Multiple cyber-espionage operations targeted الفلسطينيين, activists, and organizations in the Palestinian territories with politically themed phishing lures and fake documents that delivered custom backdoors including Micropsia, Spark, Pierogi, and Scote. Reporting from Cisco Talos, Cybereason, and Palo Alto Networks links the activity to long-running Middle East-focused threat actors Arid Viper and MoleRATs (also known as the Gaza Cybergang), which repeatedly used Arabic-language decoys tied to regional politics, social-engineering archives hosted on services such as Dropbox and Egnyte, malicious RTF and Word files, and self-extracting executables to infect victims.
The malware families provided persistent remote access and espionage capabilities including host reconnaissance, command execution, keylogging, screenshot capture, audio recording, file transfer, and HTTP-based command-and-control. Researchers said the operators also used evasion and targeting checks such as security-product discovery, Arabic language or keyboard validation, packers, and abuse of third-party platforms including Pastebin, Google+, and URL shorteners to hide infrastructure and retrieve C2 data. Across the campaigns, analysts observed largely consistent tradecraft over several years, indicating sustained intelligence collection against Palestinian political and civil-society targets despite repeated public exposure.

TTPs, infrastructure, and targeting history in one profile.
19 events from the most recent confirmed update back to the earliest known activity.
Deep Instinct analyzed three related Go-written malware samples used by Arid Viper and named the variant Arid Gopher, assessing it as a Micropsia variant still under development. The malware was delivered in archive files, dropped decoy documents, infected Windows systems, and opened a backdoor to command-and-control infrastructure.
Cisco Talos said the latest observed wave of Arid Viper's Micropsia campaign started around October 2021. It targeted Palestinian individuals, activists, and organizations with politically themed decoy documents.
Talos observed September 2021 decoy documents covering Palestinian family reunification and sustainable development in Palestine. These lures were used in the same Micropsia campaign attributed to Arid Viper.
ThreatLabz reported a Molerats espionage campaign active from July 2021 through December 2021 that targeted Palestinian banking personnel, people tied to Palestinian political parties, and human rights activists and journalists in Turkey. The operation used macro-enabled Office decoys themed around Israel-Palestine issues to deliver a .NET backdoor that used Dropbox API for command-and-control and exfiltration.
Talos observed a July 2021 decoy consisting of a patient's report containing affidavits from the State of Palestine's Ministry of Health. The lure was used in Arid Viper's Micropsia campaign targeting Palestinian victims.
Meta reported and disrupted a separate cyber espionage operation linked to the Palestinian Preventive Security Service that targeted people primarily in Palestine and Syria using fake personas, malicious links, and Android and Windows malware. Meta said it removed accounts, blocked domains, released malware hashes, and notified targeted users in what it described as the first public reporting on this activity.
Talos noted that Meta exposed Arid Viper in an April 2021 report focused mainly on the actor's mobile targeting operations. Talos said the group nevertheless continued targeting Windows-based systems afterward.
Talos observed politically themed decoys used by Arid Viper in February and March 2021, including lures referencing a February 20, 2021 presidential decree on freedom of expression ahead of legislative elections. These decoys were part of the group's continuing Micropsia espionage activity.
Cybereason investigated a campaign active since December 2019 that targeted Palestinian individuals and entities, especially within the Palestinian territories and likely including Palestinian government-related victims. The campaign delivered a previously undocumented Delphi backdoor dubbed Pierogi through social engineering and themed decoys.
Cybereason said the Pierogi campaign used infrastructure including linda-callaghan[.]icu and nicoledotson[.]icu that was registered in November 2019. This infrastructure was later used to download payloads and manage command-and-control communications.
Cybereason reported that the Spark backdoor first appeared around January 2019. The malware was described as a custom backdoor likely developed by MoleRATs.
Public bit.ly statistics cited by Unit 42 showed most activity for a malicious TopHat redirect in late October 2017. The downloads primarily originated from the Palestinian Territories and the United Arab Emirates.
Unit 42 noted that Microsoft patched CVE-2017-0199 in September 2017. TopHat operators later used malicious RTF files exploiting this vulnerability as one of their delivery methods.
Palo Alto Networks Unit 42 observed the TopHat campaign beginning in early September 2017, using Arabic-language political decoys against victims believed to include individuals or organizations in the Palestinian Territories. The campaign delivered a newly identified backdoor malware family named Scote.
Cisco Talos said the Arid Viper APT group had operated the Delphi-based Micropsia malware since at least 2017. Talos linked later activity to this long-running campaign based on similar tactics, techniques, and procedures.
Unit 42 and ClearSky said a multi-platform espionage campaign using the Windows malware families KASPERAGENT and MICROPSIA, along with the Android malware families SECUREUPDATE and VAMP, likely began as early as July 2015. The activity targeted users primarily in the United States, Israel, the Palestinian Territories, and Egypt, and researchers had not confidently attributed it to a known threat actor at the time.
Securelist published research on Operation SneakyPastes, attributing the activity to Gaza Cybergang Group1. The report described a distinct espionage operation not already represented in the existing timeline.
Cybereason identified an active espionage campaign attributed to Molerats targeting victims in the Palestinian Territories, the UAE, Egypt, and Turkey. The operation used newly described malware components SharpStage, DropBook, and MoleNet, abused Facebook, Dropbox, Google Docs, and Simplenote for command and control and exfiltration, and was linked to earlier Spark and Pierogi activity.
Cybereason reported recent simultaneous Spark and Pierogi cyber-espionage campaigns targeting Palestinian individuals and entities in the Middle East. The company assessed the operations were politically motivated and linked them with moderate confidence to MoleRATs based on tooling, lure themes, and command-and-control overlaps.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 478 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
16 references tracked. Mallory keeps watching after this page renders.
zscaler.com
Open sourcecybereason.com
Open sourcecybereason.com
Open sourceattack.mitre.org
Open sourceresearchcenter.paloaltonetworks.com
Open sourceunit42.paloaltonetworks.com
Open sourceattack.mitre.org
Open sourcesecurelist.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.