ATT&CKReferencesUnit42 OilRig Playbook 2023

Unit42 OilRig Playbook 2023

Unit42. (2016, May 1). Evasive Serpens Unit 42 Playbook Viewer. Retrieved February 6, 2023.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples15

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupOilRig

OilRig has used credential dumping tools such as Mimikatz to steal credentials to accounts logged into the compromised system and to Outlook Web Access.

T1003.004
LSA Secrets
GroupOilRig

OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access.

T1003.005
Cached Domain Credentials
GroupOilRig

OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access.

T1021.001
Remote Desktop Protocol
GroupOilRig

OilRig has used Remote Desktop Protocol for lateral movement. The group has also used tunneling tools to tunnel RDP into the environment.

T1021.004
SSH
GroupOilRig

OilRig has used Putty to access compromised systems.

T1027.013
Encrypted/Encoded File
GroupOilRig

OilRig has encrypted and encoded data in its malware, including by using base64.

T1071.001
Web Protocols
GroupOilRig

OilRig has used HTTP for C2.

T1071.004
DNS
GroupOilRig

OilRig has used DNS for C2 including the publicly available requestbin.net tunneling service.

T1078
Valid Accounts
GroupOilRig

OilRig has used compromised credentials to access other systems on a victim network.

T1119
Automated Collection
GroupOilRig

OilRig has used automated collection.

T1505.003
Web Shell
GroupOilRig

OilRig has used web shells, often to maintain access to a victim network.

T1552.001
Credentials In Files
GroupOilRig

OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access.

T1555
Credentials from Password Stores
GroupOilRig

OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access.

T1555.003
Credentials from Web Browsers
GroupOilRig

OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access. OilRig has also used tool named PICKPOCKET to dump passwords from web browsers.

T1572
Protocol Tunneling
GroupOilRig

OilRig has used the Plink utility and other tools to create tunnels to C2 servers.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.