logo

Molerats__2020__New_Cyber_Espionage_Campaigns_Targeting_Palestinians_-_Part_2_The_Discovery_of_the_New_Mysterious_Pierogi_Backdoor.pdf

ID: 3b8693b8-1881-4cfb-8bf1-7cd76acc0352

STIX ID: report--3b8693b8-1881-4cfb-8bf1-7cd76acc0352

Threat Score

75/100

Uploaded: 2026-08-19

Published Date: 2020-02-18

Last Modified Date: 2020-02-18

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Cybereason Nocturnus documents a targeted cyber-espionage campaign delivering a newly identified Delphi backdoor called "Pierogi" against Palestinian individuals and entities via spearphishing and weaponized documents; the report details the macro-based downloader, Pierogi capabilities (screenshots, file upload/download, command execution), persistence and anti-AV checks, C2 infrastructure with Ukrainian-language artifacts, IOCs (file hashes and domains), and links the operation to the MoleRATs activity profile.