Overview
InvisiMole (MITRE ATT&CK ID S0260) is a modular spyware program that has been used by the InvisiMole Group since at least 2013, per MITRE’s software profile. MITRE documents two backdoor modules, RC2FM and RC2CL, used to perform post-exploitation activities, and notes InvisiMole has been discovered on compromised victims in Ukraine and Russia. MITRE’s data also records that Gamaredon Group infrastructure has been used to download and execute InvisiMole against a small number of victims — a documented infrastructure-sharing relationship between two separately tracked groups.
What MITRE’s data links this to
Our ingested attack_relationships data does not currently include a direct group-attribution edge for InvisiMole in the batch we queried, despite MITRE’s description text naming “the InvisiMole Group” as the primary user — a gap between the prose description and the structured relationship data worth flagging rather than papering over with an inferred link.
Notable techniques (per MITRE ATT&CK relationship data)
Techniques MITRE links to InvisiMole in our data include Application Window Discovery (T1010), Archive via Custom Method (T1560.003), Archive via Library (T1560.002), Archive via Utility (T1560.001), Asynchronous Procedure Call (T1055.004), Audio Capture (T1123), Automated Collection (T1119), and Bypass User Account Control (T1548.002) — audio capture in particular is a relatively uncommon capability among the malware families in this batch, consistent with MITRE’s “spyware” classification.
What we don’t have
MITRE’s ingested data doesn’t include a structured discovery-date field for software entries, though MITRE’s description text states “at least 2013.” We have no independent telemetry or IOC data beyond MITRE’s STIX bundle, and as noted above, our structured relationship data doesn’t yet surface the group-attribution edge that MITRE’s own prose description makes explicit.
Frequently Asked Questions
What is InvisiMole? A modular spyware program, per MITRE ATT&CK, used by the InvisiMole Group since at least 2013 against victims in Ukraine and Russia.
What can InvisiMole do? Per MITRE ATT&CK’s relationship data, documented capabilities include audio capture, automated data collection, multiple archive/compression methods, and UAC bypass — consistent with a full-featured espionage spyware toolkit.
Is InvisiMole linked to Gamaredon Group? MITRE’s description notes Gamaredon Group infrastructure has been used to download and execute InvisiMole against a small number of victims — an infrastructure-sharing relationship, not necessarily common ownership or development.
Data sourced from MITRE ATT&CK® (https://attack.mitre.org), software ID S0260, aggregated August 28, 2026. This product uses MITRE ATT&CK data but is not endorsed or certified by MITRE. See more malware profiles.