Hromcova, Z. and Burgher, A. (2023, September 21). OilRig’s Outer Space and Juicy Mix: Same ol’ rig, new drill pipes. Retrieved November 21, 2024.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1020 Automated Exfiltration |
MalwareSolar | Solar can automatically exfitrate files from compromised systems. |
| T1027.013 Encrypted/Encoded File |
CampaignOuter Space | During Outer Space, OilRig deployed VBS droppers with obfuscated strings. |
| T1027.013 Encrypted/Encoded File |
MalwareMango | Mango contains a series of base64 encoded substrings. |
| T1033 System Owner/User Discovery |
MalwareMango | Mango can collect the user name from a compromised system which is used to create a unique victim identifier. |
| T1041 Exfiltration Over C2 Channel |
MalwareMango | Mango can use its HTTP C2 channel for exfiltration. |
| T1041 Exfiltration Over C2 Channel |
MalwareSolar | Solar can send staged files to C2 for exfiltration. |
| T1053.005 Scheduled Task |
MalwareMango | Mango can create a scheduled task to run every 32 seconds to communicate with C2 and execute received commands. |
| T1053.005 Scheduled Task |
CampaignJuicy Mix | During Juicy Mix, OilRig used VBS droppers to schedule tasks for persistence. |
| T1053.005 Scheduled Task |
MalwareSolar | Solar can create scheduled tasks named Earth and Venus, which run every 30 and 40 seconds respectively, to support C2 and exfiltration. |
| T1059.001 PowerShell |
CampaignJuicy Mix | During Juicy Mix, OilRig used a PowerShell script to steal credentials. |
| T1059.003 Windows Command Shell |
MalwareSampleCheck5000 | SampleCheck5000 can call cmd.exe to execute C2 command line strings. |
| T1059.005 Visual Basic |
CampaignJuicy Mix | During Juicy Mix, OilRig used VBS droppers to deliver and establish persistence for the Mango backdoor. |
| T1059.005 Visual Basic |
CampaignOuter Space | During Outer Space, OilRig used VBS droppers to deploy malware. |
| T1070.004 File Deletion |
MalwareSolar | Solar has the ability to delete staged files after they are uploaded to C2. |
| T1071.001 Web Protocols |
CampaignJuicy Mix | During Juicy Mix, OilRig used a VBS script to send POST requests to register installed malware with C2. |
| T1071.001 Web Protocols |
CampaignOuter Space | During Outer Space, OilRig used HTTP to communicate between installed backdoors and compromised servers including via the Microsoft Exchange Web Services API. |
| T1071.001 Web Protocols |
MalwareMango | Mango can retrieve C2 commands sent in HTTP responses. |
| T1074.001 Local Data Staging |
CampaignJuicy Mix | During Juicy Mix, OilRig used browser data and credential stealer tools to stage stolen files named Cupdate, Eupdate, and IUpdate in the %TEMP% directory. |
| T1082 System Information Discovery |
MalwareSolar | Solar can send basic information about the infected host to C2. |
| T1082 System Information Discovery |
MalwareMango | Mango can collect the machine name of a compromised system which is later used as part of a unique victim identifier. |
| T1082 System Information Discovery |
CampaignJuicy Mix | During Juicy Mix, OilRig used a script to send the name of the compromised host via HTTP `POST` to register it with C2. |
| T1083 File and Directory Discovery |
MalwareMango | Mango can enumerate the contents of current working or other specified directories. |
| T1102.002 Bidirectional Communication |
MalwareSampleCheck5000 | SampleCheck5000 can use the Microsoft Office Exchange Web Services API to access an actor-controlled account and retrieve C2 commands and payloads placed in Draft messages. |
| T1105 Ingress Tool Transfer |
MalwareSolar | Solar has the ability to download and execute files. |
| T1105 Ingress Tool Transfer |
CampaignOuter Space | During Outer Space, OilRig downloaded additional tools to comrpomised infrastructure. |
| T1105 Ingress Tool Transfer |
MalwareSampleCheck5000 | SampleCheck5000 can download additional payloads to compromised hosts. |
| T1106 Native API |
MalwareMango | Mango has the ability to use Native APIs. |
| T1132.001 Standard Encoding |
CampaignJuicy Mix | During Juicy Mix, OilRig used a VBS script to send the Base64-encoded name of the compromised computer to C2. |
| T1132.001 Standard Encoding |
MalwareMango | Mango can receive Base64-encoded commands from C2. |
| T1132.001 Standard Encoding |
MalwareSolar | Solar can Base64-encode and gzip compress C2 communications including command outputs. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareSampleCheck5000 | SampleCheck5000 can decode and decrypt command line strings and files received through C2. |
| T1140 Deobfuscate/Decode Files or Information |
CampaignJuicy Mix | During Juicy Mix, OilRig used a script to concatenate and deobfuscate encoded strings in Mango. |
| T1204.002 Malicious File |
MalwareMango | Mango has been executed through a Microsoft Word document with a malicious macro. |
| T1217 Browser Information Discovery |
CampaignOuter Space | During Outer Space, OilRig used a Chrome data dumper named MKG. |
| T1217 Browser Information Discovery |
CampaignJuicy Mix | During Juicy Mix, OilRig used the CDumper (Chrome browser) and EDumper (Edge browser) data stealers to collect cookies, browsing history, and credentials. |
| T1518 Software Discovery |
CampaignJuicy Mix | During Juicy Mix, OilRig used browser data dumper tools to create a list of users with Google Chrome installed. |
| T1555.003 Credentials from Web Browsers |
CampaignJuicy Mix | During Juicy Mix, OilRig used the CDumper (Chrome browser) and EDumper (Edge browser) to collect credentials. |
| T1555.004 Windows Credential Manager |
CampaignJuicy Mix | During Juicy Mix, OilRig used a Windows Credential Manager stealer for credential access. |
| T1567 Exfiltration Over Web Service |
MalwareSampleCheck5000 | SampleCheck5000 can use the Microsoft Office Exchange Web Services API to access an actor-controlled account and retrieve files for exfiltration. |
| T1573.001 Symmetric Cryptography |
MalwareMango | Mango can receive XOR-encrypted commands from C2. |
| T1573.001 Symmetric Cryptography |
MalwareSolar | Solar can XOR encrypt C2 communications. |
| T1573.002 Asymmetric Cryptography |
MalwareMango | Mango can use TLS to encrypt C2 communications. |
| T1584.004 Server |
CampaignJuicy Mix | During Juicy Mix, OilRig compromised an Israeli job portal to use for a C2 server. |
| T1584.004 Server |
CampaignOuter Space | During Outer Space, OilRig compromised an Israeli human resources site to use as a C2 server. |
| T1585.003 Cloud Accounts |
CampaignOuter Space | During Outer Space, OilRig created M365 email accounts to be used as part of C2. |
| T1587.001 Malware |
CampaignOuter Space | For Outer Space, OilRig created new implants including the Solar backdoor. |
| T1587.001 Malware |
CampaignJuicy Mix | For Juicy Mix, OilRig improved on Solar by developing the Mango backdoor. |
| T1685 Disable or Modify Tools |
MalwareMango | Mango contains an unused capability to block endpoint security solutions from loading user-mode code hooks via a DLL in a specified process by using the `UpdateProcThreadAttribute API` to set the `PROC_THREAD_ATTRIBUTE_MITIGATION_POLICY` to `PROCESS_CREATION_MITIGATION_POLICY_BLOCK_NON_MICROSOFT_BINARIES_ALWAYS_ON` for an identified process. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.