Gaza Cybergang (Molerats) is an Arabic-speaking, politically motivated threat group assessed to be Hamas-affiliated, operating since 2012 against government, diplomatic, and political targets across the Palestinian Territories, Jordan, Israel, Lebanon, Egypt, and the wider Middle East.
Additional names this actor is known by across other vendors' naming schemes — cross-referenced from external crosswalk sources, not RaqibCTI's own curated aliases (shown at the top of this page). Each source is attributed to its own licence.
+7 more relationships — see the relationships browser.
Gaza Cybergang — also known as Molerats and the Gaza Hackers Team — has operated since around 2012 and is assessed by multiple vendors with medium-to-high confidence to be aligned with Palestinian interests and affiliated with Hamas. It functions as an umbrella of related clusters (including the WIRTE and Arid Viper sub-groups tracked separately), sharing lure themes and regional targeting.
Operationally the group relies on politically themed spearphishing — decoy documents referencing Middle Eastern political affairs, the Israeli-Palestinian conflict, and inter-factional tensions — to deliver custom backdoors such as the DustySky, Spark, Pierogi, and Micropsia malware families. Tradecraft is generally less sophisticated than that of top-tier state actors but is persistent, adaptive, and effective against under-defended government targets.
MENA is the group's exclusive theater. Victims cluster in the Palestinian Territories, Jordan, Israel, Lebanon, Egypt, and neighboring states, concentrated in government, diplomatic, political, and media entities. Collection supports the political and intelligence objectives of Palestinian factions.
The group has remained active and adapted throughout the post-2023 Israel-Hamas conflict. Its WIRTE sub-cluster expanded from espionage into disruptive wiper activity (SameCoin) against Israel, while the broader Molerats umbrella continued espionage against Middle Eastern governments — reporting notes MoleRATs persisting even after ceasefire periods. Collectively the group represents the most durable Palestinian-aligned cyber-espionage capability.
Curated links to related activity — not this actor's alias list. Claimed personas are marked unverified; overlap / subgroup edges describe a related but distinct cluster, never the same actor.