InvisiMole__2020__ESET_InvisiMole.pdf
ID: 9903adc8-e564-48f8-ad28-ece3d8df5f10
STIX ID: report--9903adc8-e564-48f8-ad28-ece3d8df5f10
Threat Score
85/100
Uploaded: 2026-08-15
Published Date: 2020-06-15
Last Modified Date: 2020-06-15
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ESET's June 2020 technical report analyzes the InvisiMole espionage campaign (active since at least 2013) and its 2019–2020 toolset upgrades: two feature-rich backdoors (RC2CL/RC2FM), TCP and DNS (tunneling) downloaders, per-victim DPAPI encryption, living-off-the-land execution chains, kernel/driver and application exploits (BYOVD/BYOVS), and lateral movement using EternalBlue and BlueKeep; the investigation also uncovers operational cooperation with the Gamaredon group and provides extensive IoCs and MITRE ATT&CK mappings.
