NEW: Group Profiler — instant APT intel lookup. Try it →
Emblem illustrating the Molerats threat group

Molerats

G0021 Espionage MITRE ATT&CK →

Also known as: Operation Molerats · Gaza Cybergang

Overview

Molerats is an Arabic-speaking, politically-motivated threat group that has been operating since 2012. The group's victims have primarily been in the Middle East, Europe, and the United States.

Naming & attribution

Molerats is tracked under 3 names across the industry. It uses 16 documented ATT&CK techniques — more than 45% of the 174 groups tracked here. Activity attributed since 2012.

Who calls this group what — MITRE lists each alias with the report that used it, but not which vendor coined it.
NameFirst reported by
Operation MoleratsVilleneuve, N., Haq, H., Moran, N
Gaza CybergangClearSky
MoleratsClearSky

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • Confucius — 9 shared techniques (35% overlap)
  • Machete — 7 shared techniques (35% overlap)
  • LazyScripter — 9 shared techniques (33% overlap)
  • TA505 — 12 shared techniques (32% overlap)
  • Rancor — 6 shared techniques (32% overlap)
  • Windshift — 8 shared techniques (30% overlap)

Targets

Civil society · Defense · Education · Energy · Finance · Government · Healthcare · Legal · Media · Military · NGOs · Pharmaceuticals

Regions

Europe · Israel · Middle East · Palestine · United States

Capabilities

  • Custom malware/implant development — ATT&CK: 6 attributed custom malware families

TTPs — 16 techniques across 8 tactics

Initial Access

Execution

Persistence

Stealth

Defense Impairment

Credential Access

Discovery

Command and Control

Tools & malware (6)

MoleNet · Spark · DustySky · DropBook · SharpStage · PoisonIvy

Reporting (3)