Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1102.002 Bidirectional Communication |
OilCheck can use a REST-based Microsoft Graph API to access draft messages in a shared Microsoft Office 365 Outlook email account used for C2 communication. |
| T1105 Ingress Tool Transfer |
OilCheck can download staged payloads from an actor-controlled infrastructure. |
| T1567 Exfiltration Over Web Service |
OilCheck can upload documents from compromised hosts to a shared Microsoft Office 365 Outlook email account for exfiltration. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.