logo

InvisiMole__2020__ESET_InvisiMole.pdf

ID: 9903adc8-e564-48f8-ad28-ece3d8df5f10

STIX ID: report--9903adc8-e564-48f8-ad28-ece3d8df5f10

Threat Score

85/100

Uploaded: 2026-08-15

Published Date: 2020-06-15

Last Modified Date: 2020-06-15

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ESET's June 2020 technical report analyzes the InvisiMole espionage campaign (active since at least 2013) and its 2019–2020 toolset upgrades: two feature-rich backdoors (RC2CL/RC2FM), TCP and DNS (tunneling) downloaders, per-victim DPAPI encryption, living-off-the-land execution chains, kernel/driver and application exploits (BYOVD/BYOVS), and lateral movement using EternalBlue and BlueKeep; the investigation also uncovers operational cooperation with the Gamaredon group and provides extensive IoCs and MITRE ATT&CK mappings.