InvisiMole
S0260 · Windows
InvisiMole is a modular spyware program that has been used by the InvisiMole Group since at least 2013. InvisiMole has two backdoor modules called RC2FM and RC2CL that are used to perform post-exploitation activities. It has been discovered on compromised victims in the Ukraine and Russia.
Gamaredon Group infrastructure has been used to download and execute InvisiMole against a small number of victims.
ATT&CK S0260
Sigma rules0
YARA rules0
Live IOCs0