Movatterモバイル変換


[0]ホーム

URL:


  1. Home
  2. Campaigns
  3. Outer Space

Outer Space

Outer Space was a campaign conducted byOilRig throughout 2021 that used theSampleCheck5000 downloader andSolar backdoor to target Israeli organizations.[1]

ID: C0042
First Seen: January 2021[1]
Last Seen: December 2021[1]
Version: 1.0
Created: 21 November 2024
Last Modified: 25 November 2024

Groups

IDNameDescription
G0049OilRig

[1]

Enterprise Layer
downloadview

Techniques Used

DomainIDNameUse
EnterpriseT1071.001Application Layer Protocol:Web Protocols

DuringOuter Space,OilRig used HTTP to communicate between installed backdoors and compromised servers including via the Microsoft Exchange Web Services API.[1]

EnterpriseT1217Browser Information Discovery

DuringOuter Space,OilRig used a Chrome data dumper named MKG.[1]

EnterpriseT1059.005Command and Scripting Interpreter:Visual Basic

DuringOuter Space,OilRig used VBS droppers to deploy malware.[1]

EnterpriseT1584.004Compromise Infrastructure:Server

DuringOuter Space,OilRig compromised an Israeli human resources site to use as a C2 server.[1]

EnterpriseT1587.001Develop Capabilities:Malware

ForOuter Space,OilRig created new implants including theSolar backdoor.[1]

EnterpriseT1585.003Establish Accounts:Cloud Accounts

DuringOuter Space,OilRig created M365 email accounts to be used as part of C2.[1]

EnterpriseT1105Ingress Tool Transfer

DuringOuter Space,OilRig downloaded additional tools to comrpomised infrastructure.[1]

EnterpriseT1027.013Obfuscated Files or Information:Encrypted/Encoded File

DuringOuter Space,OilRig deployed VBS droppers with obfuscated strings.[1]

Software

References

×

[8]ページ先頭

©2009-2026 Movatter.jp