LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S0547: DropBook

DropBook is a Python-based backdoor compiled with PyInstaller.[1]

EnterpriseS0547MalwareObject v1.1Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

DropBook is a Windows malware entry in ATT&CK described as a Python-based backdoor compiled with PyInstaller. Its ATT&CK relationships make it material because the behavior is not just “malware on an endpoint”: it combines command execution, host discovery, file discovery, tool transfer, use of legitimate web services for command-and-control, and potential exfiltration over web services. For leaders, the practical issue is whether the organization can distinguish normal cloud/web-service traffic and scripting activity from suspicious backdoor behavior on Windows systems.

Executive priority

Prioritize DropBook as a validation case for Windows endpoint visibility, egress governance, and SOC readiness around legitimate web services being used as adversary infrastructure. Because ATT&CK lists no official detection text for this malware, executives should ask whether detection coverage is based on resilient behaviors such as command shell use, Python/PyInstaller-like execution, discovery activity, inbound tool transfer, and unusual web-service communications—not just malware names or static indicators. This is also relevant to audit and incident response evidence: teams need proof that endpoint, process, file, and network telemetry can reconstruct what a suspicious Windows host executed, discovered, downloaded, and sent externally.

Technical view

SOC and IR teams should validate behavior-level coverage for the related ATT&CK techniques: Windows Command Shell execution, Python execution, system and language discovery, file and directory discovery, deobfuscation or decoding activity, ingress tool transfer, web-service-based command-and-control, and exfiltration over web services. The object is Windows-platform malware, but several related techniques span other platforms; use the Windows scope for DropBook-specific validation unless local evidence expands the investigation. Detection engineering should focus on correlated sequences: an unusual executable or Python/PyInstaller-like artifact launching command shell activity, collecting host or file-system information, decoding content, transferring additional files, and communicating with legitimate external web services in a way that is unusual for the host, user, or business process.

Likely telemetry

  • Windows endpoint process creation telemetry, including parent-child process relationships and command-line arguments
  • File creation, modification, and execution evidence for suspicious executables, scripts, decoded content, or transferred tools
  • Endpoint telemetry showing system information, language, file, and directory discovery activity
  • Network connection logs, proxy logs, DNS logs, and TLS metadata for outbound web-service communications
  • Web gateway or firewall logs showing allowed traffic to common external web services

Detection direction

  • Validate behavior-based detections rather than relying only on the DropBook name, because the supplied ATT&CK object provides no official detection guidance.
  • Tune for suspicious chains of execution and discovery: unusual process execution followed by cmd activity, system information collection, language checks, and file or directory enumeration.
  • Review outbound communications to legitimate web services for host-level anomalies, especially from systems or users that do not normally interact with those services in that manner.
  • Correlate ingress tool transfer with later execution; downloaded files that are quickly executed or decoded should be treated as higher priority than isolated downloads.
  • Account for false positives from administrators, developers, automation, and legitimate Python usage; prioritize unexpected execution context, rare hosts, unusual parent processes, and web-service destinations inconsistent with business use.

Mitigation priorities

  • Establish or validate Windows endpoint logging and EDR coverage for process, file, command-line, and network activity before depending on detections.
  • Apply least-privilege and application control principles to reduce unnecessary command shell, scripting, and unapproved executable use on Windows systems.
  • Implement egress governance for external web services, including proxy visibility and business-justified allowlisting where feasible.
  • Harden monitoring for tool transfer and decoded or staged content, especially when followed by execution.
  • Prepare IR playbooks to collect endpoint process history, transferred files, discovery commands, and web-service communication evidence from suspected Windows hosts.
Additional notes and limits

ATT&CK identifies DropBook as a Python-based backdoor compiled with PyInstaller and relates it to Molerats and multiple techniques covering execution, discovery, command-and-control, ingress transfer, deobfuscation, and exfiltration over web services. The most defensible Glexia interpretation is to use DropBook as a behavior-driven coverage test for Windows backdoor tradecraft involving legitimate web services, not as a standalone indicator-driven detection case.

The supplied ATT&CK object has no official detection text, no aliases, no labels, and no specified tactics on the malware object itself. The assessment cannot claim active exploitation, customer exposure, guaranteed detection, or attribution in a specific incident. Local telemetry, asset roles, user behavior baselines, and approved web-service usage are required to determine whether observed activity is suspicious.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

DropBook

DropBook is a Python-based backdoor compiled with PyInstaller.[1]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

9 rows
DomainIDNameRelationship / procedure
EnterpriseT1059.006PythonSub-technique

DropBook is a Python-based backdoor compiled with PyInstaller.[1]

EnterpriseT1059.003Windows Command ShellSub-technique

DropBook can execute arbitrary shell commands on the victims' machines.[1][2]

EnterpriseT1083File and Directory Discovery

DropBook can collect the names of all files and folders in the Program Files directories.[1][2]

EnterpriseT1102Web Service

DropBook can communicate with its operators by exploiting the Simplenote, DropBox, and the social media platform, Facebook, where it can create fake accounts to control the backdoor and receive instructions.[1][2]

EnterpriseT1567Exfiltration Over Web Service

DropBook has used legitimate web services to exfiltrate data.[2]

EnterpriseT1105Ingress Tool Transfer

DropBook can download and execute additional files.[1][2]

EnterpriseT1140Deobfuscate/Decode Files or Information

DropBook can unarchive data downloaded from the C2 to obtain the payload and persistence modules.[1]

EnterpriseT1614.001System Language DiscoverySub-technique

DropBook has checked for the presence of Arabic language in the infected machine's settings.[2]

EnterpriseT1082System Information Discovery

DropBook has checked for the presence of Arabic language in the infected machine's settings.[1]

Associated objects

Groups, software, and campaigns

GroupEnterprise

G0021: Molerats

Molerats is an Arabic-speaking, politically-motivated threat group that has been operating since 2012. The group's victims have primarily been in the Middle East, Europe, and the United States.[1][2][3][4]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.1
Created
Modified
Raw hash
40d9b84b23157821...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.1Current bundle40d9b84b2315…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Cybereason Molerats Dec 2020

    Cybereason Nocturnus Team. (2020, December 9). MOLERATS IN THE CLOUD: New Malware Arsenal Abuses Cloud Platforms in Middle East Espionage Campaign. Retrieved December 22, 2020.

    Open source URL
  2. [2]
    BleepingComputer Molerats Dec 2020

    Ilascu, I. (2020, December 14). Hacking group’s new malware abuses Google and Facebook services. Retrieved December 28, 2020.

    Open source URL
  3. [3]
    BleepingComputer Molerats Dec 2020

    Ilascu, I. (2020, December 14). Hacking group’s new malware abuses Google and Facebook services. Retrieved December 28, 2020.

    Open source URL
  4. [4]
    BleepingComputer Molerats Dec 2020

    Ilascu, I. (2020, December 14). Hacking group’s new malware abuses Google and Facebook services. Retrieved December 28, 2020.

    Open source URL
  5. [5]
    Cybereason Molerats Dec 2020

    Cybereason Nocturnus Team. (2020, December 9). MOLERATS IN THE CLOUD: New Malware Arsenal Abuses Cloud Platforms in Middle East Espionage Campaign. Retrieved December 22, 2020.

    Open source URL
  6. [6]
    Cybereason Molerats Dec 2020

    Cybereason Nocturnus Team. (2020, December 9). MOLERATS IN THE CLOUD: New Malware Arsenal Abuses Cloud Platforms in Middle East Espionage Campaign. Retrieved December 22, 2020.

    Open source URL
  7. [7]
    DropBook

    (Citation: Cybereason Molerats Dec 2020)(Citation: BleepingComputer Molerats Dec 2020)

  8. [8]
    DropBook

    (Citation: Cybereason Molerats Dec 2020)(Citation: BleepingComputer Molerats Dec 2020)

  9. [9]
    DropBook

    (Citation: Cybereason Molerats Dec 2020)(Citation: BleepingComputer Molerats Dec 2020)

  10. [10]
    mitre-attackS0547
    Open source URL
  11. [11]
    mitre-attackS0547
    Open source URL
  12. [12]
    mitre-attackS0547
    Open source URL
  13. [13]
    Cybereason Molerats Dec 2020

    Cybereason Nocturnus Team. (2020, December 9). MOLERATS IN THE CLOUD: New Malware Arsenal Abuses Cloud Platforms in Middle East Espionage Campaign. Retrieved December 22, 2020.

    Open source URL
  14. [14]
    Cybereason Molerats Dec 2020

    Cybereason Nocturnus Team. (2020, December 9). MOLERATS IN THE CLOUD: New Malware Arsenal Abuses Cloud Platforms in Middle East Espionage Campaign. Retrieved December 22, 2020.

    Open source URL
  15. [15]
    BleepingComputer Molerats Dec 2020

    Ilascu, I. (2020, December 14). Hacking group’s new malware abuses Google and Facebook services. Retrieved December 28, 2020.

    Open source URL
  16. [16]
    BleepingComputer Molerats Dec 2020

    Ilascu, I. (2020, December 14). Hacking group’s new malware abuses Google and Facebook services. Retrieved December 28, 2020.

    Open source URL
  17. [17]
    Cybereason Molerats Dec 2020

    Cybereason Nocturnus Team. (2020, December 9). MOLERATS IN THE CLOUD: New Malware Arsenal Abuses Cloud Platforms in Middle East Espionage Campaign. Retrieved December 22, 2020.

    Open source URL
  18. [18]
    Cybereason Molerats Dec 2020

    Cybereason Nocturnus Team. (2020, December 9). MOLERATS IN THE CLOUD: New Malware Arsenal Abuses Cloud Platforms in Middle East Espionage Campaign. Retrieved December 22, 2020.

    Open source URL
  19. [19]
    Cybereason Molerats Dec 2020

    Cybereason Nocturnus Team. (2020, December 9). MOLERATS IN THE CLOUD: New Malware Arsenal Abuses Cloud Platforms in Middle East Espionage Campaign. Retrieved December 22, 2020.

    Open source URL
  20. [20]
    Cybereason Molerats Dec 2020

    Cybereason Nocturnus Team. (2020, December 9). MOLERATS IN THE CLOUD: New Malware Arsenal Abuses Cloud Platforms in Middle East Espionage Campaign. Retrieved December 22, 2020.

    Open source URL
  21. [21]
    BleepingComputer Molerats Dec 2020

    Ilascu, I. (2020, December 14). Hacking group’s new malware abuses Google and Facebook services. Retrieved December 28, 2020.

    Open source URL
  22. [22]
    BleepingComputer Molerats Dec 2020

    Ilascu, I. (2020, December 14). Hacking group’s new malware abuses Google and Facebook services. Retrieved December 28, 2020.

    Open source URL
  23. [23]
    Cybereason Molerats Dec 2020

    Cybereason Nocturnus Team. (2020, December 9). MOLERATS IN THE CLOUD: New Malware Arsenal Abuses Cloud Platforms in Middle East Espionage Campaign. Retrieved December 22, 2020.

    Open source URL
  24. [24]
    Cybereason Molerats Dec 2020

    Cybereason Nocturnus Team. (2020, December 9). MOLERATS IN THE CLOUD: New Malware Arsenal Abuses Cloud Platforms in Middle East Espionage Campaign. Retrieved December 22, 2020.

    Open source URL
  25. [25]
    BleepingComputer Molerats Dec 2020

    Ilascu, I. (2020, December 14). Hacking group’s new malware abuses Google and Facebook services. Retrieved December 28, 2020.

    Open source URL
  26. [26]
    BleepingComputer Molerats Dec 2020

    Ilascu, I. (2020, December 14). Hacking group’s new malware abuses Google and Facebook services. Retrieved December 28, 2020.

    Open source URL
  27. [27]
    Cybereason Molerats Dec 2020

    Cybereason Nocturnus Team. (2020, December 9). MOLERATS IN THE CLOUD: New Malware Arsenal Abuses Cloud Platforms in Middle East Espionage Campaign. Retrieved December 22, 2020.

    Open source URL
  28. [28]
    Cybereason Molerats Dec 2020

    Cybereason Nocturnus Team. (2020, December 9). MOLERATS IN THE CLOUD: New Malware Arsenal Abuses Cloud Platforms in Middle East Espionage Campaign. Retrieved December 22, 2020.

    Open source URL
  29. [29]
    BleepingComputer Molerats Dec 2020

    Ilascu, I. (2020, December 14). Hacking group’s new malware abuses Google and Facebook services. Retrieved December 28, 2020.

    Open source URL
  30. [30]
    BleepingComputer Molerats Dec 2020

    Ilascu, I. (2020, December 14). Hacking group’s new malware abuses Google and Facebook services. Retrieved December 28, 2020.

    Open source URL
  31. [31]
    BleepingComputer Molerats Dec 2020

    Ilascu, I. (2020, December 14). Hacking group’s new malware abuses Google and Facebook services. Retrieved December 28, 2020.

    Open source URL
  32. [32]
    BleepingComputer Molerats Dec 2020

    Ilascu, I. (2020, December 14). Hacking group’s new malware abuses Google and Facebook services. Retrieved December 28, 2020.

    Open source URL
  33. [33]
    Cybereason Molerats Dec 2020

    Cybereason Nocturnus Team. (2020, December 9). MOLERATS IN THE CLOUD: New Malware Arsenal Abuses Cloud Platforms in Middle East Espionage Campaign. Retrieved December 22, 2020.

    Open source URL
  34. [34]
    Cybereason Molerats Dec 2020

    Cybereason Nocturnus Team. (2020, December 9). MOLERATS IN THE CLOUD: New Malware Arsenal Abuses Cloud Platforms in Middle East Espionage Campaign. Retrieved December 22, 2020.

    Open source URL
  35. [35]
    Cybereason Molerats Dec 2020

    Cybereason Nocturnus Team. (2020, December 9). MOLERATS IN THE CLOUD: New Malware Arsenal Abuses Cloud Platforms in Middle East Espionage Campaign. Retrieved December 22, 2020.

    Open source URL
  36. [36]
    Cybereason Molerats Dec 2020

    Cybereason Nocturnus Team. (2020, December 9). MOLERATS IN THE CLOUD: New Malware Arsenal Abuses Cloud Platforms in Middle East Espionage Campaign. Retrieved December 22, 2020.

    Open source URL
  37. [37]
    BleepingComputer Molerats Dec 2020

    Ilascu, I. (2020, December 14). Hacking group’s new malware abuses Google and Facebook services. Retrieved December 28, 2020.

    Open source URL
  38. [38]
    BleepingComputer Molerats Dec 2020

    Ilascu, I. (2020, December 14). Hacking group’s new malware abuses Google and Facebook services. Retrieved December 28, 2020.

    Open source URL
  39. [39]
    Cybereason Molerats Dec 2020

    Cybereason Nocturnus Team. (2020, December 9). MOLERATS IN THE CLOUD: New Malware Arsenal Abuses Cloud Platforms in Middle East Espionage Campaign. Retrieved December 22, 2020.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.