Mango

MITRE ATT&CK: S1169 View on attack.mitre.org

Aliases: Mango

First seen
2018-05-01 00:00:00
Malware type
backdoor
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 15:11:03

Targeted industries: government-and-public-sector energy-and-utilities financial-services

Targeted regions: country_code:sa country_code:ae country_code:ir

Context

Mango is a first-stage backdoor written in C#/.NET that was used by OilRig during the Juicy Mix campaign. Mango is the successor to Solar and includes additional exfiltration capabilities, the use of native APIs, and added detection evasion code.

Detection coverage

  • 343 Sigma rules

Malware & tools used

  • Symmetric Cryptography (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Asymmetric Cryptography (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • Malicious File (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Web Protocols (attack-pattern)
  • System Owner/User Discovery (attack-pattern)
  • Standard Encoding (attack-pattern)
  • Native API (attack-pattern)
  • Scheduled Task (attack-pattern)

Used by threat actors

  • OilRig (threat-actor)
  • Juicy Mix (campaign)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Mango (report)
  • ESET — Oilrigs Outer Space Juicy Mix Same Ol Rig New Drill Pipes (report)
  • MITRE ATT&CK — S1169 (report)

External references