ATT&CKSoftwareISMInjector

ISMInjector

S0189

Malware.View on attack.mitre.org

About this malware

ISMInjector is a Trojan used to install another OilRig backdoor, ISMAgent.

Techniques used4

Procedure examples4

TechniqueProcedure example
T1027
Obfuscated Files or Information

ISMInjector is obfuscated with the off-the-shelf SmartAssembly .NET obfuscator created by red-gate.com.

T1053.005
Scheduled Task

ISMInjector creates scheduled tasks to establish persistence.

T1055.012
Process Hollowing

ISMInjector hollows out a newly created process RegASM.exe and injects its payload into the hollowed process.

T1140
Deobfuscate/Decode Files or Information

ISMInjector uses the certutil command to decode a payload file.

Groups that use it1

Campaigns0

None recorded.

References1

  1. OilRig New Delivery Oct 2017 Open source
    Falcone, R. and Lee, B. (2017, October 9). OilRig Group Steps Up Attacks with New Delivery Documents and New Injector Trojan. Retrieved January 8, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.