Also known as: Operation Molerats, Gaza Cybergang, Gaza cyber gang, Gaza Hacker Team, Gaza, Gaza Hackers Team, Extreme Jackal, Moonlight, ALUMINUM SARATOGA, G0021, BLACKSTEM, Military, Government, Desert Falcon, APT-C-23, Two-tailed Scorpion, Golden Rat, Goldmouse, Arid Viper, Bearded Barbie, ATK80, NIOBIUM, RENEGADE JACKAL, Desert Falcons, Scimitar
Molerats is an Arabic-speaking, politically-motivated threat group that has been operating since 2012. The group's victims have primarily been in the Middle East, Europe, and the United States.(Citation: DustySky)(Citation: DustySky2)(Citation: Kaspersky MoleRATs April 2019)(Citation: Cybereason Molerats Dec 2020)
Targeted emails with malware. fake website with malicipretending to be a legitimate iOS management software, and linking to it in an online freelancing marketplace.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Molerats is a sophisticated Arabic-speaking cyber threat group that has been operational since at least 2012, primarily targeting organizations in sectors such as government, defense, financial services, and healthcare. They employ phishing campaigns, fake websites, and malware to achieve financial gain through espionage and data theft.
Goals & Targeting
Molerats' primary motivation appears to be financial gain, with politically motivated activities also playing a role. Their targeting profile includes high-value sectors such as government, defense, and healthcare, likely to maximize the potential for sensitive data theft or espionage. The group's focus on both Middle Eastern and Western targets suggests a global outlook aimed at maximizing opportunities for financial and intelligence gains.
Enhanced Description
Molerats is an Arabic-speaking threat group that has been active since at least 2012, with a primary focus on financially motivated activities despite its political motivations. The group targets a wide range of sectors including government, defense, financial services, healthcare, and education across the Middle East, Europe, and the United States. Their tactics include spear-phishing emails containing malware, fake websites disguised as legitimate iOS management software, and malicious links embedded in online marketplaces. Molerats has demonstrated the capability to remain stealthy and persistent in their campaigns, leveraging a variety of tools and techniques to compromise victims.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Molerats has been involved in multiple campaigns, including DustySky and TopHat, targeting various sectors globally. Their operational tempo suggests a focus on high-value targets with long-term goals of data exfiltration and financial gain. Notable campaigns involve the use of malicious email attachments, fake online marketplaces, and malware distribution via compromised websites.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in Molerats' existence and activity based on multiple sources, including Kaspersky and Cybereason reports. However, specific details about their operational TTPs beyond 2023 remain unclear, creating some gaps in understanding their evolving capabilities.
No observed data linked yet.
No IOCs linked yet.
16
Techniques
11
Tools
3
Campaigns
0
IOCs
0
Observed Data
8
Tactics