NimbleMamba

First seen
2022-03-01 00:00:00
Malware type
rat
Profile updated
2026-07-07 13:10:19

Targeted industries: government-and-public-sector

Targeted regions: country_code:ps country_code:eg

Context

NimbleMamba is a new implant used by TA402/Molerats group as replacement of LastConn. It uses guardrails to ensure that victims are within the TA's target region. It is written in C# and delivered as an obfuscated .NET executable. One seen obfuscator is SmartAssembly.

Reports & references

  • proofpoint.com — Ugg Boots 4 Sale Tale Palestinian Aligned Espionage (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Nimblemamba (report)
  • thehackernews.com — Palestinian Hackers Using New (report)

External references