ATT&CKReferencesPalo Alto OilRig Sep 2018

Palo Alto OilRig Sep 2018

Wilhoit, K. and Falcone, R. (2018, September 12). OilRig Uses Updated BONDUPDATER to Target Middle Eastern Government. Retrieved February 18, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples5

TechniqueUsed byProcedure example
T1053.005
Scheduled Task
MalwareBONDUPDATER

BONDUPDATER persists using a scheduled task that executes every minute.

T1059.001
PowerShell
MalwareBONDUPDATER

BONDUPDATER is written in PowerShell.

T1059.003
Windows Command Shell
MalwareBONDUPDATER

BONDUPDATER can read batch commands in a file sent from its C2 server and execute them with cmd.exe.

T1071.004
DNS
MalwareBONDUPDATER

BONDUPDATER can use DNS and TXT records within its DNS tunneling protocol for command and control.

T1105
Ingress Tool Transfer
MalwareBONDUPDATER

BONDUPDATER can download or upload files from its C2 server.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.