Juicy Mix

C0044

Campaign, Jan 2022 to Dec 2022.View on attack.mitre.org

About this campaign

Juicy Mix was a campaign conducted by OilRig throughout 2022 that targeted Israeli organizations with the Mango backdoor.

Techniques used14

Procedure examples14

TechniqueProcedure example
T1053.005
Scheduled Task

During Juicy Mix, OilRig used VBS droppers to schedule tasks for persistence.

T1059.001
PowerShell

During Juicy Mix, OilRig used a PowerShell script to steal credentials.

T1059.005
Visual Basic

During Juicy Mix, OilRig used VBS droppers to deliver and establish persistence for the Mango backdoor.

T1071.001
Web Protocols

During Juicy Mix, OilRig used a VBS script to send POST requests to register installed malware with C2.

T1074.001
Local Data Staging

During Juicy Mix, OilRig used browser data and credential stealer tools to stage stolen files named Cupdate, Eupdate, and IUpdate in the %TEMP% directory.

T1082
System Information Discovery

During Juicy Mix, OilRig used a script to send the name of the compromised host via HTTP `POST` to register it with C2.

T1132.001
Standard Encoding

During Juicy Mix, OilRig used a VBS script to send the Base64-encoded name of the compromised computer to C2.

T1140
Deobfuscate/Decode Files or Information

During Juicy Mix, OilRig used a script to concatenate and deobfuscate encoded strings in Mango.

T1217
Browser Information Discovery

During Juicy Mix, OilRig used the CDumper (Chrome browser) and EDumper (Edge browser) data stealers to collect cookies, browsing history, and credentials.

T1518
Software Discovery

During Juicy Mix, OilRig used browser data dumper tools to create a list of users with Google Chrome installed.

T1555.003
Credentials from Web Browsers

During Juicy Mix, OilRig used the CDumper (Chrome browser) and EDumper (Edge browser) to collect credentials.

T1555.004
Windows Credential Manager

During Juicy Mix, OilRig used a Windows Credential Manager stealer for credential access.

T1584.004
Server

During Juicy Mix, OilRig compromised an Israeli job portal to use for a C2 server.

T1587.001
Malware

For Juicy Mix, OilRig improved on Solar by developing the Mango backdoor.

Attributed groups1

Software1

References1

  1. ESET OilRig Campaigns Sep 2023 Open source
    Hromcova, Z. and Burgher, A. (2023, September 21). OilRig’s Outer Space and Juicy Mix: Same ol’ rig, new drill pipes. Retrieved November 21, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.