Recent reports reveal a sophisticated cyber campaign targeting Middle Eastern nations, leveraging advanced malware to infiltrate critical systems. The attackers used three new variants—SharpStage, DropBook, and MoleNet—to bypass defenses and steal sensitive data.
These tools enabled remote access, file manipulation, and even language-based targeting, suggesting a highly strategic approach. The malware often hid behind legitimate platforms like Dropbox and Facebook, making detection difficult.
Geopolitical tensions, particularly around Israel-Saudi relations, appear to be a key motivator. The attackers exploited political events as lures, increasing their success rate.
Key Takeaways
- New malware variants SharpStage, DropBook, and MoleNet were used in recent campaigns.
- Legitimate platforms like Dropbox and Facebook served as command centers.
- Geopolitical events were weaponized to deceive targets.
- Detection remains challenging due to low antivirus recognition.
- The attacks focused on Middle Eastern diplomatic developments.
Introduction to the Molerats Hacker Group
A shadowy collective has targeted Middle Eastern entities for over a decade, blending political motives with advanced tools. Initially identified as part of the Gaza Cybergang, they focus on diplomatic and governmental systems.
Who Are the Molerats?
Active since 2012, this group emerged as Gaza Cybergang Group 1, one of three subgroups. Their attacks often use Arabic-language phishing documents themed around regional politics. Targets include Palestinian officials and neighboring governments.
Attribution remains difficult. In 2019, Alien Labs contested Kaspersky’s findings, linking them to APT-C-37 instead. This confusion highlights their ability to evade scrutiny.
Why Are They a Persistent Threat?
Their adaptability sets them apart. They rotate malware variants and use HTTPS command servers to mask traffic. Geolocation filtering ensures only victims in specific regions receive payloads.
Detection rates are alarmingly low. For example, SharpStage malware scored just 1/70 on VirusTotal. Such stealth makes them a long-term security challenge.
Unpacking the Threat: Tactics and Evolution
A decade-long cyber campaign demonstrates increasing refinement in evasion and targeting methods. What began as basic remote access tools (RATs) like njRat has escalated into custom .NET malware, showcasing a clear trajectory toward sophistication.
Key Tactics and Techniques
Their tactics rely heavily on multi-stage infections. Autoit scripts, for instance, deploy payloads in phases to avoid suspicion. These techniques often mimic legitimate software updates, further complicating detection.
One notable shift is the weaponization of cloud services. Platforms like Dropbox and Egnyte serve as covert command centers. This move to cloud-based infrastructure reduces reliance on direct servers, making attribution harder.
Evolution of Attack Methods
Early attack methods involved simple phishing emails. Today, they use geo-targeted lures in Arabic, ensuring only specific victims trigger malware. *Phishing* documents often reference regional politics, increasing credibility.
- 2012–2018: Basic RATs with limited persistence.
- 2020: SharpStage variants abused Dropbox’s API.
- 2025: PowerShell scripts embed deeper into systems.
“The shift to legitimate platforms marks a paradigm shift in cyber espionage—blurring lines between malicious and normal traffic.”
Recent innovations focus on persistence. Malware now uses PowerShell to maintain access even after reboots. This *evasion* tactic ensures long-term infiltration, posing severe challenges for defenders.
Recent Attacks by Molerats in 2025
December 2025 marked a turning point in cyber espionage tactics against Middle Eastern entities. Attackers exploited diplomatic tensions, deploying malware disguised as peace-talk updates. Their campaign relied on socially engineered lure content, blending current events with malicious intent.

Campaigns Targeting the Middle East
A wave of phishing emails circulated, impersonating legitimate news outlets. One decoy, a fake “MBS-Israel” PDF, detailed supposed negotiations between Netanyahu and bin Salman. The attached archives, hosted on Dropbox and Google Drive, contained executables named after peace-talk agendas.
Key indicators of compromise (IOCs) included:
- Malware masquerading as election updates for Palestinian authorities.
- Fake Al-Ahram newspaper articles redirecting to credential-harvesting pages.
- Egnyte links delivering Spark malware, targeting Hamas-Fatah discussions.
Notable Phishing and Espionage Efforts
Attackers mirrored regional conflicts in their documents. For example, fabricated reports on Gaza reconstruction funds hid backdoor installers. Parallel campaigns like Pierogi used Egnyte to exfiltrate data, evading traditional security scans.
This multi-pronged approach demonstrates how geopolitical narratives are weaponized. By embedding malware in familiar platforms, attackers ensured higher success rates across the Middle East.
Malware Variants Used by Molerats
Three distinct malware variants have emerged as the backbone of recent cyber espionage efforts. Each tool serves specialized functions while sharing common evasion techniques. Together, they form a potent toolkit for persistent system infiltration.
SharpStage Backdoor: Capabilities and Impact
The modular .NET architecture of SharpStage allows attackers to customize its functions. It verifies the victim’s system language before activating, specifically checking for Arabic configurations. This targeted approach helps avoid detection in unintended regions.
Researchers found SharpStage using Dropbox’s API for command communication. The backdoor captures screens and transmits them via encrypted channels. Its low detection rate (1/70 on VirusTotal) makes it particularly dangerous for Middle Eastern targets.
DropBook Backdoor: Abuse of Legitimate Platforms
This variant stands out for its unconventional command system. Instead of traditional servers, DropBook reads instructions from Facebook posts and Simplenote entries. The malware requires WinRAR for payload extraction, blending with normal user activity.
Security teams noted its unique persistence method. DropBook creates hidden registry entries that survive system reboots. By leveraging social media platforms, it bypasses many network monitoring tools.
MoleNet Downloader: Persistence and Evasion
Operating since 2019, MoleNet specializes in long-term system access. It uses PowerShell scripts to maintain presence across reboots. The downloader first profiles the operating system before retrieving encrypted secondary payloads.
Advanced anti-analysis features include WMI checks for virtual machines. MoleNet also hides its windows and processes from standard task managers. These evasion techniques make it exceptionally difficult to detect and remove.
When comparing compilation timestamps, researchers found consistent development patterns. All three variants show ongoing refinement, suggesting active maintenance by their creators. This highlights the persistent threat posed by these tools.
Evasion Techniques and Detection Challenges
Advanced cyber threats now employ sophisticated evasion methods to bypass security measures. By exploiting language settings and legitimate platforms, attackers remain hidden while stealing data. These tactics create significant hurdles for traditional detection systems.

Language-Based Targeting: Arabic Checks
Malware often verifies system configurations before activating. For example, SharpStage uses Win32 API calls to check keyboard layouts. If the system language isn’t Arabic, the payload deactivates.
This targeted approach reduces exposure to analysis tools. Researchers found malware with 0/70 detection rates on VirusTotal, highlighting its stealth.
Abuse of Cloud Services and Social Media
Attackers increasingly hide commands in legal platforms. Dropbox tokens were stored in Facebook posts, while Simplenote hosted encrypted instructions. Traffic masked as cnet.com visits further confused defenders.
Multi-layer encryption (Base64 + custom algorithms) added complexity. Below is a breakdown of common evasion patterns:
| Technique | Example | Impact |
|---|---|---|
| WMI Queries | Detects antivirus products | Avoids sandbox analysis |
| Cloud C2 | Dropbox API calls | Blends with normal traffic |
| Social Media | Facebook post commands | Bypasses network filters |
These methods exploit trust in everyday tools. Security teams must adapt to spot anomalies in seemingly harmless activities.
Comparing Molerats to Other Threat Groups
Cyber espionage groups often share tactics, but their goals and targets vary widely. By examining their methods, we uncover critical distinctions that shape defense strategies.
Molerats vs. APT-C-37: Key Differences
APT-C-37 focuses on Western governments, while Molerats targets the Middle East. The former prefers disruptive actions like website defacements. The latter relies on stealth, avoiding attention.
In 2019, security reports disputed Molerats’ attribution. Some linked them to Gaza Cybergang, others to APT-C-37. This confusion highlights their ability to blur digital footprints.

Overlaps with Gaza Cybergang Subgroups
The Gaza Cybergang splits into three subgroups. Molerats (Group 1) specializes in diplomatic espionage. Desert Falcons (Group 2) and Parliament (Group 3) target broader geopolitical interests.
Notable overlaps include:
- Houdini RAT: Used by both Molerats and Parliament for remote access.
- Operation Parliament: High-profile attacks on Palestinian entities.
- Shared infrastructure: Some servers hosted malware for multiple subgroups.
Despite similarities, Molerats’ campaigns are more refined. Their malware avoids detection better than other groups in the network.
The Political Motivations Behind Molerats’ Attacks
Cyber campaigns often mirror real-world conflicts, and recent attacks show clear political motivations. By analyzing lure documents, we uncover how regional tensions fuel these operations. The Middle East and North Africa remain primary targets, with attackers exploiting sensitive diplomatic developments.
Geopolitical Themes in Lure Documents
Attackers craft content that aligns with current events. For example, fake PDFs about the Hamas-Fatah conflict contained malware. These documents referenced real meetings between Palestinian leaders, increasing their credibility.
Another campaign used the Soleimani assassination as bait. Fake vigilance alerts urged targets to open malicious attachments. This tactic shows how attackers weaponize breaking news for infiltration.
| Theme | Example | Impact |
|---|---|---|
| Election Fraud | Palestinian election updates | High open rates |
| Peace Talks | Israel-Palestine negotiations | Diplomatic targets |
| Regional Conflicts | Hamas-Egypt tensions | Military entities |
Targeting Palestinian and Middle Eastern Entities
The group focuses on Palestinian organizations and neighboring governments. Decoys about Ismail Haniyeh’s movements tricked officials into activating malware. These attacks often coincide with real political events.
VirusTotal data reveals patterns in targeting. Over 80% of submissions came from the Middle East and North Africa region. This precision suggests deep knowledge of local political landscapes.
Key findings include:
- Executables named after peace process milestones
- Fake Al-Ahram articles targeting Egyptian readers
- Malware disguised as Gaza reconstruction plans
Future Projections: Molerats’ Tactics in 2025 and Beyond
Security analysts warn of evolving cyber threats leveraging trusted platforms for malicious purposes. As defenders strengthen traditional protections, attackers adapt by weaponizing everyday digital services. This creates new challenges for detection systems worldwide.
Cloud Platforms as Command Centers
Microsoft 365 APIs may become prime targets for abuse. Recent Cybereason reports predict expanded misuse of legitimate cloud services. Attackers could transform these platforms into invisible command hubs for global operations.
We expect three key developments:
- API-based malware distribution through SharePoint and Teams
- Encrypted payloads hidden in OneNote files
- Automated credential harvesting via Azure functions
Next-Generation Malware Capabilities
The Enigma Packer shows how evasion techniques are advancing. Future variants might combine AI-generated lure documents with blockchain-based infrastructure. This could make campaigns harder to trace and disrupt.
Potential innovations include:
- RAT-as-a-Service models lowering entry barriers
- Cross-platform malware targeting Windows and Android simultaneously
- Self-modifying code that adapts to detection methods
“The line between legitimate and malicious cloud usage will blur as attackers innovate.”
These projections highlight the need for adaptive security strategies. As threats evolve, so must our approaches to identifying and neutralizing them.
Conclusion
Over the past decade, cyber threats have evolved significantly, shifting from basic tools to highly sophisticated malware. These tools now exploit trusted platforms, making detection more challenging than ever.
Language-aware systems are critical. Attackers often tailor their methods to specific regions, using local themes to bypass defenses. Monitoring cloud services for unusual activity is equally vital, as attackers increasingly abuse them for stealthy operations.
Geopolitical intelligence plays a key role in anticipating threats. Understanding regional tensions helps predict potential attacks. For example, the Spark backdoor demonstrates how persistent threats adapt over time.
To stay ahead, we must prioritize adaptive security measures. Combining threat intelligence with advanced monitoring can mitigate risks effectively.