Middle East users targeted by Molerats APT
ID: ddd60173-1123-56a9-a942-08a9a03bbd2b
STIX ID: report--ddd60173-1123-56a9-a942-08a9a03bbd2b
Feed Name: Zscaler Security Research Blog
ThreatLabz documents a targeted campaign active since July 2021 attributed to the Molerats APT: malicious Office macros download a .NET backdoor (ConfuserEx/Themida packed) that uses Dropbox API for C2 and data exfiltration. The report provides a full technical breakdown of the attack chain, network and infrastructure pivots (domains, IPs, SSL thumbprints), the attacker-controlled cloud accounts, MITRE ATT&CK mappings, and a long list of IOCs for detection and takedown.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
