NEW: Group Profiler — instant APT intel lookup. Try it →

Molerats

G0021 Espionage MITRE ATT&CK →

Also known as: Operation Molerats · Gaza Cybergang

Overview

Molerats is an Arabic-speaking, politically-motivated threat group that has been operating since 2012. The group's victims have primarily been in the Middle East, Europe, and the United States.

Naming & attribution

Molerats is tracked under 3 names across the industry. It uses 16 documented ATT&CK techniques — more than 45% of the 174 groups tracked here. Activity attributed since 2012.

Who calls this group what — MITRE lists each alias with the report that used it, but not which vendor coined it.
NameFirst reported by
Operation MoleratsVilleneuve, N., Haq, H., Moran, N
Gaza CybergangClearSky
MoleratsClearSky

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • Confucius — 9 shared techniques (35% overlap)
  • Machete — 7 shared techniques (35% overlap)
  • LazyScripter — 9 shared techniques (33% overlap)
  • TA505 — 12 shared techniques (32% overlap)
  • Rancor — 6 shared techniques (32% overlap)
  • Windshift — 8 shared techniques (30% overlap)

Malware families with current indicators

One family attributed to Molerats, carrying 1 indicators currently tracked from abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL. MITRE documents what a group does; this is what its tooling is doing now.

  • Spark 1 indicators

Browse or copy the indicators by hash, domain, IP or URL, filtered by age from 1 day to 3 years.

Targets

Civil society · Defense · Education · Energy · Finance · Government · Healthcare · Legal · Media · Military · NGOs · Pharmaceuticals

Regions

Europe · Israel · Middle East · Palestine · United States

Capabilities

  • Custom malware/implant development — ATT&CK: 6 attributed custom malware families

TTPs — 16 techniques across 8 tactics

Initial Access

Execution

Persistence

Stealth

Defense Impairment

Credential Access

Discovery

Command and Control

Tools & malware (6)

MoleNet · Spark · DustySky · DropBook · SharpStage · PoisonIvy

Reporting (3)