Gaza Cybergang (Molerats) is an Arabic-speaking, politically motivated threat group assessed to be Hamas-affiliated, operating since 2012 against government, diplomatic, and political targets across the Palestinian Territories, Jordan, Israel, Lebanon, Egypt, and the wider Middle East.
Gaza Cybergang — also known as Molerats and the Gaza Hackers Team — has operated since around 2012 and is assessed by multiple vendors with medium-to-high confidence to be aligned with Palestinian interests and affiliated with Hamas. It functions as an umbrella of related clusters (including the WIRTE and Arid Viper sub-groups tracked separately), sharing lure themes and regional targeting.
Operationally the group relies on politically themed spearphishing — decoy documents referencing Middle Eastern political affairs, the Israeli-Palestinian conflict, and inter-factional tensions — to deliver custom backdoors such as the DustySky, Spark, Pierogi, and Micropsia malware families. Tradecraft is generally less sophisticated than that of top-tier state actors but is persistent, adaptive, and effective against under-defended government targets.
MENA is the group's exclusive theater. Victims cluster in the Palestinian Territories, Jordan, Israel, Lebanon, Egypt, and neighboring states, concentrated in government, diplomatic, political, and media entities. Collection supports the political and intelligence objectives of Palestinian factions.
The group has remained active and adapted throughout the post-2023 Israel-Hamas conflict. Its WIRTE sub-cluster expanded from espionage into disruptive wiper activity (SameCoin) against Israel, while the broader Molerats umbrella continued espionage against Middle Eastern governments — reporting notes MoleRATs persisting even after ceasefire periods. Collectively the group represents the most durable Palestinian-aligned cyber-espionage capability.
| Technique | Name | Tactic | Observed use |
|---|---|---|---|
| T1105 ↗ | Ingress Tool Transfer | command and control | used executables to download malicious files from different sources |
| T1555.003 ↗ | Credentials from Password Stores: Credentials from Web Browsers | credential access | used the public tool BrowserPasswordDump10 to dump passwords saved in browsers on victims |
| T1218.007 ↗ | System Binary Proxy Execution: Msiexec | defense evasion | used msiexec.exe to execute an MSI payload |
| T1140 ↗ | Deobfuscate/Decode Files or Information | defense evasion | decompresses ZIP files once on the victim machine |
| T1027.015 ↗ | Obfuscated Files or Information: Compression | defense evasion | delivered compressed executables within ZIP files to victims |
| T1553.002 ↗ | Subvert Trust Controls: Code Signing | defense evasion | used forged Microsoft code-signing certificates on malware |
| T1057 ↗ | Process Discovery | discovery | obtained a list of active processes on the victim and sent them to C2 servers |
| T1059.007 ↗ | Command and Scripting Interpreter: JavaScript | execution | used various implants, including those built with JS, on target machines |
| T1059.001 ↗ | Command and Scripting Interpreter: PowerShell | execution | used PowerShell implants on target machines |
| T1204.001 ↗ | User Execution: Malicious Link | execution | sent malicious links via email trick users into opening a RAR archive and running an executable |
| T1059.005 ↗ | Command and Scripting Interpreter: Visual Basic | execution | used various implants, including those built with VBScript, on target machines |
| T1053.005 ↗ | Scheduled Task/Job: Scheduled Task | execution | created scheduled tasks to persistently run VBScripts |
| T1204.002 ↗ | User Execution: Malicious File | execution | sent malicious files via email that tricked users into clicking Enable Content to run an embedded macro |
| T1566.002 ↗ | Phishing: Spearphishing Link | initial access | sent phishing emails with malicious links included |
| T1566.001 ↗ | Phishing: Spearphishing Attachment | initial access | sent phishing emails with malicious Microsoft Word and PDF attachments |
| T1547.001 ↗ | Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder | persistence | saved malicious files within the AppData and Startup folders to maintain persistence |