logo

Molerats__2020__Molerats-in-the-Cloud-New-Malware-Arsenal-Abuses-Cloud-Platforms-in-Middle-East-Espionage-Campaign.pdf

ID: 01049b82-2f58-4132-81eb-61be20392f51

STIX ID: report--01049b82-2f58-4132-81eb-61be20392f51

Threat Score

85/100

Uploaded: 2026-08-19

Published Date: 2020-12-09

Last Modified Date: 2020-12-09

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
**Executive summary:** Cybereason Nocturnus details an active, targeted espionage campaign attributed to the Molerats (Gaza Cybergang) that uses newly discovered backdoors (SharpStage, DropBook), the MoleNet downloader and previously observed tools (Spark, Pierogi). The actors leverage social engineering themed to Middle Eastern politics to deliver payloads, use legitimate cloud services (Dropbox, Google Drive, Simplenote) and social media (Facebook) for C2 and exfiltration to evade detection, and target Arabic-speaking government and political figures across the Palestinian Territories, UAE, Egypt and Turkey; the report includes technical analysis, persistence and execution details, observed IOCs and MITRE ATT&CK mappings.