Molerats
Molerats, also referred to in the content as Gaza Cybergang, WIRTE, TA402, Operation Molerats, and Ashen Lepus, is a suspected Hamas-aligned threat cluster active since at least 2012. The group is assessed as primarily focused on intelligence collection and espionage. Reported targeting is concentrated across the Middle East, especially Palestinian entities and Israel, with additional less-observed activity in the EU and US. Targeted sectors mentioned in the content include government, defense, energy, financial, media, technology, telecommunication, and civil society. The content describes Molerats/Gaza Cybergang as favoring spearphishing and other social engineering for initial access. Observed delivery methods include phishing emails with malicious Microsoft Word and PDF attachments, malicious links, archives, and files that trick users into enabling document macros or clicking Enable Content. WIRTE is specifically described as using look-alike domains and graphics of trusted security solution providers to entice victims to click phishing links, and as using UDL-file-based spearphishing attachments. Techniques and behaviors directly mentioned include PowerShell execution, malicious file execution, ZIP decompression on victim machines, HTTP network communication, and Base64 decoding of malicious VBS scripts. The content also states that Molerats has used shared modules execution. For persistence and follow-on access, the broader Gaza Cybergang reporting in the content notes use of implants and malware families including Molerat Loader, XtremeRAT, SharpStage, DropBook, Spark, Pierogi, Pierogi++, PoisonIvy, DustySky, MoleNet, and BarbWire. The content further describes Gaza Cybergang as a cluster with adjacent sub-groups, including Group 1 Molerats, Group 2 Arid Viper/Desert Falcons/APT-C-23, and Group 3 associated with Operation Parliament. SentinelLABS is cited as assessing likely consolidation among these sub-groups based on shared victims, TTPs, malware evolution, and overlapping infrastructure. The content also notes likely relations among TA402, WIRTE, and Gaza Cybergang based on shared malware staging behavior and command-and-control traits. Additional directly mentioned activity includes use of the public tool BrowserPasswordDump10 to dump browser-saved passwords, and use of DustySky, a multi-stage malware described as being used by Molerats for intelligence gathering.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Software & Services
Tradecraft
47 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
34 malware families attributed to this actor across reporting.
29 additional families tracked in Mallory.
Associated vulnerabilities
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
Observables
544 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as a threat actor associated with PowerShell execution behavior relevant to this detection.
Listed as a threat actor associated with the PowerShell P/Invoke process injection API chain detection and related ATT&CK techniques.
Listed as a threat actor associated with PowerShell execution behavior relevant to this detection analytic.
Listed as a threat actor associated with Windows Command Shell execution behavior relevant to this detection.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.