Threats Feed|OilRig|Last Updated 29/07/2026|AuthorCertfa Radar|Publish Date14/12/2023

Analysis of OilRig's Continued Cyberattacks on Israeli Sectors Using Cloud APIs

  • Actor Motivations: Espionage,Exfiltration
  • Attack Vectors: Backdoor,Downloader,Malware
  • Attack Complexity: Medium
  • Threat Risk: High Impact/Low Probability

Threat Overview

ESET researchers identified a series of downloaders used by the OilRig group in campaigns against Israeli targets throughout 2022 and 2023. These downloaders, named SampleCheck5000 (SC5k v1-v3), OilCheck, ODAgent, and OilBooster, utilize legitimate cloud service APIs such as Microsoft Graph OneDrive, Outlook, and Office Exchange Web Services for command and control (C&C) communication and data exfiltration. Sharing a common OilRig-operated account, these downloaders enable the exchange of messages, commands, and data uploads between victims and operators. Notably, the same account is often used by multiple victims. The tools are part of OilRig's ongoing efforts to re-compromise persistently targeted entities in Israel, including a manufacturing company, a governmental organization, and a healthcare entity. The use of cloud services helps the downloaders blend into regular network traffic, making detection more challenging.

Detected Targets

TypeDescriptionConfidence
SectorGovernment Agencies and Services
Verified
SectorManufacturing
Verified
SectorHealthcare
Verified
RegionIsrael
Verified

Extracted IOCs

  • 0f164894dc7d8256b66d0ebaa7afedcf5462f881
  • 1b2fedd5f2a37a0152231ae4099a13c8d4b73c9e
  • 2236d4dcf68c65a822ff0a2ad48d4df99761ad07
  • 35e0e78ec35b68d3ee1805eeceea352c5fe62eb6
  • 3bf19ae7fb24fce2509623e7e0d03b5a872456d4
  • 51b6ec5de852025f63740826b8edf1c8d22f9261
  • 6001a008a3d3a0c672e80960387f4b10c0a7bd9b
  • 7ad4dcda1c65accc9ef1e168162de7559d2fdf60
  • 7e498b3366f54e936cb0af767bfc3d1f92d80687
  • 8d84d32df5768b0d4d2ab8b1327c43f17f182001
  • a56622a6ef926568d0bdd56fedbff14bd218ad37
  • a97f4b4519947785f66285b546e13e52661a6e6f
  • aae958960657c52b848a7377b170886a34f4ae99
  • aef3140cd0ee6f49bfcc41f086b7051908b91bdd
  • ba439d2fc3298675f197c8b17b79f34485271498
  • be9b6aca8a175df61f2c75932e029f19789fd7e3
  • c04f874430c261aabd413f27953d30303c382953
  • c225e0b256edb9a2ea919bacc62f29319de6cb11
  • ddf0b7b509b240aab6d4ab096284a21d9a3cb910
  • e78830384ff14a58df36303602bc9a2c0334a2a4
  • ea8c3e9f418dcf92412eb01fcdcdc81fdd591bf1
  • 188[.]114.96.2
download

Tip: 22 related IOCs (1 IP, 0 domain, 0 URL, 0 email, 21 file hash) to this threat have been found.

Overlaps

OilRigOilRig's Dual Campaigns Against Israeli Organizations: A Deep Dive

Source: ESET - September 2023

Detection (three cases): 2236d4dcf68c65a822ff0a2ad48d4df99761ad07, be9b6aca8a175df61f2c75932e029f19789fd7e3, ea8c3e9f418dcf92412eb01fcdcdc81fdd591bf1

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

The OilRig Cloud-Abuse Campaign

A cyberattack campaign was discovered where attackers used newly developed malicious tools to secretly download files and steal data. These tools bypassed normal security by hiding their communications inside legitimate cloud services, like shared email and online storage accounts.

The attacks were carried out by a known threat group called OilRig. This group is recognized for continuously developing new malicious tools and dedicating significant effort to repeatedly re-compromising the exact same targets.

The primary goal of these attacks was to maintain persistent, hidden access to networks of interest. Once inside, the attackers used this access to run hidden commands on the computers, drop additional malicious files, and extract sensitive information.

The campaign involved multiple different malicious tools deployed continuously throughout 2022. The attackers scaled their operations by using single, shared online accounts to control and manage multiple victims simultaneously.

These specific tools were deployed exclusively against organizations located in Israel. The targeted entities were often victims who had already been successfully attacked by this same group in the past.

The attackers set up shared online accounts and programmed their tools to log in and read hidden messages, such as unsent email drafts or disguised document files. The malicious tools would receive instructions from these messages, execute them on the computer, and then upload the stolen information back to the same shared accounts.

The report indicates that these specific entities are highly attractive because the attackers dedicated significant time to attacking the same networks repeatedly over several months. This suggests the targets hold high-value information that the attackers want continuous access to.

Organizations should closely monitor their network traffic for unusual activity communicating with common cloud services and APIs. Additionally, security teams should look for suspicious file creations, unusual file extensions, or strange commands running locally on their computers.

This is a highly targeted issue. The malicious tools were custom-built to focus on specific victims and networks of interest rather than being spread widely across the general public.

About Affiliation
OilRig
OilRig is an Iranian MOIS-linked threat cluster active since at least 2014, considered one of Iran's most technically capable and consistently active espionage groups. The cluster targets government, energy, financial, and telecommunications organizations across the Middle East and beyond, using spear phishing, credential harvesting portals, DNS tunneling, and a large arsenal of custom backdoors including HELMINTH, BONDUPDATER, VEATY, and SPEARAL. OilRig is tracked as APT34 (Mandiant), Helix Kitten (CrowdStrike), Cobalt Gypsy (Secureworks), and Hazel Sandstorm (Microsoft) among other names.
View OilRig's Insights