Molerats
Molerats, also referred to as Gaza Cybergang, Operation Molerats, TA402, WIRTE, and Ashen Lepus, is a suspected Hamas-aligned, Arab-speaking threat cluster active since at least 2012. The group is described as politically motivated and focused primarily on intelligence collection and espionage, with operations mainly targeting Palestinian entities and Israel. Supporting content also links Gaza Cybergang to Palestine-based activity and associates it with the Jerusalem Electronic Army hacktivist persona. Known tooling and malware associated with Molerats in the provided content include DustySky (also called NeD Worm by its developer), DropBook, SharpStage, MoleNet, and WIRTE. DustySky is described as a multi-stage malware in use since May 2015 and used by Molerats for intelligence gathering. WIRTE activity in the content includes use of PowerShell for script execution, Base64 to decode malicious VBS scripts, staging collected documents in C:\Users\Public, and use of the Windows command line in infection chains to open documents. Initial access and execution tradecraft described in the content centers on phishing and user execution. Molerats sent phishing emails with malicious Microsoft Word and PDF attachments, as well as malicious links and archives. Victims were tricked into clicking Enable Content to run embedded macros and download malicious archives. The group is also described as using malicious files delivered by email and spearphishing attachments more broadly. Persistence behavior in the content includes saving malicious files within AppData and Startup folders, and placing malicious LNK files or files in Startup-related folders. Execution techniques explicitly mentioned include PowerShell execution, shared modules execution, malicious file execution, macro-enabled document execution, and command-line-assisted document opening. Credential access is also documented: Molerats used the public tool BrowserPasswordDump10/BrowserPasswordDump to dump passwords saved in victims' browsers. The content additionally notes infrastructure overlap identified by Citizen Lab between an Egypt-linked FinFisher lure domain and known MOLERATS domains, but does not establish Molerats as a FinFisher operator.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Government & Administration
- Military
- Financial Services
- Independent Media
- Software & Services
Where they target
Geographies tied to known operations.
- 🇮🇱 Israel
- 🇪🇬 Egypt
- 🇸🇦 Saudi Arabia
- 🇦🇪 United Arab Emirates
- 🇮🇶 Iraq
- 🇺🇸 United States
Where they're from
Attributed origin per open-source reporting.
- PS
Tradecraft
47 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
30 malware families attributed to this actor across reporting.
25 additional families tracked in Mallory.
Associated vulnerabilities
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
Observables
542 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as a threat actor associated with the PowerShell P/Invoke process injection API chain detection and related ATT&CK techniques.
Listed as a threat actor associated with PowerShell execution behavior relevant to this detection analytic.
Listed as a threat actor associated with Windows Command Shell execution behavior relevant to this detection.
Listed as a threat actor associated with exploitation of public-facing applications and malware/tool upload activity relevant to Confluence exploitation detection.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.