logo

Molerats__2022__Zscaler_Molerats-APT-targeting-Middle-East_01-20-2022.pdf

ID: a908910b-ab2e-40c4-beba-950fbdad050c

STIX ID: report--a908910b-ab2e-40c4-beba-950fbdad050c

Threat Score

88/100

Uploaded: 2026-08-19

Published Date: 2022-02-21

Last Modified Date: 2022-02-21

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Zscaler ThreatLabz describes a targeted espionage campaign by the Molerats APT (July–Dec 2021) using macro-laden Office documents and PowerShell to drop a ConfuserEx/Themida-protected .NET backdoor that communicates with attacker-controlled Dropbox accounts for C2 and file exfiltration; the report includes static/dynamic analysis, C2/TTP mapping, extensive IOCs (hashes, IPs, domains, cloud accounts) and observed victim profiles in the Middle East.