Operation Molerats: Middle East Cyber Attacks Using Poison Ivy
ID: c87fd1de-542a-48ba-8ade-e8f743ea36e1
STIX ID: report--c87fd1de-542a-48ba-8ade-e8f743ea36e1
Threat Score
72/100
Uploaded: 2026-08-19
Published Date: 2020-12-22
Last Modified Date: 2020-12-22
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
FireEye analysis of "Operation Molerats" documents a targeted campaign leveraging Poison Ivy (PIVY) and other publicly available RATs against Middle Eastern (and some U.S.) targets using Arabic-themed decoys and spear-phishing; the report provides sample hashes, PIVY configurations and passwords, C2 domains and IPs, delivery methods (weaponized RARs and Dropbox links), forged Microsoft code-signing evidence, and a YARA rule to detect related signed binaries.
