Netskope Threat Labs

InvisiMole

ATP Sandbox Adv. HeuristicsAVNetskope IPS

InvisiMole is a Windows backdoor used for espionage, documented by ESET in 2018 but active since at least 2013. Its modules provide extensive surveillance capabilities, including webcam and microphone control, screen capture, file exfiltration, and execution of commands on compromised systems. Cyberattackers typically deploy it on already compromised machines, often following Gamaredon intrusions, and its victims have been concentrated in Russia and Ukraine.

First seen
May 2022
Last seen
October 2026
Invisimole

73 techniques across 10 tactics.

TA0002 Execution

TA0003 Persistence

TA0004 Privilege Escalation

  • T1068Exploitation for Privilege Escalation
  • T1548Abuse Elevation Control Mechanism

TA0005 Stealth

TA0007 Discovery

  • T1007System Service Discovery
  • T1010Application Window Discovery
  • T1012Query Registry
  • T1016System Network Configuration Discovery
  • T1033System Owner/User Discovery
  • T1046Network Service Discovery
  • T1057Process Discovery
  • T1082System Information Discovery
  • T1083File and Directory Discovery
  • T1087Account Discovery
  • T1124System Time Discovery
  • T1135Network Share Discovery
  • T1518Software Discovery
  • T1680Local Storage Discovery

TA0008 Lateral Movement

  • T1080Taint Shared Content
  • T1210Exploitation of Remote Services

TA0009 Collection

TA0011 Command and Control

TA0040 Impact

  • T1490Inhibit System Recovery

TA0112 Defense Impairment

  • T1112Modify Registry
  • T1686Disable or Modify System Firewall
Alert Name
Trojan.InvisiMole.A
Win32.Trojan.InvisiMole
Win64.Trojan.Invisimole
Win64.Trojan.InvisiMole