OilRig

G0049

Threat group.View on attack.mitre.org

About this group

OilRig is a suspected Iranian threat group that has targeted Middle Eastern and international victims since at least 2014. The group has targeted a variety of sectors, including financial, government, energy, chemical, and telecommunications. It appears the group carries out supply chain attacks, leveraging the trust relationship between organizations to attack their primary targets. The group works on behalf of the Iranian government based on infrastructure details that contain references to Iran, use of Iranian infrastructure, and targeting that aligns with nation-state interests.

Techniques used76

Procedure examples76

TechniqueProcedure example
T1003.001
LSASS Memory

OilRig has used credential dumping tools such as Mimikatz to steal credentials to accounts logged into the compromised system and to Outlook Web Access.

T1003.004
LSA Secrets

OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access.

T1003.005
Cached Domain Credentials

OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access.

T1005
Data from Local System

OilRig has used PowerShell to upload files from compromised systems.

T1007
System Service Discovery

OilRig has used sc query on a victim to gather information about services.

T1008
Fallback Channels

OilRig malware ISMAgent falls back to its DNS tunneling mechanism if it is unable to reach the C2 server over HTTP.

T1012
Query Registry

OilRig has used reg query “HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client\Default” on a victim to query the Registry.

T1016
System Network Configuration Discovery

OilRig has run ipconfig /all on a victim.

T1021.001
Remote Desktop Protocol

OilRig has used Remote Desktop Protocol for lateral movement. The group has also used tunneling tools to tunnel RDP into the environment.

T1021.004
SSH

OilRig has used Putty to access compromised systems.

T1025
Data from Removable Media

OilRig has used Wireshark’s usbcapcmd utility to capture USB traffic.

T1027.005
Indicator Removal from Tools

OilRig has tested malware samples to determine AV detection and subsequently modified the samples to ensure AV evasion.

T1027.013
Encrypted/Encoded File

OilRig has encrypted and encoded data in its malware, including by using base64.

T1033
System Owner/User Discovery

OilRig has run whoami on a victim.

T1036
Masquerading

OilRig has used .doc file extensions to mask malicious executables.

View all 76 procedure examples

Software30

Show 6 more

Campaigns2

References7

  1. ClearSky OilRig Jan 2017 Open source
    ClearSky Cybersecurity. (2017, January 5). Iranian Threat Agent OilRig Delivers Digitally Signed Malware, Impersonates University of Oxford. Retrieved May 3, 2017.
  2. FireEye APT34 Dec 2017 Open source
    Sardiwal, M, et al. (2017, December 7). New Targeted Attack in the Middle East by APT34, a Suspected Iranian Threat Group, Using CVE-2017-11882 Exploit. Retrieved December 20, 2017.
  3. Palo Alto OilRig April 2017 Open source
    Falcone, R.. (2017, April 27). OilRig Actors Provide a Glimpse into Development and Testing Efforts. Retrieved May 3, 2017.
  4. Palo Alto OilRig May 2016 Open source
    Falcone, R. and Lee, B.. (2016, May 26). The OilRig Campaign: Attacks on Saudi Arabian Organizations Deliver Helminth Backdoor. Retrieved May 3, 2017.
  5. Palo Alto OilRig Oct 2016 Open source
    Grunzweig, J. and Falcone, R.. (2016, October 4). OilRig Malware Campaign Updates Toolset and Expands Targets. Retrieved May 3, 2017.
  6. Unit 42 QUADAGENT July 2018 Open source
    Lee, B., Falcone, R. (2018, July 25). OilRig Targets Technology Service Provider and Government Agency with QUADAGENT. Retrieved August 9, 2018.
  7. Unit42 OilRig Playbook 2023 Open source
    Unit42. (2016, May 1). Evasive Serpens Unit 42 Playbook Viewer. Retrieved February 6, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.