ATT&CKSoftwareOilBooster

OilBooster

S1172

Malware.View on attack.mitre.org

About this malware

OilBooster is a downloader written in Microsoft Visual C/C++ that has been used by OilRig since at least 2022 including against target organizations in Israel to download and execute files and for exfiltration.

Techniques used15

Procedure examples15

TechniqueProcedure example
T1008
Fallback Channels

OilBooster can use a backup channel to request a new refresh token from its C2 server after 10 consecutive unsuccessful connections to the primary OneDrive C2 server.

T1033
System Owner/User Discovery

OilBooster can identify the compromised system's username which is then used as part of a unique identifier.

T1041
Exfiltration Over C2 Channel

OilBooster can use an actor-controlled OneDrive account for C2 communication and exfiltration.

T1059.003
Windows Command Shell

OilBooster has the ability to execute shell commands and exfiltrate the results.

T1071.001
Web Protocols

OilBooster can send HTTP `GET`, `POST`, `PUT`, and `DELETE` requests to the Microsoft Graph API over port 443 for C2 communication.

T1074.001
Local Data Staging

OilBooster can stage files in the `tempFiles` directory for exfiltration.

T1082
System Information Discovery

OilBooster can identify the compromised system's hostname which is used to create a unique identifier.

T1102.002
Bidirectional Communication

OilBooster uses the Microsoft Graph API to connect to an actor-controlled OneDrive account to download and execute files and shell commands, and to create directories to share exfiltrated data.

T1105
Ingress Tool Transfer

OilBooster can download and execute files from an actor-controlled OneDrive account.

T1106
Native API

OilBooster has used the `ShowWindow` and `CreateProcessW` APIs.

T1140
Deobfuscate/Decode Files or Information

OilBooster can Base64-decode and XOR-decrypt C2 commands taken from JSON files.

T1559
Inter-Process Communication

OilBooster can read the results of command line execution via an unnamed pipe connected to the process.

T1564.003
Hidden Window

OilBooster can hide its console window upon execution through the `ShowWindow` API.

T1567.002
Exfiltration to Cloud Storage

OilBooster can exfiltrate files to an actor-controlled OneDrive account via the Microsoft Graph API.

T1573.002
Asymmetric Cryptography

OilBooster can use the OpenSSL library to encrypt C2 communications.

Groups that use it1

Campaigns0

None recorded.

References1

  1. ESET OilRig Downloaders DEC 2023 Open source
    Hromcova, Z. and Burgher, A. (2023, December 14). OilRig’s persistent attacks using cloud service-powered downloaders. Retrieved November 26, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.