AdversaryGraph public intelligence page
This page is part of Threat Matrix, the public browser workspace for the main AdversaryGraph platform. Use it for ATT&CK pivots, actor and technique context, similarity leads, detection coverage review, and analyst-ready investigation paths.
Validation disclaimer: TTP overlap, actor similarity, generated summaries, and coverage findings are investigation leads, not attribution proof or operational validation without analyst review.
Main AdversaryGraph project Documentation Malware Analysis GitHub
Molerats
Aliases: Operation Molerats, Gaza Cybergang
Molerats is an Arabic-speaking, politically-motivated threat group that has been operating since 2012. The group's victims have primarily been in the Middle East, Europe, and the United States.
Open interactive actor investigation
ATT&CK techniques
MsiexecT1204.001
Malicious LinkT1105
Ingress Tool TransferT1553.002
Code SigningT1027.013
Encrypted/Encoded FileT1053.005
Scheduled TaskT1140
Deobfuscate/Decode Files or InformationT1566.001
Spearphishing AttachmentT1057
Process DiscoveryT1566.002
Spearphishing LinkT1555.003
Credentials from Web BrowsersT1547.001
Registry Run Keys / Startup FolderT1059.001
PowerShellT1059.005
Visual BasicT1059.007
JavaScriptT1204.002
Malicious FileT1059
Command and Scripting Interpreter
Correlated CTI and IR reports
Proofpoint · direct source mappingThe Israel-Hamas War: Cyber Domain State-Sponsored Activity of Interest
SentinelOne · actor referenceActor Deep Research Prompts
Israel Threat Actors CTI · explicit report mentionCyber Threat Intelligence Dossier: Iranian and Hamas-Aligned Operations Targeting Israeli and Allied Ecosystems (2023-2026)
Israel Threat Actors CTI · explicit report mentionDefensive CTI Research on Threats to Israeli Government and Public-Sector Environments
Israel Threat Actors CTI · explicit report mentionIsrael Government Threat Actors CTI: Evidentiary Foundation Intake
Israel Threat Actors CTI · explicit report mentionAshen Lepus uses new AshTag malware suite
Unit 42 · downloaded report actor contextHamas-affiliated threat actor expands to disruptive activity
Check Point · downloaded report actor context
Continue the investigation
Cyber Knowledge routes
These contextual routes explain behaviors associated with this ATT&CK group record. They support learning and investigation planning; they do not add attribution evidence.
Blue Team & Defensive Security · explicit-idModule 11 — Email, web, API, data, and insider defense
Blue Team & Defensive Security · explicit-nameBinary formats, ABI, loaders, and mitigations
Vulnerability Research & Exploit Development · explicit-nameEmbedded, firmware, hardware, and update-chain research
Vulnerability Research & Exploit Development · explicit-nameFiles, parsers, serialization, URL fetching, and isolation
Secure Code & Application Security · explicit-nameImages, video, audio, geolocation, chronolocation, and media verification
OSINT & Reconnaissance · explicit-nameInfrastructure, network, resource, and availability security
AI Security · explicit-nameModule 7 — Privilege, lateral movement, and controlled impact
Red Team & Offensive Security · explicit-nameModule 7 — Endpoint defense and EDR
Blue Team & Defensive Security · explicit-nameControlled dynamic behavior and differential observation
Malware Analysis & Reverse Engineering · explicit-nameWindows endpoint and identity forensics
Digital Forensics & Incident Response (DFIR) · explicit-nameModule 5 — Threat hunting
Blue Team & Defensive Security · explicit-name