InvisiMole
Also reported as UAC-0035 and Storm-0593. Linked to Russia by two sources.
Reports per quarter
Techniques seen in the last two years
- T1012 1 report
- T1036.005 1 report
- T1057 1 report
- T1059.001 1 report
- T1071.001 1 report
- T1082 1 report
- T1083 1 report
- T1102 1 report
- T1140 1 report
- T1480.001 1 report
Show all 16 techniques Show fewer
Counts come from technique IDs in the actor's report text.
CVEs named in reports
- CVE-2007-5633
- CVE-2009-0824
- CVE-2010-1592
- CVE-2012-0158 KEV ransomware
- CVE-2012-5687
- CVE-2013-5947
- CVE-2014-1225
- CVE-2014-2962
- CVE-2014-4019
- CVE-2014-8361 KEV
- CVE-2014-9583
- CVE-2015-0554
Show all 52 CVEs Show fewer
- CVE-2015-1635 KEV
- CVE-2015-2051 KEV
- CVE-2015-7248
- CVE-2015-7254
- CVE-2017-0144 KEV ransomware
- CVE-2017-11882 KEV ransomware
- CVE-2017-18368 KEV
- CVE-2017-5638 KEV ransomware
- CVE-2018-10562 KEV ransomware
- CVE-2018-19320 KEV ransomware
- CVE-2018-8453 KEV ransomware
- CVE-2019-0708 KEV ransomware
- CVE-2019-11510 KEV ransomware
- CVE-2019-15126
- CVE-2019-19781 KEV ransomware
- CVE-2020-0968 KEV ransomware
- CVE-2020-15479
- CVE-2020-15480
- CVE-2020-15481
- CVE-2020-15892
- CVE-2020-15893
- CVE-2020-15894
- CVE-2020-15895
- CVE-2020-15896
- CVE-2020-28921
- CVE-2020-28922
- CVE-2020-3702
- CVE-2021-1636
- CVE-2021-26334
- CVE-2021-26855 KEV ransomware
- CVE-2021-32648 KEV
- CVE-2021-3970
- CVE-2021-3971
- CVE-2021-3972
- CVE-2021-40444 KEV ransomware
- CVE-2021-44228 KEV ransomware
- CVE-2022-0847 KEV
- CVE-2022-22963 KEV
- CVE-2022-22965 KEV
- CVE-2022-30190 KEV ransomware
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor DCRat (Malware Family)
-
HermeticWiper (Malware Family)
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor HermeticWiper (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor IsaacWiper (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor DoubleZero (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor AcidRain (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor PartyTicket (Malware Family)
-
Overview of the Cyber Weapons Used in the Ukraine - Russia War
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Overview of the Cyber Weapons Used in the Ukraine - Russia War
Show all 25 reports Show fewer
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor eset_threat_report_t12022
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Ukraine CyberWar Overview
-
Signed kernel drivers – Unguarded gateway to Windows’ core
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Signed kernel drivers – Unguarded gateway to Windows’ core
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ESET_Threat_Report_Q32020
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ESET_Threat_Report_Q22020
-
Digging up InvisiMole’s hidden arsenal
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Digging up InvisiMole’s hidden arsenal
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ESET_InvisiMole
-
InvisiMole- Surprisingly equipped spyware, undercover since 2013
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor InvisiMole- Surprisingly equipped spyware, undercover since 2013
Newest first. Details opens the report in Explore.