Spark is a Windows backdoor associated with the MoleRATs threat actor, also known as the Gaza Cybergang, and has been used in politically motivated cyber-espionage operations targeting Palestinian individuals and entities in the Middle East. Activity involving Spark has been linked to social-engineering campaigns built around regional political themes, with victims lured into opening malware disguised as documents and delivered through cloud-hosted archives and similar staging mechanisms. The malware has also appeared alongside other tooling used by the same actor set, including SharpStage, DropBook, Pierogi, Quasar RAT, and related loaders or downloaders.
Spark provides core espionage functionality including system reconnaissance, user discovery, remote command execution, payload download, keylogging, audio recording, and data exfiltration over its command-and-control channel. Observed behavior includes collecting host information, running commands such as whoami to identify the current user, and transmitting stolen data back to operator-controlled infrastructure over HTTP. Its communications have been observed to use layered obfuscation, including Base64 encoding and additional encryption, and some samples used custom XOR-based decryption routines for payload handling.
The malware incorporates multiple evasion and targeting checks. It has been observed querying security products through WMI, using packing to hinder analysis, and validating that the infected system uses Arabic language or keyboard settings before proceeding with malicious activity. This geofencing behavior aligns with its victimology and suggests deliberate restriction to Arabic-speaking targets. Persistence has been established through mechanisms such as scheduled tasks and Startup-folder execution.
Spark is best characterized as a custom espionage backdoor used in targeted intrusions against political, governmental, and related targets in the Palestinian territories and broader Middle East.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Spark Backdoor: Hashes (SHA-256 + SHA-1) ... Domains Brooksprofessional[.]com IPs 168.119.82.89 93.115.10.142
"The payload in a majority of these attacks was a backdoor called Spark, which is a backdoor that allows the threat actors to open applications and run command line commands on the compromised system."
29 distinct techniques documented for this family, organized by ATT&CK tactic.
This latest campaign leverages phishing documents that include various themes related to current Middle Eastern events... Themes used to lure the victims included the Israeli-Saudi relations, Hamas elections, Palestinian politicians as well as other regional events
the Autoit code also creates the following scheduled task for persistence: SCHTASKS /Create /f /SC minute /TN runawy /mo 5 /tr C:\Users\<USER>\runawy.exe
The extracted executable file contains a compiled Autoit script, which can be seen in the RT_RCDATA section of the file.
the Autoit code also creates the following scheduled task for persistence: SCHTASKS /Create /f /SC minute /TN runawy /mo 5 /tr C:\Users\<USER>\runawy.exe
the Autoit code also creates the following scheduled task for persistence: SCHTASKS /Create /f /SC minute /TN runawy /mo 5 /tr C:\Users\<USER>\runawy.exe
They pack the malware with a powerful commercial tool called Enigma Packer ... All the payloads observed by Cybereason in this campaign were packed by ... Enigma Packer.
The executable has a Microsoft Word icon to trick victims into believing they are opening a Word document.
The content is a long ATT&CK-style listing of malware and threat groups that 'decrypt', 'decode', 'deobfuscate', 'unpack', or 'decompress' payloads, strings, configuration data, shellcode, and files prior to execution or use.
The content repeatedly describes malware and threat actors collecting the victim username, identifying logged-in users, running whoami, query user, quser, or similar commands to determine the current user or user sessions.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
If Arabic keyboard and language settings are not found on the machine, the backdoor will not carry out its malicious activity ... It can thwart detection by automated analysis engines and sandbox solutions.
One common evasive mechanism used by the Spark backdoor is its ability to check for installed security products using WMI queries (WQL). SELECT * FROM AntiVirusProduct SELECT * FROM FirewallProduct
Examples include 'Bazar can also check if the Russian language is installed,' 'DropBook has checked for the presence of Arabic language,' 'Maze has checked the language of the infected system,' and 'SynAck ... checks installed keyboard layouts to estimate if it has been launched from a certain list of countries.'
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
The Spark backdoor allows the attackers to ... Download additional payloads.
118 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
27 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A backdoor/implant used by Gaza Cybergang to maintain persistence on compromised systems for espionage.
Backdoor used in a related campaign targeting Palestinians via social engineering.
A backdoor previously attributed to Molerats and used in conjunction with the newly discovered malware in targeted attacks against Palestinian officials.
Backdoor malware tied to the Molerats APT indicators and associated C2 domain/IP infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.