logo

A Mole exposing itself to sunlight

ID: 42b8656e-8abf-527b-aaa1-3b31c62abfee

STIX ID: report--42b8656e-8abf-527b-aaa1-3b31c62abfee

Feed Name: Fox-IT blog

Threat Score
72/100

Date Published: 2017-04-14

Date Updated: 2026-04-27

...
...

Fox-IT observed an active ransomware campaign named "Mole" spread via a social-engineering exploit kit that lures users to install a malicious Office "plugin"; upon execution it terminates processes, removes Windows backups, encrypts files with a .MOLE extension (RSA-1024), and displays a ransom note. The report provides infection statistics (500+ infections, many unique IPs suggesting targeted organizations), multiple IoCs (two binary hashes, several download hostnames, and a C2 IP), and ransom contact addresses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.