Molerats__2020__Molerats-in-the-Cloud-New-Malware-Arsenal-Abuses-Cloud-Platforms-in-Middle-East-Espionage-Campaign.pdf
ID: 01049b82-2f58-4132-81eb-61be20392f51
STIX ID: report--01049b82-2f58-4132-81eb-61be20392f51
Threat Score
85/100
Uploaded: 2026-08-19
Published Date: 2020-12-09
Last Modified Date: 2020-12-09
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
**Executive summary:** Cybereason Nocturnus details an active, targeted espionage campaign attributed to the Molerats (Gaza Cybergang) that uses newly discovered backdoors (SharpStage, DropBook), the MoleNet downloader and previously observed tools (Spark, Pierogi). The actors leverage social engineering themed to Middle Eastern politics to deliver payloads, use legitimate cloud services (Dropbox, Google Drive, Simplenote) and social media (Facebook) for C2 and exfiltration to evade detection, and target Arabic-speaking government and political figures across the Palestinian Territories, UAE, Egypt and Turkey; the report includes technical analysis, persistence and execution details, observed IOCs and MITRE ATT&CK mappings.
