Palestinian-aligned threat group TA402 (also tracked as Molerats) ran a spear-phishing campaign against Middle Eastern governments, foreign policy think tanks, and a state-affiliated airline, delivering a newly identified C# implant called NimbleMamba. Researchers said the malware appears designed to replace the group’s older LastConn backdoor and was used alongside a secondary trojan, BrittleBush, in parts of the operation. The activity was tied to late-2021 and early-2022 intelligence collection efforts focused on carefully selected regional targets.
The attackers used evolving delivery chains to limit exposure and evade detection, including geofenced links, actor-controlled domains, Dropbox-hosted payloads, and WordPress-based redirects to legitimate Arabic news sites before serving malicious RAR archives. NimbleMamba reportedly includes regional guardrails, anti-analysis checks, and configuration hosted on JustPasteIt, while using the Dropbox API for command-and-control and data exfiltration. Proofpoint linked the campaign to TA402 through technical overlaps, victim targeting, lure themes, and infrastructure connections between LastConn and NimbleMamba.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
Proofpoint published research attributing the late-2021 to early-2022 espionage campaign to TA402/Molerats and detailing the new NimbleMamba implant as a likely replacement for LastConn.
In December 2021 and January 2022, TA402 incorporated actor-controlled WordPress redirect sites such as emaratalyoumcom[.]wordpress[.]com into its infection chain. These sites impersonated Arabic-language news content and likely redirected in-region victims to NimbleMamba downloads.
In December 2021, TA402 changed its delivery chain to use Dropbox URLs to distribute malicious RAR files containing NimbleMamba. Proofpoint also found the actor was abusing Dropbox for command-and-control.
In November 2021, TA402 used an actor-controlled Gmail account and the domain uggboots4sale[.]com while masquerading as Quora. The geofenced delivery URL served a malicious RAR file to selected-country targets and redirected others to emaratalyoum[.]com.
Proofpoint stated that pivoting on the JustPasteIt user “Nefaty Benet” suggested the NimbleMamba campaign likely began in August 2021.
Proofpoint had previously reported an attack involving deployment of the LastConn backdoor, which it later assessed NimbleMamba was likely intended to replace.
Proofpoint said LastConn was likely an updated version of the SharpStage backdoor, which Cybereason had reported being used by the same threat actor in campaigns in December 2020.
After Proofpoint shared its findings, Dropbox took action to neutralize the malicious activity associated with the TA402 campaign.
Across late 2021 to early 2022, Proofpoint observed TA402 spear-phishing campaigns targeting Middle Eastern governments, foreign policy think tanks, and a state-affiliated airline. The campaigns delivered the new NimbleMamba implant and often the BrittleBush trojan.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.