QUADAGENT

S0269

Malware.View on attack.mitre.org

About this malware

QUADAGENT is a PowerShell backdoor used by OilRig.

Techniques used17

Procedure examples17

TechniqueProcedure example
T1008
Fallback Channels

QUADAGENT uses multiple protocols (HTTPS, HTTP, DNS) for its C2 server as fallback channels if communication with one is unsuccessful.

T1012
Query Registry

QUADAGENT checks if a value exists within a Registry key in the HKCU hive whose name is the same as the scheduled task it has created.

T1016
System Network Configuration Discovery

QUADAGENT gathers the current domain the victim system belongs to.

T1027.010
Command Obfuscation

QUADAGENT was likely obfuscated using `Invoke-Obfuscation`.

T1027.011
Fileless Storage

QUADAGENT stores a session identifier unique to the compromised system as well as a pre-shared key used for encrypting and decrypting C2 communications within a Registry key (such as `HKCU\Office365DCOMCheck`) in the `HKCU` hive.

T1033
System Owner/User Discovery

QUADAGENT gathers the victim username.

T1036.005
Match Legitimate Resource Name or Location

QUADAGENT used the PowerShell filenames Office365DCOMCheck.ps1 and SystemDiskClean.ps1.

T1053.005
Scheduled Task

QUADAGENT creates a scheduled task to maintain persistence on the victim’s machine.

T1059.001
PowerShell

QUADAGENT uses PowerShell scripts for execution.

T1059.003
Windows Command Shell

QUADAGENT uses cmd.exe to execute scripts and commands on the victim’s machine.

T1059.005
Visual Basic

QUADAGENT uses VBScripts.

T1070.004
File Deletion

QUADAGENT has a command to delete its Registry key and scheduled task.

T1071.001
Web Protocols

QUADAGENT uses HTTPS and HTTP for C2 communications.

T1071.004
DNS

QUADAGENT uses DNS for C2 communications.

T1112
Modify Registry

QUADAGENT modifies an HKCU Registry key to store a session identifier unique to the compromised system as well as a pre-shared key used for encrypting and decrypting C2 communications.

View all 17 procedure examples

Groups that use it1

Campaigns0

None recorded.

References1

  1. Unit 42 QUADAGENT July 2018 Open source
    Lee, B., Falcone, R. (2018, July 25). OilRig Targets Technology Service Provider and Government Agency with QUADAGENT. Retrieved August 9, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.