Molatori

Primary motivation
financial-gain
Sophistication
intermediate
Resource level
team
Actor type
criminal
Last IoC activity
2026-07-22 01:54:03
Profile updated
2026-07-07 12:21:46

Targeted industries: financial-services government-and-public-sector

Context

Molatori is a threat actor group identified by Malwarebytes researchers, known for utilizing malicious ScreenConnect clients hosted on domains like atmolatori.icu and gomolatori.cyou. They employ phishing tactics, masquerading as communications from the Social Security Administration to lure targets into installing the client. Once installed, the ScreenConnect client allows the actors to remotely access the victim's computer, facilitating the exfiltration of sensitive information such as banking details and personal identification numbers. The primary objective of the Molatori group is financial fraud, leveraging the stolen data for identity theft and other malicious activities.

Reports & references

  • malwarebytes.com — Fake Social Security Statement Emails Trick Users Into Installing Remote Tool (report)

External references