InvisiMole is a stealth-focused cyberespionage threat actor publicly uncovered in 2018 and associated with highly selective intrusions, particularly involving Ukrainian targets. The group has been observed attacking systems that were previously compromised and fingerprinted by Gamaredon, and researchers have also documented cases where Gamaredon infrastructure was used by InvisiMole, indicating operational collaboration or access-sharing among Russia-aligned actors. Available reporting does not support a definitive state attribution for InvisiMole itself, but its activity has been linked to the broader Russia-aligned intrusion ecosystem operating against Ukraine. InvisiMole is known for modular malware and post-compromise tradecraft oriented toward covert collection and long-term access. Documented behaviors include compressing stolen data with WinRAR prior to exfiltration, downloading additional modules over TCP, and using Windows services to execute malicious payloads. The actor has also employed process injection, including the ListPlanting technique to inject code into legitimate processes, and has used droppers disguised as legitimate software or documents to reduce suspicion. The group has demonstrated advanced Windows kernel exploitation capabilities. InvisiMole has used Bring Your Own Vulnerable Driver techniques, including exploitation of the SpeedFan driver vulnerability CVE-2007-5633 to load unsigned malicious drivers. A newer variant was observed on Windows 10 x64 using MSR-based exploitation to bypass mitigations such as SMEP and SMAP. InvisiMole has also installed legitimate but vulnerable software components to exploit stack overflow and input validation flaws for code execution. Additional destructive or anti-recovery behavior has included removing all system restore points on compromised hosts. Known aliases include Storm-0593. InvisiMole is best characterized as a technically capable espionage actor that combines stealth, modular tooling, kernel-level tradecraft, and selective targeting, with notable historical links to Gamaredon operations against Ukraine.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Threat actor previously observed collaborating with Gamaredon.
Mentioned as another actor that has historically received shared access from Gamaredon (no additional operational details provided in this content).
Actor previously observed using Gamaredon infrastructure (2020), indicating operational overlap or infrastructure sharing among Russian-aligned actors.
Conducts targeted follow-on intrusions against select systems previously compromised/fingerprinted by Gamaredon.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.