InvisiMole
MITRE ATT&CK: S0260 View on attack.mitre.org
Aliases: InvisiMole
- First seen
- 2013-01-01 00:00:00
- Malware type
- spyware, backdoor
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 66 (40 malicious)
- Last IoC activity
- 2026-09-01 20:36:20
- Profile updated
- 2026-07-07 12:49:56
Targeted industries: government-and-public-sector
Targeted regions: country_code:ua country_code:ru
Context
InvisiMole is a modular spyware program that has been used by the InvisiMole Group since at least 2013. InvisiMole has two backdoor modules called RC2FM and RC2CL that are used to perform post-exploitation activities. It has been discovered on compromised victims in the Ukraine and Russia. Gamaredon Group infrastructure has been used to download and execute InvisiMole against a small number of victims.
Recent IoC activity
40 malicious indicators in Maltiverse are attributed to InvisiMole (S0260). The 20 most recently updated:
Detection coverage
- 9 YARA rules
- 991 Sigma rules
Malware & tools used
- Symmetric Cryptography (attack-pattern)
- Disable or Modify System Firewall (attack-pattern)
- Data from Removable Media (attack-pattern)
- Rundll32 (attack-pattern)
- Inhibit System Recovery (attack-pattern)
- Portable Executable Injection (attack-pattern)
- System Checks (attack-pattern)
- Service Execution (attack-pattern)
- File Deletion (attack-pattern)
- Fallback Channels (attack-pattern)
- Component Object Model (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Asynchronous Procedure Call (attack-pattern)
- Non-Application Layer Protocol (attack-pattern)
- Archive via Library (attack-pattern)
- Archive via Utility (attack-pattern)
- Screen Capture (attack-pattern)
- Application Window Discovery (attack-pattern)
- Keylogging (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- Local Data Staging (attack-pattern)
- Data from Local System (attack-pattern)
- Hidden Files and Directories (attack-pattern)
- Exploitation for Privilege Escalation (attack-pattern)
- Non-Standard Encoding (attack-pattern)
Detection rules
- ESET_Apt_Windows_Invisimole_Logs (yara-rule)
- ESET_Apt_Windows_Invisimole_SFX_Dropper (yara-rule)
- ESET_Apt_Windows_Invisimole_CPL_Loader (yara-rule)
- ESET_Apt_Windows_Invisimole_Wrapper_DLL (yara-rule)
- ESET_Apt_Windows_Invisimole_DNS_Downloader (yara-rule)
- ESET_Apt_Windows_Invisimole_RC2CL_Backdoor (yara-rule)
- ESET_Apt_Windows_Invisimole (yara-rule)
- ESET_Apt_Windows_Invisimole_C2 (yara-rule)
- MALPEDIA_Win_Invisimole_Auto (yara-rule)
Reports & references
- ESET — Digging Up Invisimole Hidden Arsenal (report)
- ESET — Invisimole Equipped Spyware Undercover (report)
- ESET — Signed Kernel Drivers Unguarded Gateway Windows Core (report)
- trustwave.com — Overview Of The Cyber Weapons Used In The Ukraine Russia War (report)
- ESET — Eset Industry Report Government (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Invisimole (report)
- ESET — Eset Invisimole (report)
- cocomelonc.github.io — Malware Tricks 24 (report)
- MITRE ATT&CK — S0260 (report)