Campaign, Jan 2021 to Dec 2021.View on attack.mitre.org
Outer Space was a campaign conducted by OilRig throughout 2021 that used the SampleCheck5000 downloader and Solar backdoor to target Israeli organizations.
| Technique | Procedure example |
|---|---|
| T1027.013 Encrypted/Encoded File |
During Outer Space, OilRig deployed VBS droppers with obfuscated strings. |
| T1059.005 Visual Basic |
During Outer Space, OilRig used VBS droppers to deploy malware. |
| T1071.001 Web Protocols |
During Outer Space, OilRig used HTTP to communicate between installed backdoors and compromised servers including via the Microsoft Exchange Web Services API. |
| T1105 Ingress Tool Transfer |
During Outer Space, OilRig downloaded additional tools to comrpomised infrastructure. |
| T1217 Browser Information Discovery |
During Outer Space, OilRig used a Chrome data dumper named MKG. |
| T1584.004 Server |
During Outer Space, OilRig compromised an Israeli human resources site to use as a C2 server. |
| T1585.003 Cloud Accounts |
During Outer Space, OilRig created M365 email accounts to be used as part of C2. |
| T1587.001 Malware |
For Outer Space, OilRig created new implants including the Solar backdoor. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.