InvisiMole is a modular spyware platform and associated espionage threat actor active since at least 2013. It is tracked under names including InvisiMole Group and Storm-0593. The actor is associated with stealthy post-compromise operations and selective targeting, and has been observed operating on systems previously compromised and fingerprinted by Gamaredon, indicating access-sharing or operational collaboration between Russia-aligned intrusion sets. InvisiMole is known for a broad Windows-focused toolset that supports code execution, persistence, defense evasion, process injection, and data theft. Reported tradecraft includes disguising droppers as legitimate software or documents, masquerading malicious components as benign system libraries, using Windows services to execute payloads, downloading additional modules over TCP, compressing stolen data with WinRAR prior to exfiltration, and removing system restore points to hinder recovery. The malware has also used ListPlanting for code injection into legitimate processes. A notable aspect of InvisiMole’s capability set is kernel-level tradecraft. The actor has used Bring Your Own Vulnerable Driver techniques, including exploitation of CVE-2007-5633 in a signed vulnerable driver, to load unsigned malicious drivers. Newer variants demonstrated attempts to bypass modern Windows protections such as SMEP and SMAP in order to execute kernel-mode payloads and interfere with security tooling. InvisiMole has also been reported using legitimate but vulnerable software components to achieve code execution on compromised hosts. The group is best characterized as a cyber-espionage actor focused on covert surveillance and information theft rather than disruption or extortion.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Threat actor previously observed collaborating with Gamaredon.
Referenced in relation to infrastructure/arsenal overlap discussion involving Gamaredon, but not the primary subject of this content.
Mentioned as another actor that has historically received shared access from Gamaredon (no additional operational details provided in this content).
Actor previously observed using Gamaredon infrastructure (2020), indicating operational overlap or infrastructure sharing among Russian-aligned actors.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.