ODAgent

S1170

Malware.View on attack.mitre.org

About this malware

ODAgent is a C#/.NET downloader that has been used by OilRig since at least 2022 including against target organizations in Israel to download and execute payloads and to exfiltrate staged files.

Techniques used9

Procedure examples9

TechniqueProcedure example
T1041
Exfiltration Over C2 Channel

ODAgent can use an attacker-controlled OneDrive account to receive C2 commands and to exfiltrate files.

T1059.003
Windows Command Shell

ODAgent can execute a specified command line passed via API.

T1070.004
File Deletion

ODAgent can delete payloads and files used to pass C2 commands from remotely hosted cloud accounts.

T1083
File and Directory Discovery

ODAgent can identify the current working directory.

T1102.002
Bidirectional Communication

ODAgent can use the Microsoft Graph API to access an attacker-controlled OneDrive account and retrieve payloads and backdoor commands.

T1105
Ingress Tool Transfer

ODAgent has the ability to download and execute files on compromised systems.

T1106
Native API

ODAgent can pass commands using native APIs.

T1140
Deobfuscate/Decode Files or Information

ODAgent can Base64-decode and XOR decrypt received C2 commands.

T1567.002
Exfiltration to Cloud Storage

ODAgent can use an attacker-controlled OneDrive account for exfiltration.

Groups that use it1

Campaigns0

None recorded.

References1

  1. ESET OilRig Downloaders DEC 2023 Open source
    Hromcova, Z. and Burgher, A. (2023, December 14). OilRig’s persistent attacks using cloud service-powered downloaders. Retrieved November 26, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.