OopsIE

MITRE ATT&CK: S0264 View on attack.mitre.org

Aliases: OopsIE

First seen
2017-01-01 00:00:00
Malware type
trojan, rat
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 12:49:05

Targeted industries: government-and-public-sector financial-services energy-and-utilities

Targeted regions: country_code:sa country_code:ae

Context

OopsIE is a Trojan used by OilRig to remotely execute commands as well as upload/download files to/from victims.

Detection coverage

  • 406 Sigma rules

Malware & tools used

  • Local Data Staging (attack-pattern)
  • Data Transfer Size Limits (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • File Deletion (attack-pattern)
  • Windows Management Instrumentation (attack-pattern)
  • Standard Encoding (attack-pattern)
  • System Information Discovery (attack-pattern)
  • System Checks (attack-pattern)
  • Web Protocols (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Archive via Custom Method (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Visual Basic (attack-pattern)
  • Archive via Utility (attack-pattern)
  • Scheduled Task (attack-pattern)
  • Software Packing (attack-pattern)
  • System Time Discovery (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)

Used by threat actors

Reports & references

  • Palo Alto Unit 42 — Evasive Serpens (report)
  • docs.google.com — Edit (report)
  • cyware.com — Apt34 The Helix Kitten Cybercriminal Group Loves To Meow Middle Eastern And International Organizations 48Ae (report)
  • ptsecurity.com — Antisandbox Techniques (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Oopsie (report)
  • researchcenter.paloaltonetworks.com — Unit42 Oopsie Oilrig Uses Threedollars Deliver New Trojan (report)
  • MITRE ATT&CK — S0264 (report)
  • researchcenter.paloaltonetworks.com — Unit42 Oilrig Targets Middle Eastern Government Adds Evasion Techniques Oopsie (report)

External references