Juicy Mix is an intrusion campaign associated with OilRig, an Iran-aligned threat actor. The campaign is notable for OilRig’s development and use of the Mango backdoor as an evolution of the earlier Solar malware family. Activity linked to Juicy Mix includes host registration and victim identification behavior in which compromised system names were collected and transmitted to command-and-control infrastructure. This reflects post-compromise reconnaissance and environment fingerprinting used to manage infected hosts and support follow-on operations. As an OilRig-associated campaign, Juicy Mix fits the broader pattern of custom malware development, persistence-oriented access, and operational tooling tailored for long-term intrusion activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operation in which OilRig registered compromised hosts with C2 using host-name reporting over HTTP POST.
Activity cluster in which OilRig evolved the Solar backdoor into Mango.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.