Solar

S1166

Malware.View on attack.mitre.org

About this malware

Solar is a C#/.NET backdoor that was used by OilRig during the Outer Space campaign to download, execute, and exfiltrate files.

Techniques used8

Procedure examples8

TechniqueProcedure example
T1020
Automated Exfiltration

Solar can automatically exfitrate files from compromised systems.

T1041
Exfiltration Over C2 Channel

Solar can send staged files to C2 for exfiltration.

T1053.005
Scheduled Task

Solar can create scheduled tasks named Earth and Venus, which run every 30 and 40 seconds respectively, to support C2 and exfiltration.

T1070.004
File Deletion

Solar has the ability to delete staged files after they are uploaded to C2.

T1082
System Information Discovery

Solar can send basic information about the infected host to C2.

T1105
Ingress Tool Transfer

Solar has the ability to download and execute files.

T1132.001
Standard Encoding

Solar can Base64-encode and gzip compress C2 communications including command outputs.

T1573.001
Symmetric Cryptography

Solar can XOR encrypt C2 communications.

Groups that use it1

Campaigns1

References1

  1. ESET OilRig Campaigns Sep 2023 Open source
    Hromcova, Z. and Burgher, A. (2023, September 21). OilRig’s Outer Space and Juicy Mix: Same ol’ rig, new drill pipes. Retrieved November 21, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.