Mango
MITRE ATT&CK: S1169 View on attack.mitre.org
Aliases: Mango
- First seen
- 2018-05-01 00:00:00
- Malware type
- backdoor
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 15:11:03
Targeted industries: government-and-public-sector energy-and-utilities financial-services
Targeted regions: country_code:sa country_code:ae country_code:ir
Context
Mango is a first-stage backdoor written in C#/.NET that was used by OilRig during the Juicy Mix campaign. Mango is the successor to Solar and includes additional exfiltration capabilities, the use of native APIs, and added detection evasion code.
Detection coverage
- 343 Sigma rules
Malware & tools used
- Symmetric Cryptography (attack-pattern)
- System Information Discovery (attack-pattern)
- Asymmetric Cryptography (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Disable or Modify Tools (attack-pattern)
- Malicious File (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Web Protocols (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- Standard Encoding (attack-pattern)
- Native API (attack-pattern)
- Scheduled Task (attack-pattern)
Used by threat actors
- OilRig (threat-actor)
- Juicy Mix (campaign)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Mango (report)
- ESET — Oilrigs Outer Space Juicy Mix Same Ol Rig New Drill Pipes (report)
- MITRE ATT&CK — S1169 (report)