Threat group.View on attack.mitre.org
Molerats is an Arabic-speaking, politically-motivated threat group that has been operating since 2012. The group's victims have primarily been in the Middle East, Europe, and the United States.
| Technique | Procedure example |
|---|---|
| T1027.015 Compression |
Molerats has delivered compressed executables within ZIP files to victims. |
| T1053.005 Scheduled Task |
Molerats has created scheduled tasks to persistently run VBScripts. |
| T1057 Process Discovery |
Molerats actors obtained a list of active processes on the victim and sent them to C2 servers. |
| T1059.001 PowerShell |
Molerats used PowerShell implants on target machines. |
| T1059.005 Visual Basic |
Molerats used various implants, including those built with VBScript, on target machines. |
| T1059.007 JavaScript |
Molerats used various implants, including those built with JS, on target machines. |
| T1105 Ingress Tool Transfer |
Molerats used executables to download malicious files from different sources. |
| T1140 Deobfuscate/Decode Files or Information |
Molerats decompresses ZIP files once on the victim machine. |
| T1204.001 Malicious Link |
Molerats has sent malicious links via email trick users into opening a RAR archive and running an executable. |
| T1204.002 Malicious File |
Molerats has sent malicious files via email that tricked users into clicking Enable Content to run an embedded macro and to download malicious archives. |
| T1218.007 Msiexec |
Molerats has used msiexec.exe to execute an MSI payload. |
| T1547.001 Registry Run Keys / Startup Folder |
Molerats saved malicious files within the AppData and Startup folders to maintain persistence. |
| T1553.002 Code Signing |
Molerats has used forged Microsoft code-signing certificates on malware. |
| T1555.003 Credentials from Web Browsers |
Molerats used the public tool BrowserPasswordDump10 to dump passwords saved in browsers on victims. |
| T1566.001 Spearphishing Attachment |
Molerats has sent phishing emails with malicious Microsoft Word and PDF attachments. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.