ATT&CKReferencesESET OilRig Downloaders DEC 2023

ESET OilRig Downloaders DEC 2023

Hromcova, Z. and Burgher, A. (2023, December 14). OilRig’s persistent attacks using cloud service-powered downloaders. Retrieved November 26, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software4

Campaigns0

None recorded.

Procedure examples38

TechniqueUsed byProcedure example
T1008
Fallback Channels
MalwareOilBooster

OilBooster can use a backup channel to request a new refresh token from its C2 server after 10 consecutive unsuccessful connections to the primary OneDrive C2 server.

T1033
System Owner/User Discovery
MalwareOilBooster

OilBooster can identify the compromised system's username which is then used as part of a unique identifier.

T1041
Exfiltration Over C2 Channel
MalwareOilBooster

OilBooster can use an actor-controlled OneDrive account for C2 communication and exfiltration.

T1041
Exfiltration Over C2 Channel
MalwareODAgent

ODAgent can use an attacker-controlled OneDrive account to receive C2 commands and to exfiltrate files.

T1059.003
Windows Command Shell
MalwareOilBooster

OilBooster has the ability to execute shell commands and exfiltrate the results.

T1059.003
Windows Command Shell
MalwareSampleCheck5000

SampleCheck5000 can call cmd.exe to execute C2 command line strings.

T1059.003
Windows Command Shell
MalwareODAgent

ODAgent can execute a specified command line passed via API.

T1070.004
File Deletion
MalwareODAgent

ODAgent can delete payloads and files used to pass C2 commands from remotely hosted cloud accounts.

T1071.001
Web Protocols
MalwareOilBooster

OilBooster can send HTTP `GET`, `POST`, `PUT`, and `DELETE` requests to the Microsoft Graph API over port 443 for C2 communication.

T1071.001
Web Protocols
MalwareSampleCheck5000

SampleCheck5000 can use the Exchange Web Services API for C2 communication.

T1074.001
Local Data Staging
MalwareSampleCheck5000

SampleCheck5000 can log the output from C2 commands in an encrypted and compressed format on disk prior to exfiltration.

T1074.001
Local Data Staging
MalwareOilBooster

OilBooster can stage files in the `tempFiles` directory for exfiltration.

T1082
System Information Discovery
MalwareOilBooster

OilBooster can identify the compromised system's hostname which is used to create a unique identifier.

T1082
System Information Discovery
MalwareSampleCheck5000

SampleCheck5000 can create unique victim identifiers by using the compromised system’s computer name.

T1083
File and Directory Discovery
MalwareODAgent

ODAgent can identify the current working directory.

T1102.002
Bidirectional Communication
MalwareSampleCheck5000

SampleCheck5000 can use the Microsoft Office Exchange Web Services API to access an actor-controlled account and retrieve C2 commands and payloads placed in Draft messages.

T1102.002
Bidirectional Communication
MalwareOilCheck

OilCheck can use a REST-based Microsoft Graph API to access draft messages in a shared Microsoft Office 365 Outlook email account used for C2 communication.

T1102.002
Bidirectional Communication
MalwareODAgent

ODAgent can use the Microsoft Graph API to access an attacker-controlled OneDrive account and retrieve payloads and backdoor commands.

T1102.002
Bidirectional Communication
MalwareOilBooster

OilBooster uses the Microsoft Graph API to connect to an actor-controlled OneDrive account to download and execute files and shell commands, and to create directories to share exfiltrated data.

T1105
Ingress Tool Transfer
MalwareOilBooster

OilBooster can download and execute files from an actor-controlled OneDrive account.

T1105
Ingress Tool Transfer
MalwareODAgent

ODAgent has the ability to download and execute files on compromised systems.

T1105
Ingress Tool Transfer
MalwareSampleCheck5000

SampleCheck5000 can download additional payloads to compromised hosts.

T1105
Ingress Tool Transfer
MalwareOilCheck

OilCheck can download staged payloads from an actor-controlled infrastructure.

T1106
Native API
MalwareODAgent

ODAgent can pass commands using native APIs.

T1106
Native API
MalwareOilBooster

OilBooster has used the `ShowWindow` and `CreateProcessW` APIs.

T1140
Deobfuscate/Decode Files or Information
MalwareOilBooster

OilBooster can Base64-decode and XOR-decrypt C2 commands taken from JSON files.

T1140
Deobfuscate/Decode Files or Information
MalwareODAgent

ODAgent can Base64-decode and XOR decrypt received C2 commands.

T1140
Deobfuscate/Decode Files or Information
MalwareSampleCheck5000

SampleCheck5000 can decode and decrypt command line strings and files received through C2.

T1559
Inter-Process Communication
MalwareOilBooster

OilBooster can read the results of command line execution via an unnamed pipe connected to the process.

T1560.001
Archive via Utility
MalwareSampleCheck5000

SampleCheck5000 can gzip compress files uploaded to a shared mailbox used for C2 and exfiltration.

T1564.003
Hidden Window
MalwareOilBooster

OilBooster can hide its console window upon execution through the `ShowWindow` API.

T1567
Exfiltration Over Web Service
MalwareSampleCheck5000

SampleCheck5000 can use the Microsoft Office Exchange Web Services API to access an actor-controlled account and retrieve files for exfiltration.

T1567
Exfiltration Over Web Service
MalwareOilCheck

OilCheck can upload documents from compromised hosts to a shared Microsoft Office 365 Outlook email account for exfiltration.

T1567.002
Exfiltration to Cloud Storage
MalwareODAgent

ODAgent can use an attacker-controlled OneDrive account for exfiltration.

T1567.002
Exfiltration to Cloud Storage
MalwareOilBooster

OilBooster can exfiltrate files to an actor-controlled OneDrive account via the Microsoft Graph API.

T1573.002
Asymmetric Cryptography
MalwareOilBooster

OilBooster can use the OpenSSL library to encrypt C2 communications.

T1587.001
Malware
GroupOilRig

OilRig actively developed and used a series of downloaders during 2022.

T1680
Local Storage Discovery
MalwareSampleCheck5000

SampleCheck5000 can create unique victim identifiers by using the compromised system’s volume ID.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.