OilRig’s Outer Space and Juicy Mix: Same ol’ rig, new drill pipes
ID: 3a1d22a8-b545-5fb0-a245-7b40893885f7
STIX ID: report--3a1d22a8-b545-5fb0-a245-7b40893885f7
Feed Name: WeLiveSecurity (ESET Research)
Threat Score
ESET documents two OilRig (Lyceum) campaigns targeting Israeli organizations that used compromised websites for C2, VBS droppers to install C#/.NET backdoors (Solar and successor Mango), an Exchange-based downloader (SC5k), and multiple post-compromise tools to steal browser data and Windows credentials; the report includes technical analysis, IoCs (hashes, domains, IP), and MITRE ATT&CK mappings to support detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
