LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S0260: InvisiMole

InvisiMole is a modular spyware program that has been used by the InvisiMole Group since at least 2013. InvisiMole has two backdoor modules called RC2FM and RC2CL that are used to perform post-exploitation activities. It has been discovered on compromised victims in the Ukraine and Russia. Gamaredon Group infrastructure has been used to download and execute InvisiMole against a small number of victims.CitationESET InvisiMole June 2018CitationESET InvisiMole June 2020

EnterpriseS0260MalwareObject v2.1Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

InvisiMole is a Windows-focused modular spyware family with backdoor modules used for post-exploitation activity. Its ATT&CK relationships show why it matters operationally: the behavior spans stealth, persistence, discovery, collection, command-and-control disguise, and credential-relevant collection such as keylogging. For leaders, this is less about one malware name and more about whether Windows monitoring can prove coverage for long-running espionage-style activity that blends into normal services, scheduled tasks, processes, scripts, and network traffic.

Executive priority

Prioritize this as a resilience and assurance question for Windows estates that handle sensitive data or operate in regions or business contexts where targeted intrusion risk is material. The supplied ATT&CK data does not provide detection guidance, so executives should ask whether SOC and IR teams can validate telemetry for persistence, process injection, local/removable data access, command execution, registry/service discovery, and disguised or fallback C2. This also supports audit and compliance evidence: controls should demonstrate not only malware prevention, but visibility into post-compromise behavior and data collection paths.

Technical view

ATT&CK lists InvisiMole as Windows malware and relates it to techniques including protocol/service impersonation, fallback C2, local and removable-media collection, registry/service/process/window/user/network discovery, scheduled tasks, process injection variants, Windows command shell, JavaScript/JScript execution, keylogging, obfuscation, masquerading, and privilege escalation through exploitation. SOC teams should validate behavioral detections around these technique clusters rather than relying on static indicators alone. IR teams should be prepared to investigate persistence via scheduled tasks or masqueraded services, suspicious script or cmd execution, injected processes, evidence of local or removable-media file access, and network sessions that appear to imitate legitimate protocols or shift to alternate channels.

Likely telemetry

  • Windows endpoint process creation and command-line telemetry
  • Windows scheduled task creation, modification, and execution records
  • Windows service creation, service query, and service metadata changes
  • Registry query and modification telemetry
  • Endpoint file access telemetry for local files and removable media

Detection direction

  • Build coverage around ATT&CK technique clusters used by this malware, since the official object provides no dedicated detection text.
  • Correlate persistence indicators such as scheduled tasks and service changes with suspicious command shell, script execution, or unusual binary locations/names.
  • Tune for masquerading carefully: compare task, service, file, and registry names against known-good baselines rather than treating familiar-looking names as benign.
  • Validate EDR visibility for process injection behaviors on Windows, including PE injection, APC-related patterns, and other cross-process execution signals.
  • Review network analytics for traffic that mimics legitimate protocols or services and for fallback channels; avoid depending only on blocklists or signatures.

Mitigation priorities

  • Start with telemetry assurance: confirm Windows endpoint, task, service, registry, script, file, and network logs are collected and retained for investigation.
  • Reduce execution and persistence opportunities through controlled script execution, least privilege, and review of scheduled task and service creation rights.
  • Strengthen endpoint prevention and response controls that can observe memory-based and injected execution, not only files on disk.
  • Maintain vulnerability management and patch prioritization for Windows systems to reduce privilege escalation opportunities.
  • Apply egress control and monitoring for unusual outbound communications, including traffic that appears to impersonate legitimate services or uses alternate channels.
Additional notes and limits

The object’s official description identifies InvisiMole as modular spyware used by the InvisiMole Group since at least 2013, with RC2FM and RC2CL backdoor modules, and notes discovery on victims in Ukraine and Russia. It also states Gamaredon Group infrastructure was used to download and execute InvisiMole against a small number of victims. Those statements are useful for threat-intelligence context, but defensive planning should focus on the ATT&CK behavior relationships and local telemetry validation.

Official detection guidance is not provided. The object platform is Windows, while several related ATT&CK techniques list broader platforms; this take applies platform recommendations to Windows unless otherwise stated. No claim is made that any environment is exposed, that activity is currently occurring, or that specific detections will be effective without local validation.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

InvisiMole

InvisiMole is a modular spyware program that has been used by the InvisiMole Group since at least 2013. InvisiMole has two backdoor modules called RC2FM and RC2CL that are used to perform post-exploitation activities. It has been discovered on compromised victims in the Ukraine and Russia. Gamaredon Group infrastructure has been used to download and execute InvisiMole against a small number of victims.CitationESET InvisiMole June 2018CitationESET InvisiMole June 2020

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

Relationship explorer

All related ATT&CK context

No relationships are available in the current normalized data for this object.

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
2.1
Created
Modified
Raw hash
3f68e1202752ceb9...
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.