Falcone, R. and Lee, B.. (2016, May 26). The OilRig Campaign: Attacks on Saudi Arabian Organizations Deliver Helminth Backdoor. Retrieved May 3, 2017.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1007 System Service Discovery |
GroupOilRig | OilRig has used |
| T1012 Query Registry |
GroupOilRig | OilRig has used |
| T1016 System Network Configuration Discovery |
GroupOilRig | OilRig has run |
| T1027.013 Encrypted/Encoded File |
MalwareHelminth | The Helminth config file is encrypted with RC4. |
| T1030 Data Transfer Size Limits |
MalwareHelminth | Helminth splits data into chunks up to 23 bytes and sends the data in DNS queries to its C2 server. |
| T1033 System Owner/User Discovery |
GroupOilRig | OilRig has run |
| T1049 System Network Connections Discovery |
GroupOilRig | OilRig has used |
| T1056.001 Keylogging |
MalwareHelminth | The executable version of Helminth has a module to log keystrokes. |
| T1057 Process Discovery |
GroupOilRig | OilRig has run |
| T1059.001 PowerShell |
MalwareHelminth | One version of Helminth uses a PowerShell script. |
| T1059.003 Windows Command Shell |
MalwareHelminth | Helminth can provide a remote shell. One version of Helminth uses batch scripting. |
| T1059.005 Visual Basic |
MalwareHelminth | One version of Helminth consists of VBScript scripts. |
| T1069.001 Local Groups |
GroupOilRig | OilRig has used |
| T1069.002 Domain Groups |
GroupOilRig | OilRig has used |
| T1071.001 Web Protocols |
MalwareHelminth | Helminth can use HTTP for C2. |
| T1071.004 DNS |
MalwareHelminth | Helminth can use DNS for C2. |
| T1074.001 Local Data Staging |
MalwareHelminth | Helminth creates folders to store output from batch scripts prior to sending the information to its C2 server. |
| T1082 System Information Discovery |
GroupOilRig | OilRig has run |
| T1087.001 Local Account |
GroupOilRig | OilRig has run |
| T1087.002 Domain Account |
GroupOilRig | OilRig has run |
| T1105 Ingress Tool Transfer |
MalwareHelminth | Helminth can download additional files. |
| T1115 Clipboard Data |
MalwareHelminth | The executable version of Helminth has a module to log clipboard contents. |
| T1119 Automated Collection |
MalwareHelminth | A Helminth VBScript receives a batch script to execute a set of commands in a command prompt. |
| T1132.001 Standard Encoding |
MalwareHelminth | For C2 over HTTP, Helminth encodes data with base64 and sends it via the "Cookie" field of HTTP requests. For C2 over DNS, Helminth converts ASCII characters into their hexadecimal values and sends the data in cleartext. |
| T1218.001 Compiled HTML File |
GroupOilRig | OilRig has used a CHM payload to load and execute another malicious file once delivered to a victim. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareHelminth | Helminth establishes persistence by creating a shortcut in the Start Menu folder. |
| T1547.009 Shortcut Modification |
MalwareHelminth | Helminth establishes persistence by creating a shortcut. |
| T1573.001 Symmetric Cryptography |
MalwareHelminth | Helminth encrypts data sent to its C2 server over HTTP with RC4. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.