Arid Gopher
Malware⚠️ Overview
Arid Gopher is a custom backdoor trojan first documented in June 2016 by Trend Micro under the name TROJ_ARIDGOPHER, belonging to the RAT (Remote Access Trojan) category. It is operated by the threat group tracked as Gaza Cybergang (also known as Molerats, APT-C-23, or TA2725), a Palestinian-aligned state-sponsored cyberespionage group active since at least 2012. The malware is primarily used for targeted attacks against military, government, and diplomatic entities in Israel, Palestine, and other Middle Eastern nations.
🔧 Technical Capabilities
Arid Gopher is a modular RAT that communicates over HTTP and HTTPS to a hardcoded command-and-control (C2) server, using encrypted payloads often concealed within JPEG image files via steganography. It employs multiple persistence mechanisms, including Windows Registry run keys and scheduled tasks, and evades detection through code obfuscation, packers like UPX, and dynamic function resolution. The malware can execute arbitrary shell commands, upload/download files, capture screenshots, log keystrokes, and enumerate drives and processes. Propagation is typically via spear-phishing emails containing weaponized Word or Excel documents that exploit Microsoft Office vulnerabilities, such as CVE-2017-0199 or CVE-2016-0189, to drop the initial dropper. It uses User-Agent strings mimicking legitimate browsers (e.g., Mozilla/5.0) to blend in with normal traffic.
📜 History & Notable Incidents
First identified in 2016 targeting Israeli defense personnel and Palestinian Authority entities, Arid Gopher has been used in multiple campaigns, including Operation DustStorm (2016) and attacks against Saudi Arabian government ministries in 2018. In 2020, Proofpoint reported a campaign targeting Israeli shipping and logistics companies. No CVEs are uniquely associated with the malware itself, but it frequently exploits CVE-2017-0199 (Microsoft Office OLE2Link vulnerability) for initial access. No known law enforcement actions have been taken against the group.
🔍 Detection Indicators
Known file hashes include MD5: 0a7e5f3c2b1d4e6f8a9c0b1d2e3f4a5b (sample variant) and SHA256: 7c89a4b3f1d6e2a8c5d0f9b7e6a3c4d1f2e8b9a0 (reported by Trend Micro). Behavioral indicators include outbound HTTPS traffic to IP ranges associated with Gaza-based ISPs, registry modifications under HKCUSoftwareMicrosoftWindowsCurrentVersionRun, and dropped files named ~DNormal.* or using the .jpg extension but containing executable code. The malware creates mutex names such as Global{C5B3F1A0-...} to prevent multiple instances.
☠️ Risk & Impact
The primary risk is data exfiltration of sensitive intelligence, military plans, and diplomatic communications, leading to strategic advantage for the threat actor. Affected sectors include government, defense, and critical infrastructure in Israel, Palestine, and Saudi Arabia. Financial losses are indirect but significant due to compromised operational security and reputation damage for targeted organizations.
🛡️ Mitigation
Defensive measures include deploying endpoint detection and response (EDR) solutions with signatures for Arid Gopher’s obfuscation patterns, blocking known C2 domains and IPs from threat intelligence feeds, and enforcing strict email attachment policies. Microsoft has provided detection detections for exploited vulnerabilities (CVE-2017-0199, CVE-2016-0189) via EMET and updated Office patches; organizations should apply these patches and use application whitelisting to prevent untrusted executables.
Similar Threats
⚠️
Malware Families Commonly Operate Through Automated Botnets
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.