Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Software/S0260
MITRE ATT&CK Malware

InvisiMole (S0260)

ShareXLinkedInRedditHN

[InvisiMole](https://attack.mitre.org/software/S0260) is a modular spyware program that has been used by the InvisiMole Group since at least 2013. [InvisiMole](https://attack.mitre.org/software/S0260) has two backdoor modules called RC2FM and RC2CL that are used to perform post-exploitation activities. It has been discovered on compromised victims in the Ukraine and Russia. [Gamaredon Group](https://attack.mitre.org/groups/G0047) infrastructure has been used to download and execute [InvisiMole](https://attack.mitre.org/software/S0260) against a small number of victims.(Citation: ESET InvisiMole June 2018)(Citation: ESET InvisiMole June 2020)

Platforms: Windows

▪Techniques implemented (73)

T1573.001Symmetric CryptographyT1686Disable or Modify System FirewallT1025Data from Removable MediaT1218.011Rundll32T1490Inhibit System RecoveryT1055.002Portable Executable InjectionT1497.001System ChecksT1569.002Service ExecutionT1070.004File DeletionT1008Fallback ChannelsT1559.001Component Object ModelT1547.001Registry Run Keys / Startup FolderT1055.004Asynchronous Procedure CallT1095Non-Application Layer ProtocolT1560.002Archive via LibraryT1560.001Archive via UtilityT1113Screen CaptureT1010Application Window DiscoveryT1056.001KeyloggingT1033System Owner/User DiscoveryT1074.001Local Data StagingT1005Data from Local SystemT1564.001Hidden Files and DirectoriesT1068Exploitation for Privilege EscalationT1132.002Non-Standard EncodingT1112Modify RegistryT1218.002Control PanelT1059.007JavaScriptT1007System Service DiscoveryT1016System Network Configuration DiscoveryT1480.001Environmental KeyingT1055.015ListPlantingT1090.001Internal ProxyT1055Process InjectionT1082System Information DiscoveryT1059.003Windows Command ShellT1680Local Storage DiscoveryT1543.003Windows ServiceT1071.004DNST1027Obfuscated Files or InformationT1123Audio CaptureT1210Exploitation of Remote ServicesT1087.001Local AccountT1083File and Directory DiscoveryT1518Software DiscoveryT1560.003Archive via Custom MethodT1070.006TimestompT1140Deobfuscate/Decode Files or InformationT1105Ingress Tool TransferT1001.003Protocol or Service ImpersonationT1070.005Network Share Connection RemovalT1119Automated CollectionT1548.002Bypass User Account ControlT1564.003Hidden WindowT1080Taint Shared ContentT1125Video CaptureT1518.001Security Software DiscoveryT1547.009Shortcut ModificationT1574.001DLLT1046Network Service DiscoveryT1204.002Malicious FileT1124System Time DiscoveryT1053.005Scheduled TaskT1071.001Web ProtocolsT1135Network Share DiscoveryT1090.002External ProxyT1057Process DiscoveryT1036.004Masquerade Task or ServiceT1027.005Indicator Removal from ToolsT1203Exploitation for Client ExecutionT1036.005Match Legitimate Resource Name or LocationT1106Native APIT1012Query Registry
S0260on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.