Threat group.View on attack.mitre.org
OilRig is a suspected Iranian threat group that has targeted Middle Eastern and international victims since at least 2014. The group has targeted a variety of sectors, including financial, government, energy, chemical, and telecommunications. It appears the group carries out supply chain attacks, leveraging the trust relationship between organizations to attack their primary targets. The group works on behalf of the Iranian government based on infrastructure details that contain references to Iran, use of Iranian infrastructure, and targeting that aligns with nation-state interests.
| Technique | Procedure example |
|---|---|
| T1003.001 LSASS Memory |
OilRig has used credential dumping tools such as Mimikatz to steal credentials to accounts logged into the compromised system and to Outlook Web Access. |
| T1003.004 LSA Secrets |
OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access. |
| T1003.005 Cached Domain Credentials |
OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access. |
| T1005 Data from Local System |
OilRig has used PowerShell to upload files from compromised systems. |
| T1007 System Service Discovery |
OilRig has used |
| T1008 Fallback Channels |
OilRig malware ISMAgent falls back to its DNS tunneling mechanism if it is unable to reach the C2 server over HTTP. |
| T1012 Query Registry |
OilRig has used |
| T1016 System Network Configuration Discovery |
OilRig has run |
| T1021.001 Remote Desktop Protocol |
OilRig has used Remote Desktop Protocol for lateral movement. The group has also used tunneling tools to tunnel RDP into the environment. |
| T1021.004 SSH |
OilRig has used Putty to access compromised systems. |
| T1025 Data from Removable Media |
OilRig has used Wireshark’s usbcapcmd utility to capture USB traffic. |
| T1027.005 Indicator Removal from Tools |
OilRig has tested malware samples to determine AV detection and subsequently modified the samples to ensure AV evasion. |
| T1027.013 Encrypted/Encoded File |
OilRig has encrypted and encoded data in its malware, including by using base64. |
| T1033 System Owner/User Discovery |
OilRig has run |
| T1036 Masquerading |
OilRig has used .doc file extensions to mask malicious executables. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.