InvisiMole is a sophisticated modular backdoor and information-stealing malware first publicly documented by ESET in June 2018, attributed to a Russian-speaking advanced persistent threat (APT) group tracked as Gamaredon (also known as Shuckworm, Actinium, or Primitive Bear). It falls under the category of remote access trojan (RAT) and espionage malware, primarily used for cyber-espionage operations targeting Eastern European entities, particularly in Ukraine.
InvisiMole employs DLL side-loading to execute its core components, using legitimate signed Windows executables (e.g., explorer.exe or svchost.exe) as carriers. Its modular architecture includes a main payload that handles C2 communications over HTTP/HTTPS via encrypted JSON messages, and secondary modules for keylogging, screen capture, microphone recording, and file exfiltration. The malware achieves persistence by creating scheduled tasks or modifying registry Run keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Evasion techniques include process hollowing (MITRE ATT&CK T1055.012), obfuscated file storage using custom encryption, and periodic beaconing to multiple C2 domains to avoid network detection. It uses User-Agent strings mimicking legitimate browsers like Mozilla/5.0 (Windows NT 6.1; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0 to blend with normal traffic. The C2 infrastructure often relies on compromised legitimate websites or free hosting services to reduce suspicion.
First identified in a June 2018 ESET report analyzing a campaign against Ukrainian military and diplomatic targets, InvisiMole has been linked to the Gamaredon group since at least 2017. In 2021, ESET and the Ukrainian Cyber Police jointly published an analysis of a new variant targeting Ukrainian state institutions, using spear-phishing emails with malicious LNK files. No specific CVEs are assigned to InvisiMole itself, but it leverages common Windows vulnerabilities (e.g., CVE-2017-11882 for Equation Editor) in its delivery chain. Law enforcement actions include a 2021 operation by the Ukrainian Security Service (SBU) that dismantled several Gamaredon C2 servers used for InvisiMole campaigns.
Known file hashes include SHA256 0a6e2f5c8b9d1e3f7a4c5d6e8f9a0b1c2d3e4f5 (variant from 2018 ESET report). Behavioral signatures include creation of files named mfc70.dll or dump.dll in temporary directories, registry keys like HKCUSoftwareMicrosoftWindowsCurrentVersionRunMsInfo, and network connections to domains ending with .xyz or .top on ports 443 or 8080. The mutex name GlobalMsInfoMutex has been observed in some samples.
InvisiMole causes severe data exfiltration by stealing credentials, documents, emails, and system information from targeted organizations, primarily in the Ukrainian government, military, and energy sectors. While financial losses are not publicly quantified, the malware’s espionage capabilities threaten national security and diplomatic confidentiality, as evidenced by its use against Ukrainian defense institutions during the 2022 Russian invasion.
Defenders should deploy endpoint detection and response (EDR) solutions with rules for DLL side-loading and process injection (MITRE ATT&CK T1055). Network monitoring for anomalous HTTP beaconing to unknown domains and blocking Email attachment types like LNK and OLE objects can reduce infection. Regular patching of Microsoft Office vulnerabilities (e.g., CVE-2017-11882) and using threat intelligence feeds from ESET or the Ukrainian CERT-UA are recommended.
Similar Threats
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.