visibility into the victim’s environment via automated discovery scripts (e.g., T1499). The group actively exfiltrates data over compromised cloud storage solutions while maintaining a low profile by using legitimate service endpoints for command‑and‑control traffic. Endpoint DoS attacks against DNS and web services are used both to cause disruption and to distract defenders during data staging or lateral movement phases. Molatori’s operations are highly opportunistic, targeting high‑value sectors across the US, UK, Italy, and Iran, often adjusting tactics based on the target’s defensive posture.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The available intelligence provides a mid‑to‑high level of confidence in Molatori’s use of trojanized ScreenConnect installers, AsyncRAT deployments, and phishing campaigns targeting official documents. The linkage to compromised third‑party cloud accounts for C&C and exfiltration is corroborated by multiple sources but lacks granular visibility into the full command‑and‑control architecture. Detailed attack timelines, attribution certainty regarding specific state sponsors, and comprehensive coverage of all technical capabilities remain gaps that warrant further investigation.
No campaigns linked yet.
No observed data linked yet.
50
Techniques
43
Tools
0
Campaigns
38
IOCs
0
Observed Data
14
Tactics