logo

Operation Molerats: Middle East Cyber Attacks Using Poison Ivy | FireEye Blog

ID: f0d174db-c0a9-4b8f-9682-904646f36c29

STIX ID: report--f0d174db-c0a9-4b8f-9682-904646f36c29

Threat Score

72/100

Uploaded: 2026-08-19

Published Date: 2014-01-15

Last Modified Date: 2014-01-15

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
FireEye details 'Operation Molerats', an active campaign using the Poison Ivy RAT against Middle Eastern and U.S. targets; the report includes sample hashes, PIVY config/passwords and key-files, C2 domains and IPs, delivery methods (spear-phishing with weaponized RARs/hosted links), Arabic decoy documents, and detection artifacts including a YARA signature to support detection and attribution.