Malware.View on attack.mitre.org
OilBooster is a downloader written in Microsoft Visual C/C++ that has been used by OilRig since at least 2022 including against target organizations in Israel to download and execute files and for exfiltration.
| Technique | Procedure example |
|---|---|
| T1008 Fallback Channels |
OilBooster can use a backup channel to request a new refresh token from its C2 server after 10 consecutive unsuccessful connections to the primary OneDrive C2 server. |
| T1033 System Owner/User Discovery |
OilBooster can identify the compromised system's username which is then used as part of a unique identifier. |
| T1041 Exfiltration Over C2 Channel |
OilBooster can use an actor-controlled OneDrive account for C2 communication and exfiltration. |
| T1059.003 Windows Command Shell |
OilBooster has the ability to execute shell commands and exfiltrate the results. |
| T1071.001 Web Protocols |
OilBooster can send HTTP `GET`, `POST`, `PUT`, and `DELETE` requests to the Microsoft Graph API over port 443 for C2 communication. |
| T1074.001 Local Data Staging |
OilBooster can stage files in the `tempFiles` directory for exfiltration. |
| T1082 System Information Discovery |
OilBooster can identify the compromised system's hostname which is used to create a unique identifier. |
| T1102.002 Bidirectional Communication |
OilBooster uses the Microsoft Graph API to connect to an actor-controlled OneDrive account to download and execute files and shell commands, and to create directories to share exfiltrated data. |
| T1105 Ingress Tool Transfer |
OilBooster can download and execute files from an actor-controlled OneDrive account. |
| T1106 Native API |
OilBooster has used the `ShowWindow` and `CreateProcessW` APIs. |
| T1140 Deobfuscate/Decode Files or Information |
OilBooster can Base64-decode and XOR-decrypt C2 commands taken from JSON files. |
| T1559 Inter-Process Communication |
OilBooster can read the results of command line execution via an unnamed pipe connected to the process. |
| T1564.003 Hidden Window |
OilBooster can hide its console window upon execution through the `ShowWindow` API. |
| T1567.002 Exfiltration to Cloud Storage |
OilBooster can exfiltrate files to an actor-controlled OneDrive account via the Microsoft Graph API. |
| T1573.002 Asymmetric Cryptography |
OilBooster can use the OpenSSL library to encrypt C2 communications. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.