Palestine-based cyber espionage group targeting Middle Eastern and Western entities via spearphishing and custom malware.
Analyst brief
Molerats (also known as Gaza Hackers Team) is a Palestine-origin nation-state cyber espionage group targeting government, defense, media, and NGOs primarily in the Middle East, US, and Europe. They leverage spearphishing (T1566.001, T1566.002) for initial access and maintain persistence via Registry Run Keys and Scheduled Tasks. The group uses custom malware like MoleNet, PoisonIvy, and Spark, along with DropBook and SharpStage for exfiltration. Defenders should harden email security gateways, closely monitor for suspicious macros and Msiexec misuse, and watch for credential theft from web browsers (T1555.003).
Molerats
Gaza Hackers TeamGaza cybergangGaza Cybergang
activenation-state
In October 2012, malware attacks against Israeli government targets grabbed media attention as officials temporarily cut off Internet access for its entire police force and banned the use of USB memory sticks. Security researchers subsequently linked these attacks to a broader, yearlong campaign that targeted not just Israelis but Palestinians as well. and as discovered later, even the U.S. and UK governments. Further research revealed a connection between these attacks and members of the so-called “Gaza Hackers Team.” We refer to this campaign as “Molerats.”