QUADAGENT

MITRE ATT&CK: S0269 View on attack.mitre.org

Aliases: QUADAGENT

First seen
2018-02-01 00:00:00
Malware type
backdoor
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 12:58:42

Targeted industries: government-and-public-sector energy-and-utilities

Targeted regions: country_code:sa country_code:ae

Context

QUADAGENT is a PowerShell backdoor used by OilRig.

Detection coverage

  • 484 Sigma rules

Malware & tools used

  • Web Protocols (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Standard Encoding (attack-pattern)
  • Visual Basic (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Command Obfuscation (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Fileless Storage (attack-pattern)
  • File Deletion (attack-pattern)
  • Query Registry (attack-pattern)
  • PowerShell (attack-pattern)
  • Fallback Channels (attack-pattern)
  • Modify Registry (attack-pattern)
  • System Owner/User Discovery (attack-pattern)
  • Scheduled Task (attack-pattern)
  • DNS (attack-pattern)

Used by threat actors

Reports & references

  • youtu.be — Pbdu8Egwrc4 (report)
  • researchcenter.paloaltonetworks.com — Unit42 Oilrig Targets Technology Service Provider Government Agency Quadagent (report)
  • docs.google.com — Edit (report)
  • cyware.com — Apt34 The Helix Kitten Cybercriminal Group Loves To Meow Middle Eastern And International Organizations 48Ae (report)
  • Palo Alto Unit 42 — Dns Tunneling In The Wild Overview Of Oilrigs Dns Tunneling (report)
  • Mandiant — Scandalous External Detection Using Network Scan Data And Automation (report)
  • malpedia.caad.fkie.fraunhofer.de — Ps1.Quadagent (report)
  • MITRE ATT&CK — S0269 (report)

External references