Threat actor · all actors
MoleratsG0021 state
🌍 PS
aka Molerats, Operation Molerats, Gaza Cybergang, Gaza Hackers Team, Extreme Jackal, Moonlight, ALUMINUM SARATOGA, G0021, BLACKSTEM
Last updated: 2026-08-20
About this actor
[Molerats](https://attack.mitre.org/groups/G0021) is an Arabic-speaking, politically-motivated threat group that has been operating since 2012. The group's victims have primarily been in the Middle East, Europe, and the United States.(Citation: DustySky)(Citation: DustySky2)(Citation: Kaspersky MoleRATs April 2019)(Citation: Cybereason Molerats Dec 2020)
Source: MITRE ATT&CK
Names & naming systems
Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.
MITRE ATT&CKG-number catalogue id
CrowdStrikenation-animal names
Secureworkscolour-metal names
Unclassifiedno scheme matched
How we know this
- Data origin
- MITRE ATT&CK Imported from the MITRE ATT&CK STIX bundle as an intrusion-set object.
- Techniques
- MITRE ATT&CK STIX mappings — 25 ATT&CK techniques on file.
- Named victims
- None on file.
See how actor data is built for the full pipeline.
Activity timeline
No activity events recorded.
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
| No attributed CVEs. | |||||
T1027Obfuscated Files or Information ↗T1027.015Compression ↗T1053Scheduled Task/Job ↗T1053.005Scheduled Task ↗T1057Process Discovery ↗T1059Command and Scripting Interpreter ↗T1059.001PowerShell ↗T1059.005Visual Basic ↗T1059.007JavaScript ↗T1105Ingress Tool Transfer ↗T1140Deobfuscate/Decode Files or Information ↗T1204User Execution ↗T1204.001Malicious Link ↗T1204.002Malicious File ↗T1218System Binary Proxy Execution ↗T1218.007Msiexec ↗T1547Boot or Logon Autostart Execution ↗T1547.001Registry Run Keys / Startup Folder ↗T1553Subvert Trust Controls ↗T1553.002Code Signing ↗T1555Credentials from Password Stores ↗T1555.003Credentials from Web Browsers ↗T1566Phishing ↗T1566.001Spearphishing Attachment ↗T1566.002Spearphishing Link ↗
Mitigating controls (NIST 800-53)
| Control | Techniques covered | Coverage |
|---|---|---|
CM-2 | 17 / 25 | 68% |
CM-6 | 17 / 25 | 68% |
SI-4 | 17 / 25 | 68% |
CM-7 | 13 / 25 | 52% |
SI-3 | 13 / 25 | 52% |
CA-7 | 12 / 25 | 48% |
AC-3 | 11 / 25 | 44% |
AC-6 | 10 / 25 | 40% |
SI-2 | 10 / 25 | 40% |
AC-2 | 9 / 25 | 36% |
SI-7 | 9 / 25 | 36% |
AC-4 | 8 / 25 | 32% |
CM-8 | 8 / 25 | 32% |
RA-5 | 8 / 25 | 32% |
SC-7 | 8 / 25 | 32% |
Co-occurring actors
None.
Similar actors
Similar TTPs
- Machete 0.40
- Confucius 0.39
- LazyScripter 0.38
- Rancor 0.37
- Windshift 0.36
Same category
- Night Dragon 1.00
- FunnyDream 1.00
- C0011 1.00
- Operation Wocao 1.00
- Operation Dream Job 1.00