logo

OilRig’s persistent attacks using cloud service-powered downloaders

ID: bdcda218-4ddc-59e4-934f-8183c1cf7b1c

STIX ID: report--bdcda218-4ddc-59e4-934f-8183c1cf7b1c

Feed Name: WeLiveSecurity (ESET Research)

Threat Score
78/100

Date Published: 2023-12-14

Date Updated: 2026-05-01

...
...

ESET researchers detail OilRig (Lyceum/APT34) activity where a set of lightweight downloaders (SC5k v1–v3, ODAgent, OilCheck, OilBooster) were used throughout 2022 to maintain persistent access to Israeli targets by abusing Microsoft cloud services (OneDrive, Outlook/EWS, Microsoft Graph) for command-and-control and exfiltration; the report provides technical analysis of each downloader, TTP mapping to MITRE ATT&CK, and IoCs including file hashes and a fallback C2 domain.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.