Hromcova, Z. and Burgher, A. (2023, December 14). OilRig’s persistent attacks using cloud service-powered downloaders. Retrieved November 26, 2024.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1008 Fallback Channels |
MalwareOilBooster | OilBooster can use a backup channel to request a new refresh token from its C2 server after 10 consecutive unsuccessful connections to the primary OneDrive C2 server. |
| T1033 System Owner/User Discovery |
MalwareOilBooster | OilBooster can identify the compromised system's username which is then used as part of a unique identifier. |
| T1041 Exfiltration Over C2 Channel |
MalwareOilBooster | OilBooster can use an actor-controlled OneDrive account for C2 communication and exfiltration. |
| T1041 Exfiltration Over C2 Channel |
MalwareODAgent | ODAgent can use an attacker-controlled OneDrive account to receive C2 commands and to exfiltrate files. |
| T1059.003 Windows Command Shell |
MalwareOilBooster | OilBooster has the ability to execute shell commands and exfiltrate the results. |
| T1059.003 Windows Command Shell |
MalwareSampleCheck5000 | SampleCheck5000 can call cmd.exe to execute C2 command line strings. |
| T1059.003 Windows Command Shell |
MalwareODAgent | ODAgent can execute a specified command line passed via API. |
| T1070.004 File Deletion |
MalwareODAgent | ODAgent can delete payloads and files used to pass C2 commands from remotely hosted cloud accounts. |
| T1071.001 Web Protocols |
MalwareOilBooster | OilBooster can send HTTP `GET`, `POST`, `PUT`, and `DELETE` requests to the Microsoft Graph API over port 443 for C2 communication. |
| T1071.001 Web Protocols |
MalwareSampleCheck5000 | SampleCheck5000 can use the Exchange Web Services API for C2 communication. |
| T1074.001 Local Data Staging |
MalwareSampleCheck5000 | SampleCheck5000 can log the output from C2 commands in an encrypted and compressed format on disk prior to exfiltration. |
| T1074.001 Local Data Staging |
MalwareOilBooster | OilBooster can stage files in the `tempFiles` directory for exfiltration. |
| T1082 System Information Discovery |
MalwareOilBooster | OilBooster can identify the compromised system's hostname which is used to create a unique identifier. |
| T1082 System Information Discovery |
MalwareSampleCheck5000 | SampleCheck5000 can create unique victim identifiers by using the compromised system’s computer name. |
| T1083 File and Directory Discovery |
MalwareODAgent | ODAgent can identify the current working directory. |
| T1102.002 Bidirectional Communication |
MalwareSampleCheck5000 | SampleCheck5000 can use the Microsoft Office Exchange Web Services API to access an actor-controlled account and retrieve C2 commands and payloads placed in Draft messages. |
| T1102.002 Bidirectional Communication |
MalwareOilCheck | OilCheck can use a REST-based Microsoft Graph API to access draft messages in a shared Microsoft Office 365 Outlook email account used for C2 communication. |
| T1102.002 Bidirectional Communication |
MalwareODAgent | ODAgent can use the Microsoft Graph API to access an attacker-controlled OneDrive account and retrieve payloads and backdoor commands. |
| T1102.002 Bidirectional Communication |
MalwareOilBooster | OilBooster uses the Microsoft Graph API to connect to an actor-controlled OneDrive account to download and execute files and shell commands, and to create directories to share exfiltrated data. |
| T1105 Ingress Tool Transfer |
MalwareOilBooster | OilBooster can download and execute files from an actor-controlled OneDrive account. |
| T1105 Ingress Tool Transfer |
MalwareODAgent | ODAgent has the ability to download and execute files on compromised systems. |
| T1105 Ingress Tool Transfer |
MalwareSampleCheck5000 | SampleCheck5000 can download additional payloads to compromised hosts. |
| T1105 Ingress Tool Transfer |
MalwareOilCheck | OilCheck can download staged payloads from an actor-controlled infrastructure. |
| T1106 Native API |
MalwareODAgent | ODAgent can pass commands using native APIs. |
| T1106 Native API |
MalwareOilBooster | OilBooster has used the `ShowWindow` and `CreateProcessW` APIs. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareOilBooster | OilBooster can Base64-decode and XOR-decrypt C2 commands taken from JSON files. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareODAgent | ODAgent can Base64-decode and XOR decrypt received C2 commands. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareSampleCheck5000 | SampleCheck5000 can decode and decrypt command line strings and files received through C2. |
| T1559 Inter-Process Communication |
MalwareOilBooster | OilBooster can read the results of command line execution via an unnamed pipe connected to the process. |
| T1560.001 Archive via Utility |
MalwareSampleCheck5000 | SampleCheck5000 can gzip compress files uploaded to a shared mailbox used for C2 and exfiltration. |
| T1564.003 Hidden Window |
MalwareOilBooster | OilBooster can hide its console window upon execution through the `ShowWindow` API. |
| T1567 Exfiltration Over Web Service |
MalwareSampleCheck5000 | SampleCheck5000 can use the Microsoft Office Exchange Web Services API to access an actor-controlled account and retrieve files for exfiltration. |
| T1567 Exfiltration Over Web Service |
MalwareOilCheck | OilCheck can upload documents from compromised hosts to a shared Microsoft Office 365 Outlook email account for exfiltration. |
| T1567.002 Exfiltration to Cloud Storage |
MalwareODAgent | ODAgent can use an attacker-controlled OneDrive account for exfiltration. |
| T1567.002 Exfiltration to Cloud Storage |
MalwareOilBooster | OilBooster can exfiltrate files to an actor-controlled OneDrive account via the Microsoft Graph API. |
| T1573.002 Asymmetric Cryptography |
MalwareOilBooster | OilBooster can use the OpenSSL library to encrypt C2 communications. |
| T1587.001 Malware |
GroupOilRig | OilRig actively developed and used a series of downloaders during 2022. |
| T1680 Local Storage Discovery |
MalwareSampleCheck5000 | SampleCheck5000 can create unique victim identifiers by using the compromised system’s volume ID. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.