Proofpoint reported that TA402/Molerats targeted government entities in the Middle East with a new malware family called LastConn, a .NET backdoor that appears to be an updated version of SharpStage. The malware shares several traits with earlier Molerats tooling, including Dropbox API-based command-and-control and checks associated with Arabic-language environments, reinforcing attribution to the long-running espionage group.
Independent reverse engineering showed the sample was heavily obfuscated with .NET Reactor, requiring analysts to recover encrypted strings manually after standard deobfuscation failed. Researchers extracted resource data, identified a 32-byte key-like array, reproduced the string decryption routine in Python, and recovered indicators from calls to the decryption function; the sample also contained a date-based execution check linked to an unregistered .NET Reactor trial message that prevented execution after 2021-06-30.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
One analyzed LastConn sample contained a date-based execution check that refused to continue after June 30, 2021. When run after that date, it threw an exception stating the assembly was protected by an unregistered version of .NET Reactor and would not work further.
Cybereason previously discovered the SharpStage backdoor, a .NET malware family that used the Dropbox API for exfiltration and checked for Arabic on infected machines. LastConn is described as an updated version of this backdoor.
Cybereason released an indicator-of-compromise dataset for Molerats activity covering malware families including SharpStage, DropBook, Spark Backdoor, Quasar RAT, MoleNet Downloader, and a new Pierogi variant, along with hashes, lure files, and attacker-linked infrastructure. The disclosure also listed domains, URLs, IP addresses, and cloud-hosted staging links used for payload delivery, command and control, or exfiltration.
A researcher published analysis of a LastConn sample obfuscated with .NET Reactor, documenting how de4dot failed, how encrypted strings were recovered from resources, and how the decryption logic was replicated in Python. The write-up also detailed indicators and similarities between LastConn and SharpStage.
Proofpoint discovered a recent MOLERATS/TA402 spear-phishing campaign targeting Middle Eastern government organizations and entities with diplomatic relationships in the region. The campaign aimed to exfiltrate sensitive information for intelligence gathering and used the LastConn malware payload.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cybereason.com
Open source0ffset.net
Open sourceproofpoint.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.