ATT&CKReferencesESET OilRig Campaigns Sep 2023

ESET OilRig Campaigns Sep 2023

Hromcova, Z. and Burgher, A. (2023, September 21). OilRig’s Outer Space and Juicy Mix: Same ol’ rig, new drill pipes. Retrieved November 21, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software3

Campaigns2

Procedure examples48

TechniqueUsed byProcedure example
T1020
Automated Exfiltration
MalwareSolar

Solar can automatically exfitrate files from compromised systems.

T1027.013
Encrypted/Encoded File
CampaignOuter Space

During Outer Space, OilRig deployed VBS droppers with obfuscated strings.

T1027.013
Encrypted/Encoded File
MalwareMango

Mango contains a series of base64 encoded substrings.

T1033
System Owner/User Discovery
MalwareMango

Mango can collect the user name from a compromised system which is used to create a unique victim identifier.

T1041
Exfiltration Over C2 Channel
MalwareMango

Mango can use its HTTP C2 channel for exfiltration.

T1041
Exfiltration Over C2 Channel
MalwareSolar

Solar can send staged files to C2 for exfiltration.

T1053.005
Scheduled Task
MalwareMango

Mango can create a scheduled task to run every 32 seconds to communicate with C2 and execute received commands.

T1053.005
Scheduled Task
CampaignJuicy Mix

During Juicy Mix, OilRig used VBS droppers to schedule tasks for persistence.

T1053.005
Scheduled Task
MalwareSolar

Solar can create scheduled tasks named Earth and Venus, which run every 30 and 40 seconds respectively, to support C2 and exfiltration.

T1059.001
PowerShell
CampaignJuicy Mix

During Juicy Mix, OilRig used a PowerShell script to steal credentials.

T1059.003
Windows Command Shell
MalwareSampleCheck5000

SampleCheck5000 can call cmd.exe to execute C2 command line strings.

T1059.005
Visual Basic
CampaignJuicy Mix

During Juicy Mix, OilRig used VBS droppers to deliver and establish persistence for the Mango backdoor.

T1059.005
Visual Basic
CampaignOuter Space

During Outer Space, OilRig used VBS droppers to deploy malware.

T1070.004
File Deletion
MalwareSolar

Solar has the ability to delete staged files after they are uploaded to C2.

T1071.001
Web Protocols
CampaignJuicy Mix

During Juicy Mix, OilRig used a VBS script to send POST requests to register installed malware with C2.

T1071.001
Web Protocols
CampaignOuter Space

During Outer Space, OilRig used HTTP to communicate between installed backdoors and compromised servers including via the Microsoft Exchange Web Services API.

T1071.001
Web Protocols
MalwareMango

Mango can retrieve C2 commands sent in HTTP responses.

T1074.001
Local Data Staging
CampaignJuicy Mix

During Juicy Mix, OilRig used browser data and credential stealer tools to stage stolen files named Cupdate, Eupdate, and IUpdate in the %TEMP% directory.

T1082
System Information Discovery
MalwareSolar

Solar can send basic information about the infected host to C2.

T1082
System Information Discovery
MalwareMango

Mango can collect the machine name of a compromised system which is later used as part of a unique victim identifier.

T1082
System Information Discovery
CampaignJuicy Mix

During Juicy Mix, OilRig used a script to send the name of the compromised host via HTTP `POST` to register it with C2.

T1083
File and Directory Discovery
MalwareMango

Mango can enumerate the contents of current working or other specified directories.

T1102.002
Bidirectional Communication
MalwareSampleCheck5000

SampleCheck5000 can use the Microsoft Office Exchange Web Services API to access an actor-controlled account and retrieve C2 commands and payloads placed in Draft messages.

T1105
Ingress Tool Transfer
MalwareSolar

Solar has the ability to download and execute files.

T1105
Ingress Tool Transfer
CampaignOuter Space

During Outer Space, OilRig downloaded additional tools to comrpomised infrastructure.

T1105
Ingress Tool Transfer
MalwareSampleCheck5000

SampleCheck5000 can download additional payloads to compromised hosts.

T1106
Native API
MalwareMango

Mango has the ability to use Native APIs.

T1132.001
Standard Encoding
CampaignJuicy Mix

During Juicy Mix, OilRig used a VBS script to send the Base64-encoded name of the compromised computer to C2.

T1132.001
Standard Encoding
MalwareMango

Mango can receive Base64-encoded commands from C2.

T1132.001
Standard Encoding
MalwareSolar

Solar can Base64-encode and gzip compress C2 communications including command outputs.

T1140
Deobfuscate/Decode Files or Information
MalwareSampleCheck5000

SampleCheck5000 can decode and decrypt command line strings and files received through C2.

T1140
Deobfuscate/Decode Files or Information
CampaignJuicy Mix

During Juicy Mix, OilRig used a script to concatenate and deobfuscate encoded strings in Mango.

T1204.002
Malicious File
MalwareMango

Mango has been executed through a Microsoft Word document with a malicious macro.

T1217
Browser Information Discovery
CampaignOuter Space

During Outer Space, OilRig used a Chrome data dumper named MKG.

T1217
Browser Information Discovery
CampaignJuicy Mix

During Juicy Mix, OilRig used the CDumper (Chrome browser) and EDumper (Edge browser) data stealers to collect cookies, browsing history, and credentials.

T1518
Software Discovery
CampaignJuicy Mix

During Juicy Mix, OilRig used browser data dumper tools to create a list of users with Google Chrome installed.

T1555.003
Credentials from Web Browsers
CampaignJuicy Mix

During Juicy Mix, OilRig used the CDumper (Chrome browser) and EDumper (Edge browser) to collect credentials.

T1555.004
Windows Credential Manager
CampaignJuicy Mix

During Juicy Mix, OilRig used a Windows Credential Manager stealer for credential access.

T1567
Exfiltration Over Web Service
MalwareSampleCheck5000

SampleCheck5000 can use the Microsoft Office Exchange Web Services API to access an actor-controlled account and retrieve files for exfiltration.

T1573.001
Symmetric Cryptography
MalwareMango

Mango can receive XOR-encrypted commands from C2.

T1573.001
Symmetric Cryptography
MalwareSolar

Solar can XOR encrypt C2 communications.

T1573.002
Asymmetric Cryptography
MalwareMango

Mango can use TLS to encrypt C2 communications.

T1584.004
Server
CampaignJuicy Mix

During Juicy Mix, OilRig compromised an Israeli job portal to use for a C2 server.

T1584.004
Server
CampaignOuter Space

During Outer Space, OilRig compromised an Israeli human resources site to use as a C2 server.

T1585.003
Cloud Accounts
CampaignOuter Space

During Outer Space, OilRig created M365 email accounts to be used as part of C2.

T1587.001
Malware
CampaignOuter Space

For Outer Space, OilRig created new implants including the Solar backdoor.

T1587.001
Malware
CampaignJuicy Mix

For Juicy Mix, OilRig improved on Solar by developing the Mango backdoor.

T1685
Disable or Modify Tools
MalwareMango

Mango contains an unused capability to block endpoint security solutions from loading user-mode code hooks via a DLL in a specified process by using the `UpdateProcThreadAttribute API` to set the `PROC_THREAD_ATTRIBUTE_MITIGATION_POLICY` to `PROCESS_CREATION_MITIGATION_POLICY_BLOCK_NON_MICROSOFT_BINARIES_ALWAYS_ON` for an identified process.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.