OilCheck

MITRE ATT&CK: S1171 View on attack.mitre.org

Aliases: OilCheck

First seen
2022-01-01 00:00:00
Malware type
downloader
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 15:28:53

Targeted industries: government-and-public-sector

Targeted regions: country_code:il

Context

OilCheck is a C#/.NET downloader that has been used by OilRig since at least 2022 including against targets in Israel. OilCheck uses draft messages created in a shared email account for C2 communication.

Detection coverage

  • 84 Sigma rules

Malware & tools used

  • Exfiltration Over Web Service (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Bidirectional Communication (attack-pattern)

Used by threat actors

Reports & references

  • ESET — Oilrig Persistent Attacks Cloud Service Powered Downloaders (report)
  • MITRE ATT&CK — S1171 (report)

External references