Netskope Threat Labs

Mole

ATP Sandbox Adv. HeuristicsAV

Mole is ransomware that encrypts files on infected systems and demands payment for decryption. Its operators gain initial access through phishing and compromised remote services, and its encryption routine locks documents and data while leaving ransom demands. Defenders should treat detections as urgent because ransomware spreads through network shares once it executes, and early containment preserves recovery options.

First seen
April 2022
Last seen
October 2026
Alert Name
Binary.Trojan.Mole
CMD:Heur.BZC.YAX.Mole.11.2270AF9A
CMD:Heur.BZC.YAX.Mole.11.30377297
CMD:Heur.BZC.YAX.Mole.11.31877119
CMD:Heur.BZC.YAX.Mole.2.21C8D3DD
CMD:Heur.BZC.YAX.Mole.2.27B03818
CMD:Heur.BZC.YAX.Mole.2.4C6C2BAB
CMD:Heur.BZC.YAX.Mole.2.5007B40E
CMD:Heur.BZC.YAX.Mole.2.52FB78EC
CMD:Heur.BZC.YAX.Mole.2.54F323D2