ATT&CKGroupsMolerats

Molerats

G0021

Threat group.View on attack.mitre.org

About this group

Molerats is an Arabic-speaking, politically-motivated threat group that has been operating since 2012. The group's victims have primarily been in the Middle East, Europe, and the United States.

Techniques used16

Procedure examples16

TechniqueProcedure example
T1027.015
Compression

Molerats has delivered compressed executables within ZIP files to victims.

T1053.005
Scheduled Task

Molerats has created scheduled tasks to persistently run VBScripts.

T1057
Process Discovery

Molerats actors obtained a list of active processes on the victim and sent them to C2 servers.

T1059.001
PowerShell

Molerats used PowerShell implants on target machines.

T1059.005
Visual Basic

Molerats used various implants, including those built with VBScript, on target machines.

T1059.007
JavaScript

Molerats used various implants, including those built with JS, on target machines.

T1105
Ingress Tool Transfer

Molerats used executables to download malicious files from different sources.

T1140
Deobfuscate/Decode Files or Information

Molerats decompresses ZIP files once on the victim machine.

T1204.001
Malicious Link

Molerats has sent malicious links via email trick users into opening a RAR archive and running an executable.

T1204.002
Malicious File

Molerats has sent malicious files via email that tricked users into clicking Enable Content to run an embedded macro and to download malicious archives.

T1218.007
Msiexec

Molerats has used msiexec.exe to execute an MSI payload.

T1547.001
Registry Run Keys / Startup Folder

Molerats saved malicious files within the AppData and Startup folders to maintain persistence.

T1553.002
Code Signing

Molerats has used forged Microsoft code-signing certificates on malware.

T1555.003
Credentials from Web Browsers

Molerats used the public tool BrowserPasswordDump10 to dump passwords saved in browsers on victims.

T1566.001
Spearphishing Attachment

Molerats has sent phishing emails with malicious Microsoft Word and PDF attachments.

View all 16 procedure examples

Software6

Campaigns0

None recorded.

References4

  1. Cybereason Molerats Dec 2020 Open source
    Cybereason Nocturnus Team. (2020, December 9). MOLERATS IN THE CLOUD: New Malware Arsenal Abuses Cloud Platforms in Middle East Espionage Campaign. Retrieved December 22, 2020.
  2. DustySky Open source
    ClearSky. (2016, January 7). Operation DustySky. Retrieved January 8, 2016.
  3. DustySky2 Open source
    ClearSky Cybersecurity. (2016, June 9). Operation DustySky - Part 2. Retrieved August 3, 2016.
  4. Kaspersky MoleRATs April 2019 Open source
    GReAT. (2019, April 10). Gaza Cybergang Group1, operation SneakyPastes. Retrieved May 13, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.