Molatori
- Primary motivation
- financial-gain
- Sophistication
- intermediate
- Resource level
- team
- Actor type
- criminal
- Last IoC activity
- 2026-07-22 01:54:03
- Profile updated
- 2026-07-07 12:21:46
Targeted industries: financial-services government-and-public-sector
Context
Molatori is a threat actor group identified by Malwarebytes researchers, known for utilizing malicious ScreenConnect clients hosted on domains like atmolatori.icu and gomolatori.cyou. They employ phishing tactics, masquerading as communications from the Social Security Administration to lure targets into installing the client. Once installed, the ScreenConnect client allows the actors to remotely access the victim's computer, facilitating the exfiltration of sensitive information such as banking details and personal identification numbers. The primary objective of the Molatori group is financial fraud, leveraging the stolen data for identity theft and other malicious activities.
Reports & references
- malwarebytes.com — Fake Social Security Statement Emails Trick Users Into Installing Remote Tool (report)