Grunzweig, J. and Falcone, R.. (2016, October 4). OilRig Malware Campaign Updates Toolset and Expands Targets. Retrieved May 3, 2017.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
GroupOilRig | OilRig has run |
| T1033 System Owner/User Discovery |
GroupOilRig | OilRig has run |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
GroupOilRig | OilRig has exfiltrated data via Microsoft Exchange and over FTP separately from its primary C2 channel over DNS. |
| T1082 System Information Discovery |
GroupOilRig | OilRig has run |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.