◇ SIGN IN
← all actors
apt

Gaza Cybergang / Molerats

activehigh confidence
APT / State-sponsored
MoleratsGaza Hackers TeamOperation MoleratsExtreme JackalMoonlight
Attribution
Palestinian — assessed Hamas-affiliated
Origin
Palestinian Territories
First seen
2012
Last active
2025
Motivation
Espionage
Confidence
high
MENA targeting
Palestinian Territories, Jordan, Israel, Lebanon, Egypt
Sectors
Diplomatic, government, NGOs, media, banking, healthcare
MITRE ATT&CK
Why it mattersState-sponsored / APT actor, high confidence, documented targeting Palestinian Territories, Jordan, Israel (Diplomatic, government, NGOs sectors).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.

Gaza Cybergang (Molerats) is an Arabic-speaking, politically motivated threat group assessed to be Hamas-affiliated, operating since 2012 against government, diplomatic, and political targets across the Palestinian Territories, Jordan, Israel, Lebanon, Egypt, and the wider Middle East.

History

Gaza Cybergang — also known as Molerats and the Gaza Hackers Team — has operated since around 2012 and is assessed by multiple vendors with medium-to-high confidence to be aligned with Palestinian interests and affiliated with Hamas. It functions as an umbrella of related clusters (including the WIRTE and Arid Viper sub-groups tracked separately), sharing lure themes and regional targeting.

Operationally the group relies on politically themed spearphishing — decoy documents referencing Middle Eastern political affairs, the Israeli-Palestinian conflict, and inter-factional tensions — to deliver custom backdoors such as the DustySky, Spark, Pierogi, and Micropsia malware families. Tradecraft is generally less sophisticated than that of top-tier state actors but is persistent, adaptive, and effective against under-defended government targets.

MENA is the group's exclusive theater. Victims cluster in the Palestinian Territories, Jordan, Israel, Lebanon, Egypt, and neighboring states, concentrated in government, diplomatic, political, and media entities. Collection supports the political and intelligence objectives of Palestinian factions.

The group has remained active and adapted throughout the post-2023 Israel-Hamas conflict. Its WIRTE sub-cluster expanded from espionage into disruptive wiper activity (SameCoin) against Israel, while the broader Molerats umbrella continued espionage against Middle Eastern governments — reporting notes MoleRATs persisting even after ceasefire periods. Collectively the group represents the most durable Palestinian-aligned cyber-espionage capability.

Notable campaigns

2016
DustySky / Operation Molerats
Long-running espionage against Israeli and Middle Eastern government and diplomatic targets using the DustySky backdoor.
2020
Spark / Pierogi campaigns
Cybereason-documented espionage against Palestinian and regional targets with novel backdoors.
2024
Post-conflict government espionage
Continued targeting of Middle Eastern governments through the Israel-Hamas war, with sub-clusters adding disruptive tooling.

Observed ATT&CK techniques · 16

TechniqueNameTacticObserved use
T1105Ingress Tool Transfercommand and controlused executables to download malicious files from different sources
T1555.003Credentials from Password Stores: Credentials from Web Browserscredential accessused the public tool BrowserPasswordDump10 to dump passwords saved in browsers on victims
T1218.007System Binary Proxy Execution: Msiexecdefense evasionused msiexec.exe to execute an MSI payload
T1140Deobfuscate/Decode Files or Informationdefense evasiondecompresses ZIP files once on the victim machine
T1027.015Obfuscated Files or Information: Compressiondefense evasiondelivered compressed executables within ZIP files to victims
T1553.002Subvert Trust Controls: Code Signingdefense evasionused forged Microsoft code-signing certificates on malware
T1057Process Discoverydiscoveryobtained a list of active processes on the victim and sent them to C2 servers
T1059.007Command and Scripting Interpreter: JavaScriptexecutionused various implants, including those built with JS, on target machines
T1059.001Command and Scripting Interpreter: PowerShellexecutionused PowerShell implants on target machines
T1204.001User Execution: Malicious Linkexecutionsent malicious links via email trick users into opening a RAR archive and running an executable
T1059.005Command and Scripting Interpreter: Visual Basicexecutionused various implants, including those built with VBScript, on target machines
T1053.005Scheduled Task/Job: Scheduled Taskexecutioncreated scheduled tasks to persistently run VBScripts
T1204.002User Execution: Malicious Fileexecutionsent malicious files via email that tricked users into clicking Enable Content to run an embedded macro
T1566.002Phishing: Spearphishing Linkinitial accesssent phishing emails with malicious links included
T1566.001Phishing: Spearphishing Attachmentinitial accesssent phishing emails with malicious Microsoft Word and PDF attachments
T1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folderpersistencesaved malicious files within the AppData and Startup folders to maintain persistence