The Molerats threat group, also known as the Gaza cybergang, conducted sustained cyber-espionage operations against organizations in the Middle East using targeted phishing campaigns that delivered remote-access malware including Poison Ivy and the multi-stage DustySky implant. The activity was described as politically motivated intelligence gathering and relied on recurring waves of malicious emails crafted in Hebrew, Arabic, or English to match the intended victims.
Targets included government and diplomatic institutions, aerospace and defense companies, financial organizations, journalists, and software developers, with most victims located in Israel, Egypt, Saudi Arabia, the United Arab Emirates, and Iraq. Reporting indicates the group’s operations evolved over time from earlier Poison Ivy-based intrusions to the later DustySky campaign, while also reaching victims in the United States and Europe beyond its primary Middle East focus.

TTPs, infrastructure, and targeting history in one profile.
3 events from the most recent confirmed update back to the earliest known activity.
ClearSky says the multi-stage DustySky malware, called "NeD Worm" by its developer, has been in use since May 2015 in a Molerats campaign involving dozens of attacks and weekly phishing waves.
FireEye published reporting on Operation Molerats, describing Middle East cyber attacks using the Poison Ivy malware family.
ClearSky states that the Molerats, also known as the Gaza cybergang, have been operating since 2012 as a politically motivated intelligence-gathering group.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.