ATT&CKReferencesClearSky OilRig Jan 2017

ClearSky OilRig Jan 2017

ClearSky Cybersecurity. (2017, January 5). Iranian Threat Agent OilRig Delivers Digitally Signed Malware, Impersonates University of Oxford. Retrieved May 3, 2017.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples11

TechniqueUsed byProcedure example
T1053.005
Scheduled Task
MalwareHelminth

Helminth has used a scheduled task for persistence.

T1204.001
Malicious Link
GroupOilRig

OilRig has delivered malicious links to achieve execution on the target system.

T1204.002
Malicious File
GroupOilRig

OilRig has delivered macro-enabled documents that required targets to click the "enable content" button to execute the payload on the system.

T1553.002
Code Signing
GroupOilRig

OilRig has signed its malware with stolen certificates.

T1553.002
Code Signing
MalwareHelminth

Helminth samples have been signed with legitimate, compromised code signing certificates owned by software company AI Squared.

T1566.001
Spearphishing Attachment
GroupOilRig

OilRig has sent spearphising emails with malicious attachments to potential victims using compromised and/or spoofed email accounts.

T1566.002
Spearphishing Link
GroupOilRig

OilRig has sent spearphising emails with malicious links to potential victims.

T1583.001
Domains
GroupOilRig

OilRig has set up fake VPN portals, conference sign ups, and job application websites to target victims.

T1586.002
Email Accounts
GroupOilRig

OilRig has compromised email accounts to send phishing emails.

T1588.003
Code Signing Certificates
GroupOilRig

OilRig has obtained stolen code signing certificates to digitally sign malware.

T1608.001
Upload Malware
GroupOilRig

OilRig has hosted malware on fake websites designed to target specific audiences.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.