RDAT

S0495

Malware.View on attack.mitre.org

About this malware

RDAT is a backdoor used by the suspected Iranian threat group OilRig. RDAT was originally identified in 2017 and targeted companies in the telecommunications sector.

Techniques used20

Procedure examples20

TechniqueProcedure example
T1001
Data Obfuscation

RDAT has used encoded data within subdomains as AES ciphertext to communicate from the host to the C2.

T1001.002
Steganography

RDAT can process steganographic images attached to email messages to send and receive C2 commands. RDAT can also embed additional messages within BMP images to communicate with the RDAT operator.

T1008
Fallback Channels

RDAT has used HTTP if DNS C2 communications were not functioning.

T1027.003
Steganography

RDAT can also embed data within a BMP image prior to exfiltration.

T1030
Data Transfer Size Limits

RDAT can upload a file via HTTP POST response to the C2 split into 102,400-byte portions. RDAT can also download data from the C2 which is split into 81,920-byte portions.

T1036.004
Masquerade Task or Service

RDAT has used Windows Video Service as a name for malicious services.

T1036.005
Match Legitimate Resource Name or Location

RDAT has masqueraded as VMware.exe.

T1041
Exfiltration Over C2 Channel

RDAT can exfiltrate data gathered from the infected system via the established Exchange Web Services API C2 channel.

T1059.003
Windows Command Shell

RDAT has executed commands using cmd.exe /c.

T1070.004
File Deletion

RDAT can issue SOAP requests to delete already processed C2 emails. RDAT can also delete itself from the infected system.

T1071.001
Web Protocols

RDAT can use HTTP communications for C2, as well as using the WinHTTP library to make requests to the Exchange Web Services API.

T1071.003
Mail Protocols

RDAT can use email attachments for C2 communications.

T1071.004
DNS

RDAT has used DNS to communicate with the C2.

T1105
Ingress Tool Transfer

RDAT can download files via DNS.

T1113
Screen Capture

RDAT can take a screenshot on the infected system.

View all 20 procedure examples

Groups that use it1

Campaigns0

None recorded.

References1

  1. Unit42 RDAT July 2020 Open source
    Falcone, R. (2020, July 22). OilRig Targets Middle Eastern Telecommunications Organization and Adds Novel C2 Channel with Steganography to Its Inventory. Retrieved July 28, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.