Molerats__2022__Zscaler_Molerats-APT-targeting-Middle-East_01-20-2022.pdf
ID: a908910b-ab2e-40c4-beba-950fbdad050c
STIX ID: report--a908910b-ab2e-40c4-beba-950fbdad050c
Threat Score
88/100
Uploaded: 2026-08-19
Published Date: 2022-02-21
Last Modified Date: 2022-02-21
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Zscaler ThreatLabz describes a targeted espionage campaign by the Molerats APT (July–Dec 2021) using macro-laden Office documents and PowerShell to drop a ConfuserEx/Themida-protected .NET backdoor that communicates with attacker-controlled Dropbox accounts for C2 and file exfiltration; the report includes static/dynamic analysis, C2/TTP mapping, extensive IOCs (hashes, IPs, domains, cloud accounts) and observed victim profiles in the Middle East.
