[Molerats](https://attack.mitre.org/groups/G0021) used executables to download malicious files from different sources.(Citation: Kaspersky MoleRATs April 2019)(Citation: Unit42 Molerat Mar 2020)
[Molerats](https://attack.mitre.org/groups/G0021) used the public tool BrowserPasswordDump10 to dump passwords saved in browsers on victims.(Citation: DustySky)
[Molerats](https://attack.mitre.org/groups/G0021) has used forged Microsoft code-signing certificates on malware.(Citation: FireEye Operation Molerats)
[Molerats](https://attack.mitre.org/groups/G0021) actors obtained a list of active processes on the victim and sent them to C2 servers.(Citation: DustySky)
[Molerats](https://attack.mitre.org/groups/G0021) has sent malicious links via email trick users into opening a RAR archive and running an executable.(Citation: Kaspersky MoleRATs April 2019)(Citation: Unit42 Molerat Mar 2020)
Curated links to related activity — not this actor's alias list. Claimed personas are marked unverified; overlap / subgroup edges describe a related but distinct cluster, never the same actor.
Vendor tracking name
TA402high confidencesource ↗TA402 is Proofpoint's vendor cluster name for the Molerats / Gaza Cybergang activity tracked here as gaza-cybergang-molerats (ATT&CK G0021); mapped as a crosswalk, kept visible.
Related
Semantically related in the corpus — a discovery aid, not asserted attribution.
[Molerats](https://attack.mitre.org/groups/G0021) has sent malicious files via email that tricked users into clicking Enable Content to run an embedded macro and to download malicious archives.(Citation: Kaspersky MoleRATs April 2019)(Citation: Unit42 Molerat Mar 2020)(Citation: Cybereason Molerats
[Molerats](https://attack.mitre.org/groups/G0021) used various implants, including those built with VBScript, on target machines.(Citation: Kaspersky MoleRATs April 2019)(Citation: Unit42 Molerat Mar 2020)
[Molerats](https://attack.mitre.org/groups/G0021) used various implants, including those built with JS, on target machines.(Citation: Kaspersky MoleRATs April 2019)
[Molerats](https://attack.mitre.org/groups/G0021) has sent phishing emails with malicious Microsoft Word and PDF attachments.(Citation: Kaspersky MoleRATs April 2019)(Citation: Unit42 Molerat Mar 2020)(Citation: Cybereason Molerats Dec 2020)
[Molerats](https://attack.mitre.org/groups/G0021) saved malicious files within the AppData and Startup folders to maintain persistence.(Citation: Kaspersky MoleRATs April 2019)
[Molerats](https://attack.mitre.org/groups/G0021) has delivered compressed executables within ZIP files to victims.(Citation: Kaspersky MoleRATs April 2019)
[Molerats](https://attack.mitre.org/groups/G0021) has used msiexec.exe to execute an MSI payload.(Citation: Unit42 Molerat Mar 2020)
Associated software
6 linked · 6 ATT&CK-attributed, 0 curated
Malware and tools this actor is known to use. ATT&CK-attributed rows are MITRE's own software↔group relationships; curated rows fill the gap for MENA actors ATT&CK doesn't track — treat those as analyst assessment, not authoritative attribution.
ATT&CK-attributed · 6
Sourced from MITRE ATT&CK's own uses relationships for this group.
Regional co-occurrence is association, not prediction. These techniques appeared alongside Gaza Cybergang / Molerats's activity across the tracked MENA roster — a TIE-style association computed on our corpus (not CTID's model), not a prediction of the next move. Ranked by support-adjusted lift (over-representation among actors like this one vs. the roster base rate, damped when few actors back it), so neither a merely-common technique nor a tiny-sample coincidence floats to the top. A hunting lead only; never recorded as observed. ICS techniques are excluded.
Which Microsoft 365 controls protect, detect, or respond to this actor's techniques — from the CTID Mappings Explorer (technique-level). Strength: significant / partial / minimal.
Adaptive Application Control IntegrationT1204partialAdaptive Application Control IntegrationT1204.002partialAdaptive Application Control IntegrationT1553minimalAdaptive Application Control IntegrationT1553.002partialAdvanced Anti-Phishing T1566partialAdvanced Anti-Phishing T1566.001significantAdvanced Anti-Phishing T1566.002significantApp GovernanceT1566significantAdvanced Threat HuntingT1566significantAdvanced Threat HuntingT1566.002significantMicrosoft Defender for IdentityT1059minimalMicrosoft Defender for IdentityT1059.001minimalMicrosoft Defender for IdentityT1555
respond · 9 techniques
Advanced Anti-Phishing T1566partialAdvanced Anti-Phishing T1566.001partialAdvanced Anti-Phishing T1566.002partialAutomated Investigation and ResponseT1204.001significantAutomated Investigation and ResponseT1204.002significantAutomated Investigation and ResponseT1566significantAutomated Investigation and ResponseT1566.001significantAutomated Investigation and ResponseT1566.002significantIncident ResponseT1059minimalIncident ResponseT1566minimalQuarantine PoliciesT1027significantQuarantine PoliciesT1204significantQuarantine PoliciesT1204.001
Countermeasures · D3FEND
Defensive techniques that counter Gaza Cybergang / Molerats's TTPs, from MITRE D3FEND. The ATT&CK↔D3FEND link is mitigation-mediated — treat these as candidate countermeasures, not prescriptions.