logo

Middle East users targeted by Molerats APT

ID: ddd60173-1123-56a9-a942-08a9a03bbd2b

STIX ID: report--ddd60173-1123-56a9-a942-08a9a03bbd2b

Feed Name: Zscaler Security Research Blog

Threat Score
85/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

ThreatLabz documents a targeted campaign active since July 2021 attributed to the Molerats APT: malicious Office macros download a .NET backdoor (ConfuserEx/Themida packed) that uses Dropbox API for C2 and data exfiltration. The report provides a full technical breakdown of the attack chain, network and infrastructure pivots (domains, IPs, SSL thumbprints), the attacker-controlled cloud accounts, MITRE ATT&CK mappings, and a long list of IOCs for detection and takedown.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.