MoleNet

S0553

Malware.View on attack.mitre.org

About this malware

MoleNet is a downloader tool with backdoor capabilities that has been observed in use since at least 2019.

Techniques used7

Procedure examples7

TechniqueProcedure example
T1047
Windows Management Instrumentation

MoleNet can perform WMI commands on the system.

T1059.001
PowerShell

MoleNet can use PowerShell to set persistence.

T1059.003
Windows Command Shell

MoleNet can execute commands via the command line utility.

T1082
System Information Discovery

MoleNet can collect information about the about the system.

T1105
Ingress Tool Transfer

MoleNet can download additional payloads from the C2.

T1518.001
Security Software Discovery

MoleNet can use WMI commands to check the system for firewall and antivirus software.

T1547.001
Registry Run Keys / Startup Folder

MoleNet can achieve persitence on the infected machine by setting the Registry run key.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Cybereason Molerats Dec 2020 Open source
    Cybereason Nocturnus Team. (2020, December 9). MOLERATS IN THE CLOUD: New Malware Arsenal Abuses Cloud Platforms in Middle East Espionage Campaign. Retrieved December 22, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.