Security News > 2022 > February > Molerats hackers deploy new malware in highly evasive campaign
![Molerats hackers deploy new malware in highly evasive campaign](/static/build/img/news/molerats-hackers-deploy-new-malware-in-highly-evasive-campaign-medium.jpg)
The Palestinian-aligned APT group tracked as TA402 was spotted using a new implant named 'NimbleMamba' in a cyber-espionage campaign that leverages geofencing and URL redirects to legitimate websites.
If the target's IP address matches the defined targeted region, a copy of NimbleMamba is dropped on their system inside a RAR file.
NimbleMamba inevitably carries some code similarities with LastConn, but these are limited to the programming language, C2 encoding scheme, and the use of Dropbox API for communications.
"NimbleMamba has the traditional capabilities of an intelligence-gathering trojan and is likely designed to be the initial access," explains Proofpoint's report.
The RAR files fetched from Dropbox don't always contain only NimbleMamba, as the analysts also retrieved the BrittleBush trojan, which is most likely used as a backup tool.
Already, the domains used for delivering NimbleMamba and C2 communications have been taken offline.
News URL
Related news
- Hackers hijack antivirus updates to drop GuptiMiner malware (source)
- Hackers Increasingly Abusing Microsoft Graph API for Stealthy Malware Communications (source)
- Iranian hackers pose as journalists to push backdoor malware (source)
- North Korean Hackers Deploy New Golang Malware 'Durian' Against Crypto Firms (source)
- North Korean Hackers Exploit Facebook Messenger in Targeted Malware Campaign (source)
- Russian hackers use new Lunar malware to breach a European govt's agencies (source)
- Foxit PDF Reader Flaw Exploited by Hackers to Deliver Diverse Malware Arsenal (source)
- Pakistan-linked Hackers Deploy Python, Golang, and Rust Malware on Indian Targets (source)
- Russian Hackers Target Europe with HeadLace Malware and Credential Harvesting (source)
- Andariel Hackers Target South Korean Institutes with New Dora RAT Malware (source)