OilCheck

S1171

Malware.View on attack.mitre.org

About this malware

OilCheck is a C#/.NET downloader that has been used by OilRig since at least 2022 including against targets in Israel. OilCheck uses draft messages created in a shared email account for C2 communication.

Techniques used3

Procedure examples3

TechniqueProcedure example
T1102.002
Bidirectional Communication

OilCheck can use a REST-based Microsoft Graph API to access draft messages in a shared Microsoft Office 365 Outlook email account used for C2 communication.

T1105
Ingress Tool Transfer

OilCheck can download staged payloads from an actor-controlled infrastructure.

T1567
Exfiltration Over Web Service

OilCheck can upload documents from compromised hosts to a shared Microsoft Office 365 Outlook email account for exfiltration.

Groups that use it1

Campaigns0

None recorded.

References1

  1. ESET OilRig Downloaders DEC 2023 Open source
    Hromcova, Z. and Burgher, A. (2023, December 14). OilRig’s persistent attacks using cloud service-powered downloaders. Retrieved November 26, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.