Molerats
MITRE ATT&CK: G0021 View on attack.mitre.org
Aliases: Operation Molerats, Gaza Cybergang, Gaza Hackers Team, Gaza cybergang, Extreme Jackal, Moonlight, ALUMINUM SARATOGA, BLACKSTEM, Molerats
- First seen
- 2012-01-01 00:00:00
- Origin
- PS
- Primary motivation
- espionage
- Sophistication
- intermediate
- Resource level
- team
- Actor type
- Espionage
- Related IoCs
- 8 (4 malicious)
- Last IoC activity
- 2026-08-10 07:47:49
- Profile updated
- 2026-07-07 12:31:45
Targeted industries: government-and-public-sector media-and-entertainment technology-and-telecommunications
Targeted regions: country_code:ps country_code:il country_code:eg country_code:sa country_code:ae country_code:us country_code:gb
Context
Molerats is an Arabic-speaking, politically-motivated threat group that has been operating since 2012. The group's victims have primarily been in the Middle East, Europe, and the United States.
Recent IoC activity
4 malicious indicators in Maltiverse are attributed to Molerats (G0021). The 4 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | fulltest.yourtrap.com | 2026-06-12 | 1 |
| hostname | wiknet.wikaba.com | 2026-06-12 | 1 |
| hostname | wiknet.mooo.com | 2026-05-13 | 1 |
| file sample | c75c89e09f7f2dbf5db5174efc8710c806ef6376c6d22512b96c22a0f861735e.exe | 2025-09-24 | 1 |
Detection coverage
- 2 YARA rules
- 446 Sigma rules
Malware & tools used
- Msiexec (attack-pattern)
- Malicious Link (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Code Signing (attack-pattern)
- Compression (attack-pattern)
- Scheduled Task (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- Process Discovery (attack-pattern)
- Spearphishing Link (attack-pattern)
- Credentials from Web Browsers (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- PowerShell (attack-pattern)
- Visual Basic (attack-pattern)
- JavaScript (attack-pattern)
- Malicious File (attack-pattern)
- Spark (malware)
- SharpStage (malware)
- DropBook (malware)
- DustySky (malware)
- MoleNet (malware)
- PoisonIvy (malware)
Reports & references
- Mandiant — Operation Molerats Middle East Cyber Attacks Using Poison Ivy (report)
- ti.360.net — Suspected Molerats New Attack In The Middle East (report)
- ti.360.net — Suspected Molerats New Attack In The Middle East En (report)
- middle-east-online.com — Cyber War Gaza Hackers Deface Israel Fire Service Website (report)
- Mandiant — Molerats Here For Spring (report)
- pwc.blogs.com — Attacks Against Israeli Palestinian Interests (report)
- vectra.ai — Moonlight Middle East Targeted Attacks (report)
- Kaspersky — 72283 (report)
- clearskysec.com — Operation%20Dustysky Tlp White (report)
- clearskysec.com — Operation Dustysky2 6.2016 Tlp White (report)
- Kaspersky — 82765 (report)
- kaspersky.com — 26363 (report)
- MITRE ATT&CK — G0021 (report)
- secureworks.com — Aluminum Saratoga (report)
- services.google.com — Tool Of First Resort Israel Hamas War Cyber (report)
- clearskysec.com — Operation Dustysky2 6.2016 Tlp White (report)
- Kaspersky — 90068 (report)
- web.archive.org — Operation Molerats Middle East Cyber Attacks Using Poison Ivy (report)
- cybereason.com — Molerats In The Cloud New Malware Arsenal Abuses Cloud Platforms In Middle East Espionage Campaign (report)
Attributed from
- Molerats 2021 Backdoor Delivery Campaign (campaign)
External references
- mitre-attack — G0021
- Molerats
- Gaza Cybergang
- Operation Molerats
- DustySky2
- DustySky
- Cybereason Molerats Dec 2020
- Kaspersky MoleRATs April 2019
- FireEye Operation Molerats
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy