Mango

S1169

Malware.View on attack.mitre.org

About this malware

Mango is a first-stage backdoor written in C#/.NET that was used by OilRig during the Juicy Mix campaign. Mango is the successor to Solar and includes additional exfiltration capabilities, the use of native APIs, and added detection evasion code.

Techniques used13

Procedure examples13

TechniqueProcedure example
T1027.013
Encrypted/Encoded File

Mango contains a series of base64 encoded substrings.

T1033
System Owner/User Discovery

Mango can collect the user name from a compromised system which is used to create a unique victim identifier.

T1041
Exfiltration Over C2 Channel

Mango can use its HTTP C2 channel for exfiltration.

T1053.005
Scheduled Task

Mango can create a scheduled task to run every 32 seconds to communicate with C2 and execute received commands.

T1071.001
Web Protocols

Mango can retrieve C2 commands sent in HTTP responses.

T1082
System Information Discovery

Mango can collect the machine name of a compromised system which is later used as part of a unique victim identifier.

T1083
File and Directory Discovery

Mango can enumerate the contents of current working or other specified directories.

T1106
Native API

Mango has the ability to use Native APIs.

T1132.001
Standard Encoding

Mango can receive Base64-encoded commands from C2.

T1204.002
Malicious File

Mango has been executed through a Microsoft Word document with a malicious macro.

T1573.001
Symmetric Cryptography

Mango can receive XOR-encrypted commands from C2.

T1573.002
Asymmetric Cryptography

Mango can use TLS to encrypt C2 communications.

T1685
Disable or Modify Tools

Mango contains an unused capability to block endpoint security solutions from loading user-mode code hooks via a DLL in a specified process by using the `UpdateProcThreadAttribute API` to set the `PROC_THREAD_ATTRIBUTE_MITIGATION_POLICY` to `PROCESS_CREATION_MITIGATION_POLICY_BLOCK_NON_MICROSOFT_BINARIES_ALWAYS_ON` for an identified process.

Groups that use it1

Campaigns1

References1

  1. ESET OilRig Campaigns Sep 2023 Open source
    Hromcova, Z. and Burgher, A. (2023, September 21). OilRig’s Outer Space and Juicy Mix: Same ol’ rig, new drill pipes. Retrieved November 21, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.