DropBook is a Windows backdoor associated with the Molerats threat cluster, also known as Gaza Cybergang, an espionage-focused actor active in the Middle East. It has been observed in politically themed intrusion campaigns targeting entities and individuals in the Palestinian Territories, the UAE, Egypt, Turkey, and other regional interests, with apparent emphasis on political figures and government-related targets.
DropBook is used for post-compromise remote access and data theft. It can communicate with operators through abused legitimate online services, including Simplenote, Facebook, and Dropbox, blending command-and-control and exfiltration traffic with normal web activity. Operators have used fake Facebook accounts and Simplenote pages to issue instructions, while Dropbox has been used both to exfiltrate stolen data and to store additional espionage tooling. The malware can download content from its command infrastructure and unarchive retrieved data to obtain payload and persistence components, enabling follow-on deployment of additional modules.
Observed tradecraft links DropBook to broader Molerats operations involving other malware such as SharpStage, MoleNet, Spark, Pierogi, and Quasar RAT. Campaigns using DropBook have relied on spearphishing and politically themed lure documents related to Middle Eastern affairs for initial infection. The malware also performs victim profiling by checking whether Arabic language settings are present on the infected machine, consistent with selective targeting of Arabic-speaking victims. Overall, DropBook is best characterized as a cloud-service-abusing espionage backdoor designed for covert command and control, payload retrieval, and exfiltration in targeted Middle East-focused operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
DropBook Backdoor: Hashes (SHA-256 + SHA-1) 2578cbf4980569b372e06cf414c3da9e29226df4612e2fc6c56793f77f8429d8 ... URLs http://simp[.]ly/p/04T5bp https://app.simplenote[.]com/p/04T5bp https://www.facebook.com/yora.stev.5
In late 2020, victims targeted with Pierogi variants as part of a suspected Arid Viper operation were observed to be also infected with the then-new SharpStage and DropBook malware.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
The content is a long ATT&CK-style listing of malware and threat groups that 'decrypt', 'decode', 'deobfuscate', 'unpack', or 'decompress' payloads, strings, configuration data, shellcode, and files prior to execution or use.
The content includes environment-aware checks such as "Bazar can also check if the Russian language is installed on the infected machine and terminate if it is found," "CaddyWiper can also halt execution if the compromised host is identified as a domain controller," and "OopsIE checks for information on the CPU fan, temperature, mouse, hard disk, and motherboard as part of its anti-VM checks."
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
The content is a long ATT&CK-style listing of groups and malware that can 'list files and directories,' 'search for files,' 'enumerate drives,' 'gather file metadata,' or 'browse file systems' on compromised hosts.
The content includes environment-aware checks such as "Bazar can also check if the Russian language is installed on the infected machine and terminate if it is found," "CaddyWiper can also halt execution if the compromised host is identified as a domain controller," and "OopsIE checks for information on the CPU fan, temperature, mouse, hard disk, and motherboard as part of its anti-VM checks."
Examples include: “Bazar … check if the Russian language is installed … and terminate if it is found.”; “DropBook … checked for the presence of Arabic language …”; “Maze … checked the language … GetUserDefaultUILanguage”; “SynAck … checks installed keyboard layouts to estimate … countries.”
Examples include 'Bazar can also check if the Russian language is installed,' 'DropBook has checked for the presence of Arabic language,' 'Maze has checked the language of the infected system,' and 'SynAck ... checks installed keyboard layouts to estimate if it has been launched from a certain list of countries.'
all of which can allow the attackers the ability to execute arbitrary code and collect sensitive data for exfiltration from infected computers
Examples in the content include 'DropBook can unarchive data downloaded from the C2 to obtain the payload and persistence modules,' 'Molerats decompresses ZIP files once on the victim machine,' and 'Rocke has extracted tar.gz files after downloading them from a C2 server.'
The Cybereason Nocturnus Team has identified an active espionage campaign employing three previously unidentified malware variants that use Facebook, Dropbox, Google Docs and Simplenote for command & control... The newly discovered DropBook backdoor used fake Facebook accounts or Simplenote for command and control (C2)
“APT41 DUST used compromised Google Workspace accounts for command and control… Carbon can use Pastebin to receive C2 commands… CHIMNEYSWEEP… use Telegram channels… DropBook… exploiting… Simplenote, DropBox… Facebook… Nightdoor… OneDrive or Google Drive for command and control… Turla has used… Pastebin, Dropbox, and GitHub for C2 communications.”
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware observed in overlap with Pierogi and SharpStage infections in a suspected Arid Viper operation, cited as strengthening ties between Gaza Cybergang sub-groups.
A malware/tool used by Gaza Cybergang in intelligence collection and espionage campaigns.
A newly identified backdoor used by Molerats for espionage. It uses fake Facebook accounts or Simplenote for C2 and Dropbox for exfiltration and tool storage, while enabling arbitrary code execution and sensitive data theft.
Backdoor malware using listed URLs and social/web services as part of its infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.