Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Molerats

Also known as: Operation Molerats, Gaza Cybergang, Gaza cyber gang, Gaza Hacker Team, Gaza, Gaza Hackers Team, Extreme Jackal, Moonlight, ALUMINUM SARATOGA, G0021, BLACKSTEM, Military, Government, Desert Falcon, APT-C-23, Two-tailed Scorpion, Golden Rat, Goldmouse, Arid Viper, Bearded Barbie, ATK80, NIOBIUM, RENEGADE JACKAL, Desert Falcons, Scimitar

Description

Molerats is an Arabic-speaking, politically-motivated threat group that has been operating since 2012. The group's victims have primarily been in the Middle East, Europe, and the United States.(Citation: DustySky)(Citation: DustySky2)(Citation: Kaspersky MoleRATs April 2019)(Citation: Cybereason Molerats Dec 2020)

TTP Summary

Targeted emails with malware. fake website with malicipretending to be a legitimate iOS management software, and linking to it in an online freelancing marketplace.

Goals & Targeting

Targeted Sectors

Government
Defense
Financial services
Aerospace & defense
Energy
Financial services
Healthcare
Pharmaceutical
Education
Media
Non profit
Legal services
Telecommunications
Transportation

Targeted Countries / Regions

US
IL
SA

AI Analysis

· 1 week ago

Executive Summary

Molerats is a sophisticated Arabic-speaking cyber threat group that has been operational since at least 2012, primarily targeting organizations in sectors such as government, defense, financial services, and healthcare. They employ phishing campaigns, fake websites, and malware to achieve financial gain through espionage and data theft.

Goals & Targeting

Molerats' primary motivation appears to be financial gain, with politically motivated activities also playing a role. Their targeting profile includes high-value sectors such as government, defense, and healthcare, likely to maximize the potential for sensitive data theft or espionage. The group's focus on both Middle Eastern and Western targets suggests a global outlook aimed at maximizing opportunities for financial and intelligence gains.

Enhanced Description

Molerats is an Arabic-speaking threat group that has been active since at least 2012, with a primary focus on financially motivated activities despite its political motivations. The group targets a wide range of sectors including government, defense, financial services, healthcare, and education across the Middle East, Europe, and the United States. Their tactics include spear-phishing emails containing malware, fake websites disguised as legitimate iOS management software, and malicious links embedded in online marketplaces. Molerats has demonstrated the capability to remain stealthy and persistent in their campaigns, leveraging a variety of tools and techniques to compromise victims.

Key Capabilities

  • Sophisticated phishing campaigns using malware
  • Creation of fake websites mimicking legitimate software
  • Use of malicious links and attachments in email campaigns
  • Persistence techniques including registry modifications and scheduled tasks

MITRE ATT&CK Tactics

Reconnaissance
Subversion
Resource Development
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Exfiltration
Impact

ATT&CK Techniques

T1053.005
T1027.015
T1059.007
T1204.002
T1553.002
T1566.002
T1218.007
T1059.001
T1204.001
T1566.001
T1140
T1555.003
T1057
T1547.001
T1059.005
T1105

Software / Tooling

Spark
SharpStage
DropBook
MoleNet
PoisonIvy

Campaigns & Victims

Molerats has been involved in multiple campaigns, including DustySky and TopHat, targeting various sectors globally. Their operational tempo suggests a focus on high-value targets with long-term goals of data exfiltration and financial gain. Notable campaigns involve the use of malicious email attachments, fake online marketplaces, and malware distribution via compromised websites.

IOC Patterns

  • Spear-phishing emails with malicious attachments
  • Fake websites mimicking legitimate software
  • Malicious links embedded in spear-phishing emails
  • Use of scheduled tasks and registry modifications for persistence

Recommended Actions

  • Implement rigorous email filtering to detect spear-phishing attempts.
  • Monitor for suspicious activity on known malicious domains and IP addresses.
  • Enhance endpoint detection and response (EDR) capabilities to identify and block MoleNet and PoisonIvy-related processes.
  • Conduct regular user training to raise awareness of phishing threats.
  • Secure APIs and web-facing applications to mitigate potential exploitation by tools like Spark.

Suggested Tags

APT
financial-gain
espionage
government
defense

Confidence Assessment

High confidence in Molerats' existence and activity based on multiple sources, including Kaspersky and Cybereason reports. However, specific details about their operational TTPs beyond 2023 remain unclear, creating some gaps in understanding their evolving capabilities.

ATT&CK Techniques

Execution
6 techniques

Campaigns / Victims

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. DustySky2 — ClearSky Cybersecurity. (2016, June 9). Operation DustySky - Part 2. Retrieved August 3, 2016.
  2. DustySky — ClearSky. (2016, January 7). Operation DustySky. Retrieved January 8, 2016.
  3. Cybereason Molerats Dec 2020 — Cybereason Nocturnus Team. (2020, December 9). MOLERATS IN THE CLOUD: New Malware Arsenal Abuses Cloud Platforms in Middle East Espionage Campaign. Retrieved December 22, 2020.
  4. Kaspersky MoleRATs April 2019 — GReAT. (2019, April 10). Gaza Cybergang Group1, operation SneakyPastes. Retrieved May 13, 2020.
  5. FireEye Operation Molerats — Villeneuve, N., Haq, H., Moran, N. (2013, August 23). OPERATION MOLERATS: MIDDLE EAST CYBER ATTACKS USING POISON IVY. Retrieved November 17, 2024.

Intel Summary

16

Techniques

11

Tools

3

Campaigns

0

IOCs

0

Observed Data

8

Tactics

Tags

APT
financial-gain
espionage
government
defense

Details

MITRE ID
G0021
Type
Unknown
Resource Level
Unknown
Primary Motivation
Financial gain
Country of Origin
P
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--df71bb3b-813c-45eb-a8bc-f2a419837411
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.