InvisiMole

MITRE ATT&CK: S0260 View on attack.mitre.org

Aliases: InvisiMole

First seen
2013-01-01 00:00:00
Malware type
spyware, backdoor
Family
Malware family
Operating systems
windows
Related IoCs
66 (40 malicious)
Last IoC activity
2026-09-01 20:36:20
Profile updated
2026-07-07 12:49:56

Targeted industries: government-and-public-sector

Targeted regions: country_code:ua country_code:ru

Context

InvisiMole is a modular spyware program that has been used by the InvisiMole Group since at least 2013. InvisiMole has two backdoor modules called RC2FM and RC2CL that are used to perform post-exploitation activities. It has been discovered on compromised victims in the Ukraine and Russia. Gamaredon Group infrastructure has been used to download and execute InvisiMole against a small number of victims.

Recent IoC activity

40 malicious indicators in Maltiverse are attributed to InvisiMole (S0260). The 20 most recently updated:

TypeIndicatorUpdatedSources
hostname speed-stream.com 2026-09-03 2
hostname hansung-cc.co.kr 2026-09-03 1
hostname product2020.mrbasic.com 2026-09-03 2
hostname polyboatowners.com 2026-09-02 2
hostname www.fabianiarte.com 2026-09-02 2
hostname jikyung.co.kr 2026-09-02 2
hostname www.geeks-board.com 2026-09-02 2
hostname ktri.or.kr 2026-09-02 1
hostname www.paghera.com 2026-09-02 1
hostname au-pair.org 2026-09-02 2
hostname ns3145204.ip-51-68-119.eu 2026-09-02 1
file sample 43b6b0af744124da5147aba81a98bc7188718d5d205acf929affab016407d592 2026-08-14 2
hostname americanhotboats.com 2026-08-04 2
file sample file 2026-05-03 2
hostname consumerspanel.frge.io 2026-04-20 1
hostname panelunregistertle-348.frge.io 2026-04-20 1
file sample 8dd8b9bd94de1e72f0c400c5f32dcefc114cc0a5bf14b74ba6edc19fd4aeb2a5.zip 2026-04-17 2
file sample f7fa22f3710cd7906a268081b51e34784be3798ed94dcef9cd7562707c5db608.doc 2026-04-12 2
file sample 40fbac7a241bea412734134394ca81c0090698cf0689f2b67c54aa66b7e04670.doc 2026-04-11 2
file sample 28cd09ecad4149eec8665edf79c1c2036df67375f964e7e18a101ca88fe5f8e1 2026-04-05 2

Detection coverage

  • 9 YARA rules
  • 991 Sigma rules

Malware & tools used

  • Symmetric Cryptography (attack-pattern)
  • Disable or Modify System Firewall (attack-pattern)
  • Data from Removable Media (attack-pattern)
  • Rundll32 (attack-pattern)
  • Inhibit System Recovery (attack-pattern)
  • Portable Executable Injection (attack-pattern)
  • System Checks (attack-pattern)
  • Service Execution (attack-pattern)
  • File Deletion (attack-pattern)
  • Fallback Channels (attack-pattern)
  • Component Object Model (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Asynchronous Procedure Call (attack-pattern)
  • Non-Application Layer Protocol (attack-pattern)
  • Archive via Library (attack-pattern)
  • Archive via Utility (attack-pattern)
  • Screen Capture (attack-pattern)
  • Application Window Discovery (attack-pattern)
  • Keylogging (attack-pattern)
  • System Owner/User Discovery (attack-pattern)
  • Local Data Staging (attack-pattern)
  • Data from Local System (attack-pattern)
  • Hidden Files and Directories (attack-pattern)
  • Exploitation for Privilege Escalation (attack-pattern)
  • Non-Standard Encoding (attack-pattern)

Detection rules

  • ESET_Apt_Windows_Invisimole_Logs (yara-rule)
  • ESET_Apt_Windows_Invisimole_SFX_Dropper (yara-rule)
  • ESET_Apt_Windows_Invisimole_CPL_Loader (yara-rule)
  • ESET_Apt_Windows_Invisimole_Wrapper_DLL (yara-rule)
  • ESET_Apt_Windows_Invisimole_DNS_Downloader (yara-rule)
  • ESET_Apt_Windows_Invisimole_RC2CL_Backdoor (yara-rule)
  • ESET_Apt_Windows_Invisimole (yara-rule)
  • ESET_Apt_Windows_Invisimole_C2 (yara-rule)
  • MALPEDIA_Win_Invisimole_Auto (yara-rule)

Reports & references

  • ESET — Digging Up Invisimole Hidden Arsenal (report)
  • ESET — Invisimole Equipped Spyware Undercover (report)
  • ESET — Signed Kernel Drivers Unguarded Gateway Windows Core (report)
  • trustwave.com — Overview Of The Cyber Weapons Used In The Ukraine Russia War (report)
  • ESET — Eset Industry Report Government (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Invisimole (report)
  • ESET — Eset Invisimole (report)
  • cocomelonc.github.io — Malware Tricks 24 (report)
  • MITRE ATT&CK — S0260 (report)

External references