ISMInjector

MITRE ATT&CK: S0189 View on attack.mitre.org

Aliases: ISMInjector

Malware type
trojan, dropper
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 15:30:34

Targeted industries: government-and-public-sector financial-services

Targeted regions: country_code:sa country_code:ae

Context

ISMInjector is a Trojan used to install another OilRig backdoor, ISMAgent.

Detection coverage

  • 136 Sigma rules

Malware & tools used

  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • Process Hollowing (attack-pattern)
  • Scheduled Task (attack-pattern)

Used by threat actors

Reports & references

  • MITRE ATT&CK — S0189 (report)
  • researchcenter.paloaltonetworks.com — Unit42 Oilrig Group Steps Attacks New Delivery Documents New Injector Trojan (report)

External references