logo

Operation Molerats: Middle East Cyber Attacks Using Poison Ivy

ID: c87fd1de-542a-48ba-8ade-e8f743ea36e1

STIX ID: report--c87fd1de-542a-48ba-8ade-e8f743ea36e1

Threat Score

72/100

Uploaded: 2026-08-19

Published Date: 2020-12-22

Last Modified Date: 2020-12-22

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
FireEye analysis of "Operation Molerats" documents a targeted campaign leveraging Poison Ivy (PIVY) and other publicly available RATs against Middle Eastern (and some U.S.) targets using Arabic-themed decoys and spear-phishing; the report provides sample hashes, PIVY configurations and passwords, C2 domains and IPs, delivery methods (weaponized RARs and Dropbox links), forged Microsoft code-signing evidence, and a YARA rule to detect related signed binaries.