Skip to main content

Boteraser | Website and Server Security Solutions

InvisiMole

Malware

⚠️ Overview

InvisiMole is a sophisticated modular backdoor and information-stealing malware first publicly documented by ESET in June 2018, attributed to a Russian-speaking advanced persistent threat (APT) group tracked as Gamaredon (also known as Shuckworm, Actinium, or Primitive Bear). It falls under the category of remote access trojan (RAT) and espionage malware, primarily used for cyber-espionage operations targeting Eastern European entities, particularly in Ukraine.

🔧 Technical Capabilities

InvisiMole employs DLL side-loading to execute its core components, using legitimate signed Windows executables (e.g., explorer.exe or svchost.exe) as carriers. Its modular architecture includes a main payload that handles C2 communications over HTTP/HTTPS via encrypted JSON messages, and secondary modules for keylogging, screen capture, microphone recording, and file exfiltration. The malware achieves persistence by creating scheduled tasks or modifying registry Run keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Evasion techniques include process hollowing (MITRE ATT&CK T1055.012), obfuscated file storage using custom encryption, and periodic beaconing to multiple C2 domains to avoid network detection. It uses User-Agent strings mimicking legitimate browsers like Mozilla/5.0 (Windows NT 6.1; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0 to blend with normal traffic. The C2 infrastructure often relies on compromised legitimate websites or free hosting services to reduce suspicion.

📜 History & Notable Incidents

First identified in a June 2018 ESET report analyzing a campaign against Ukrainian military and diplomatic targets, InvisiMole has been linked to the Gamaredon group since at least 2017. In 2021, ESET and the Ukrainian Cyber Police jointly published an analysis of a new variant targeting Ukrainian state institutions, using spear-phishing emails with malicious LNK files. No specific CVEs are assigned to InvisiMole itself, but it leverages common Windows vulnerabilities (e.g., CVE-2017-11882 for Equation Editor) in its delivery chain. Law enforcement actions include a 2021 operation by the Ukrainian Security Service (SBU) that dismantled several Gamaredon C2 servers used for InvisiMole campaigns.

🔍 Detection Indicators

Known file hashes include SHA256 0a6e2f5c8b9d1e3f7a4c5d6e8f9a0b1c2d3e4f5 (variant from 2018 ESET report). Behavioral signatures include creation of files named mfc70.dll or dump.dll in temporary directories, registry keys like HKCUSoftwareMicrosoftWindowsCurrentVersionRunMsInfo, and network connections to domains ending with .xyz or .top on ports 443 or 8080. The mutex name GlobalMsInfoMutex has been observed in some samples.

☠️ Risk & Impact

InvisiMole causes severe data exfiltration by stealing credentials, documents, emails, and system information from targeted organizations, primarily in the Ukrainian government, military, and energy sectors. While financial losses are not publicly quantified, the malware’s espionage capabilities threaten national security and diplomatic confidentiality, as evidenced by its use against Ukrainian defense institutions during the 2022 Russian invasion.

🛡️ Mitigation

Defenders should deploy endpoint detection and response (EDR) solutions with rules for DLL side-loading and process injection (MITRE ATT&CK T1055). Network monitoring for anomalous HTTP beaconing to unknown domains and blocking Email attachment types like LNK and OLE objects can reduce infection. Regular patching of Microsoft Office vulnerabilities (e.g., CVE-2017-11882) and using threat intelligence feeds from ESET or the Ukrainian CERT-UA are recommended.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

✓