NimbleMamba
- First seen
- 2022-03-01 00:00:00
- Malware type
- rat
- Profile updated
- 2026-07-07 13:10:19
Targeted industries: government-and-public-sector
Targeted regions: country_code:ps country_code:eg
Context
NimbleMamba is a new implant used by TA402/Molerats group as replacement of LastConn. It uses guardrails to ensure that victims are within the TA's target region. It is written in C# and delivered as an obfuscated .NET executable. One seen obfuscator is SmartAssembly.
Reports & references
- proofpoint.com — Ugg Boots 4 Sale Tale Palestinian Aligned Espionage (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Nimblemamba (report)
- thehackernews.com — Palestinian Hackers Using New (report)