A new cyber espionage campaign that uses popular social media and cloud to target high-ranking political figures has been uncovered following research by Cybereason. The campaign has been observed operating primarily across the Middle East, and researchers believe it is targeting high-ranking political figures and government officials in the region. Cybereason said that the APT group “Molerats” appears to be behind this espionage campaign, which has been active in the Middle East since 2012. The hackers have previously used Spark and Pierogi to carry out targeted attacks against Palestinian officials.
The new espionage campaign uses three advanced, and previously unknown, malware: two backdoors named SharpStage and Dropbox, and a downloader called MoleNet. These are designed to help leverage Facebook, Dropbox, Google Sheets , and Simplenote, with cybercriminals aiming to steal sensitive and confidential data from their targets’ computers.

Cybereason further added that these new malware variants were used in conjunction with the Spark backdoor previously attributed to the Molerats APT group, as well as payloads, including the open-source Quasar RAT, known to have been used by the group.
As Infosecurity Magazine reports, phishing is another aspect of this espionage operation, with topics focusing on sensitive political issues in the Middle East, including Israeli-Saudi relations, elections in Hamas, and even a secret meeting between the US Secretary of State, the Israeli Prime Minister, and Saudi Crown Prince Mohammed bin Salman.

Lior Div, co-founder and CEO of Cybereason, pointed out that while it is not surprising that hackers are exploiting politically charged events to fuel their phishing campaigns, it is concerning that social media platforms, as well as other legitimate cloud services, are increasingly being used for data theft and other malicious activities by hackers.
