ThaiCERT    ETDA    MDES
Report
Search
Home > List all groups > List all tools > List all groups using tool MoleNet

Threat Group Cards: A Threat Actor Encyclopedia

Permanent link Tool: MoleNet

NamesMoleNet
CategoryMalware
TypeBackdoor, Downloader
Description(Cybereason) Perhaps one of the most intriguing tools discovered in this campaign is the MoleNet downloader. Even though the tool itself is previously undocumented, the Nocturnus Team found evidence that it has been in active development since at least 2019 with infrastructure operating as far back as 2017 while remaining under the radar. The MoleNet downloader is just one of the tools in Molerats’ arsenal, and was discovered in this campaign being delivered by the DropBook backdoor along with the SharpStage and Spark backdoors. It is also written in .NET, and heavily obfuscated.
Information<https://www.cybereason.com/hubfs/dam/collateral/reports/Molerats-in-the-Cloud-New-Malware-Arsenal-Abuses-Cloud-Platforms-in-Middle-East-Espionage-Campaign.pdf>
Malpedia<https://malpedia.caad.fkie.fraunhofer.de/details/win.molenet>

Last change to this tool card: 23 April 2021

Download this tool card in JSON format

Previous: ModPOS
Next: Molerat Loader

All groups using tool MoleNet

ChangedNameCountryObserved

APT groups

 Molerats, Extreme Jackal, Gaza Cybergang[Gaza]2012-Apr 2021 

1 group listed (1 APT, 0 other, 0 unknown)

Thailand Computer Emergency Response Team (ThaiCERT)
Electronic Transactions Development Agency

Follow us on

Facebook Twitter

Report incidents

Telephone +66 (0)2-123-1234
E-mail report@thaicert.or.th
PGP Download PGP key