ATT&CKSoftwareBackdoor.Oldrea

Backdoor.Oldrea

S0093

Malware.View on attack.mitre.org

About this malware

Backdoor.Oldrea is a modular backdoor that used by Dragonfly against energy companies since at least 2013. Backdoor.Oldrea was distributed via supply chain compromise, and included specialized modules to enumerate and map ICS-specific systems, processes, and protocols.

Techniques used16

Procedure examples16

TechniqueProcedure example
T1016
System Network Configuration Discovery

Backdoor.Oldrea collects information about the Internet adapter configuration.

T1018
Remote System Discovery

Backdoor.Oldrea can enumerate and map ICS-specific systems in victim environments.

T1033
System Owner/User Discovery

Backdoor.Oldrea collects the current username from the victim.

T1046
Network Service Discovery

Backdoor.Oldrea can use a network scanning module to identify ICS-related ports.

T1055
Process Injection

Backdoor.Oldrea injects itself into explorer.exe.

T1057
Process Discovery

Backdoor.Oldrea collects information about running processes.

T1070.004
File Deletion

Backdoor.Oldrea contains a cleanup module that removes traces of itself from the victim.

T1082
System Information Discovery

Backdoor.Oldrea collects information about the OS and computer name.

T1083
File and Directory Discovery

Backdoor.Oldrea collects information about available drives, default browser, desktop file list, My Documents, Internet history, program files, and root of available drives. It also searches for ICS-related software files.

T1087.003
Email Account

Backdoor.Oldrea collects address book information from Outlook.

T1105
Ingress Tool Transfer

Backdoor.Oldrea can download additional modules from C2.

T1132.001
Standard Encoding

Some Backdoor.Oldrea samples use standard Base64 + bzip2, and some use standard Base64 + reverse XOR + RSA-2048 to decrypt data received from C2 servers.

T1218.011
Rundll32

Backdoor.Oldrea can use rundll32 for execution on compromised hosts.

T1547.001
Registry Run Keys / Startup Folder

Backdoor.Oldrea adds Registry Run keys to achieve persistence.

T1555.003
Credentials from Web Browsers

Some Backdoor.Oldrea samples contain a publicly available Web browser password recovery tool.

View all 16 procedure examples

Groups that use it1

Campaigns0

None recorded.

References3

  1. Gigamon Berserk Bear October 2021 Open source
    Slowik, J. (2021, October). THE BAFFLING BERSERK BEAR: A DECADE’S ACTIVITY TARGETING CRITICAL INFRASTRUCTURE. Retrieved December 6, 2021.
  2. Symantec Dragonfly Open source
    Symantec Security Response. (2014, June 30). Dragonfly: Cyberespionage Attacks Against Energy Suppliers. Retrieved April 8, 2016.
  3. Symantec Dragonfly Sept 2017 Open source
    Symantec Security Response. (2014, July 7). Dragonfly: Western energy sector targeted by sophisticated attack group. Retrieved September 9, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.