Operation Molerats: Middle East Cyber Attacks Using Poison Ivy | FireEye Blog
ID: f0d174db-c0a9-4b8f-9682-904646f36c29
STIX ID: report--f0d174db-c0a9-4b8f-9682-904646f36c29
Threat Score
72/100
Uploaded: 2026-08-19
Published Date: 2014-01-15
Last Modified Date: 2014-01-15
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
FireEye details 'Operation Molerats', an active campaign using the Poison Ivy RAT against Middle Eastern and U.S. targets; the report includes sample hashes, PIVY config/passwords and key-files, C2 domains and IPs, delivery methods (spear-phishing with weaponized RARs/hosted links), Arabic decoy documents, and detection artifacts including a YARA signature to support detection and attribution.
