Introduction
Molerats is an Arabic-speaking, politically-motivated threat group that has been operating since 2012. The groupβs victims have primarily been in the Middle East, Europe, and the United States. DustySky DustySky2 Kaspersky MoleRATs April 2019 Cybereason Molerats Dec 2020
Activities and Tactics
Targeted Sectors: Government, Defense, Energy, Finance, Healthcare, Pharmaceuticals, Education, Media, NGOs, Civil Society, Legal, Military
Country of Origin: π³οΈ Palestine
First Seen: 2013
Last Activity: 2023
Incident Type: Espionage
Suspected Victims: United States, Israel, Palestine, Middle East, Europe
Notable Campaigns
- Molerats
- DustySky
- TopHat
Tactics, Techniques, and Procedures (TTPs)
- T1218.007 Msiexec
- T1204.001 Malicious Link
- T1105 Ingress Tool Transfer
- T1553.002 Code Signing
- T1027.015 Compression
- T1053.005 Scheduled Task
- T1140 Deobfuscate/Decode Files or Information
- T1566.001 Spearphishing Attachment
- T1057 Process Discovery
- T1566.002 Spearphishing Link
- T1555.003 Credentials from Web Browsers
- T1547.001 Registry Run Keys / Startup Folder
- T1059.001 PowerShell
- T1059.005 Visual Basic
- T1059.007 JavaScript
- T1204.002 Malicious File
ATT&CK technique IDs (denormalized)
- T1027.015
- T1053.005
- T1057
- T1059.001
- T1059.005
- T1059.007
- T1105
- T1140
- T1204.001
- T1204.002
- T1218.007
- T1547.001
- T1553.002
- T1555.003
- T1566.001
- T1566.002
Notable Indicators of Compromise (IOCs)
No atomic indicators are listed in this profile. The APTnotes snapshot indexes 4 public reports that may contain IOCs; see Source Attribution for dataset links.
Malware and Tools
- Archelaus Beta
- Poison Ivy:
- DustySky:
- NeD Worm:
- Scote:
- Donβt Kill My Cat (DKMC):
- RTFs Exploiting CVE-2017-0199:
MITRE ATT&CK Software
- MoleNet (S0553) β malware
- Spark (S0543) β malware
- DustySky (S0062) β malware
- DropBook (S0547) β malware
- SharpStage (S0546) β malware
- PoisonIvy (S0012) β malware
Attribution and Evidence
Country of Origin: Palestine Additional attribution information pending cataloguing.
References
[1] mitre-attack [5] DustySky2 ClearSky Cybersecurity. (2016, June 9). Operation DustySky - Part 2. Retrieved August 3, 2016. [6] DustySky ClearSky. (2016, January 7). Operation DustySky. Retrieved January 8, 2016. [7] Cybereason Molerats Dec 2020 Cybereason Nocturnus Team. (2020, December 9). MOLERATS IN THE CLOUD: New Malware Arsenal Abuses Cloud Platforms in Middle East Espionage Campaign. Retrieved December 22, 2020. [8] Kaspersky MoleRATs April 2019 GReAT. (2019, April 10). Gaza Cybergang Group1, operation SneakyPastes. Retrieved May 13, 2020. [9] FireEye Operation Molerats Villeneuve, N., Haq, H., Moran, N. (2013, August 23). OPERATION MOLERATS: MIDDLE EAST CYBER ATTACKS USING POISON IVY. Retrieved November 17, 2024.