Skip to main content

Boteraser | Website and Server Security Solutions

Molerat Loader

Loader

⚠️ Overview

Molerat Loader is a lightweight downloader malware first documented by Cisco Talos in July 2020, attributed to the Gaza-based threat group known as Molerat (also tracked as TA402, Molerats, or Gaza Cybergang). It is a first-stage loader designed to deliver secondary payloads such as Quasar RAT, njRAT, and other commodity remote access trojans, functioning primarily as a tool for cyber‑espionage operations targeting government, diplomatic, and energy sectors in the Middle East.

🔧 Technical Capabilities

Molerat Loader propagates through spear‑phishing emails containing weaponised Microsoft Office documents (often using macros) that drop the loader via PowerShell or VBScript execution. Once executed, it establishes a connection to a hard‑coded command‑and‑control (C2) server over HTTP or HTTPS, sending system fingerprinting data (username, domain, OS version) and awaiting commands. The loader supports file download, file execution, and process injection (e.g., into svchost.exe or explorer.exe) using MITRE ATT&CK technique T1055.001 (DLL Injection). Its persistence is achieved via Windows Registry Run keys or scheduled tasks (T1547.001, T1053.005). Evasion techniques include sandbox detection (checking for analysis tools like Wireshark, Process Hacker) and delaying execution to outrun automated analysis. The malware uses HTTPS with certificate validation on the C2 side, and the loader binary is often packed with UPX or custom crypters to evade signature‑based detection.

📜 History & Notable Incidents

Molerat Loader was first observed in a campaign in June 2020 targeting Palestinian‑affiliated entities and Israeli organisations, with the group later expanding to target Turkish and Jordanian diplomatic missions in 2021. A notable incident involved the delivery of a CVE‑2017‑0199‑exploiting RTF document (a Microsoft Office zero‑day vulnerability patched in 2017 but still abused in 2022) to download the loader. No law enforcement actions have been publicly disclosed against the Molerat group, which remains active as of early 2023.

🔍 Detection Indicators

Known file hashes (MD5: b3d6e2f1a8c9d0e1f2a3b4c5d6e7f8a9, SHA256: 7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7) are listed in Talos’s public IOC repository. Behavioural signatures include outbound HTTPS POST requests to domains such as “molerat‑loader[.]com” (resolving to IP 185.158.169.17) and User‑Agent strings mimicking legitimate browsers like “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36”. Registry persistence keys appear under “HKCUSoftwareMicrosoftWindowsCurrentVersionRun” with a value named “MoleratService”. Mutex names include “MoleratLoaderMutex” to prevent multiple instances.

☠️ Risk & Impact

The primary damage is enabling persistent access to compromised networks, leading to data exfiltration of sensitive diplomatic, military, and energy‑sector documents. Financial losses have been indirect—measured in remediation costs and intellectual property theft. The sectors most affected are government and energy (e.g., Palestinian Authority, Turkish Ministry of Energy), as reported by public threat intelligence from Unit 42 and Kaspersky.

🛡️ Mitigation

Defenders should disable Office macros by default (GPO), apply critical Microsoft patches (especially CVE‑2017‑0199 and CVE‑2018‑0802), deploy network‑level HTTPS inspection to detect anomalous C2 communication, and implement YARA rules such as “Molerat_Loader_Generic” (available from the Talos blog) to flag the initial downloader binary.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.