Molerats

MITRE ATT&CK: G0021 View on attack.mitre.org

Aliases: Operation Molerats, Gaza Cybergang, Gaza Hackers Team, Gaza cybergang, Extreme Jackal, Moonlight, ALUMINUM SARATOGA, BLACKSTEM, Molerats

First seen
2012-01-01 00:00:00
Origin
PS
Primary motivation
espionage
Sophistication
intermediate
Resource level
team
Actor type
Espionage
Related IoCs
8 (4 malicious)
Last IoC activity
2026-08-10 07:47:49
Profile updated
2026-07-07 12:31:45

Targeted industries: government-and-public-sector media-and-entertainment technology-and-telecommunications

Targeted regions: country_code:ps country_code:il country_code:eg country_code:sa country_code:ae country_code:us country_code:gb

Context

Molerats is an Arabic-speaking, politically-motivated threat group that has been operating since 2012. The group's victims have primarily been in the Middle East, Europe, and the United States.

Recent IoC activity

4 malicious indicators in Maltiverse are attributed to Molerats (G0021). The 4 most recently updated:

TypeIndicatorUpdatedSources
hostname fulltest.yourtrap.com 2026-06-12 1
hostname wiknet.wikaba.com 2026-06-12 1
hostname wiknet.mooo.com 2026-05-13 1
file sample c75c89e09f7f2dbf5db5174efc8710c806ef6376c6d22512b96c22a0f861735e.exe 2025-09-24 1

Detection coverage

  • 2 YARA rules
  • 446 Sigma rules

Malware & tools used

  • Msiexec (attack-pattern)
  • Malicious Link (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Code Signing (attack-pattern)
  • Compression (attack-pattern)
  • Scheduled Task (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Process Discovery (attack-pattern)
  • Spearphishing Link (attack-pattern)
  • Credentials from Web Browsers (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • PowerShell (attack-pattern)
  • Visual Basic (attack-pattern)
  • JavaScript (attack-pattern)
  • Malicious File (attack-pattern)
  • Spark (malware)
  • SharpStage (malware)
  • DropBook (malware)
  • DustySky (malware)
  • MoleNet (malware)
  • PoisonIvy (malware)

Reports & references

  • Mandiant — Operation Molerats Middle East Cyber Attacks Using Poison Ivy (report)
  • ti.360.net — Suspected Molerats New Attack In The Middle East (report)
  • ti.360.net — Suspected Molerats New Attack In The Middle East En (report)
  • middle-east-online.com — Cyber War Gaza Hackers Deface Israel Fire Service Website (report)
  • Mandiant — Molerats Here For Spring (report)
  • pwc.blogs.com — Attacks Against Israeli Palestinian Interests (report)
  • vectra.ai — Moonlight Middle East Targeted Attacks (report)
  • Kaspersky — 72283 (report)
  • clearskysec.com — Operation%20Dustysky Tlp White (report)
  • clearskysec.com — Operation Dustysky2 6.2016 Tlp White (report)
  • Kaspersky — 82765 (report)
  • kaspersky.com — 26363 (report)
  • MITRE ATT&CK — G0021 (report)
  • secureworks.com — Aluminum Saratoga (report)
  • services.google.com — Tool Of First Resort Israel Hamas War Cyber (report)
  • clearskysec.com — Operation Dustysky2 6.2016 Tlp White (report)
  • Kaspersky — 90068 (report)
  • web.archive.org — Operation Molerats Middle East Cyber Attacks Using Poison Ivy (report)
  • cybereason.com — Molerats In The Cloud New Malware Arsenal Abuses Cloud Platforms In Middle East Espionage Campaign (report)

Attributed from

  • Molerats 2021 Backdoor Delivery Campaign (campaign)

External references