ISMAgent is a Windows .NET backdoor associated with the Iranian state-aligned OilRig (APT34, GreenBug, Helix Kitten) intrusion set. It has been deployed in espionage operations against organizations in the Middle East, including government entities. The malware uses an HTTP command-and-control channel with DNS tunneling as a fallback mechanism when HTTP connectivity fails. Its DNS protocol uses AAAA queries, encodes system and collected data into crafted subdomains, and receives commands or data through IPv6 DNS responses. ISMAgent generates a unique session identifier and supports command execution and transfer of command output through its command-and-control channel. It has been delivered through spearphishing campaigns using weaponized Microsoft Office documents exploiting CVE-2017-0199, as well as by the Agent Injector/ISMInjector .NET loader. ISMInjector can unpack and load ISMAgent directly from memory through .NET Assembly.Load, reducing reliance on a standalone payload written to disk. ISMAgent incorporates anti-analysis measures and is part of OilRig's broader DNS-tunneling toolset.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Sample change managment.dot (812d3c4fddf9bb81d507397345a29bb0) exploits CVE-2017-0199 and calls the following URL: http://www.msoffice-cdn[.]com/updatecdnsrv/prelocated/owa/auth/template.rtf | Recently we detected new samples and Infrastructure of ISMAgent, a trojan in use by Iranian Threat Group GreenBug. Interestingly, as part of the delivery mechanism, the malware is disguised as a base64 digital certificate and decoded via certutil.exe.
In Oct. 2017, the group developed the 'Agent Injector' (Trojan with the specific purpose of installing the ISMAgent backdoor)... ISMAgent - A backdoor which has a sophisticated architecture and contains anti-analysis techniques.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
During the unpacking routine, [ISMInjector] uses the Assembly.Load function to access the embedded next stage malware known as ISMAgent.
Recently we detected new samples and Infrastructure of ISMAgent, a trojan in use by Iranian Threat Group GreenBug. Interestingly, as part of the delivery mechanism, the malware is disguised as a base64 digital certificate and decoded via certutil.exe.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
The OilRig APT Group used a packed .NET malware sample known as ISMInjector to evade signature based detection. During the unpacking routine, the sample uses the Assembly.Load function to access the embedded next stage malware known as ISMAgent.
Interestingly, as part of the delivery mechanism, the malware is disguised as a base64 digital certificate and decoded via certutil.exe.
APT41 used the Steam community page as a fallback mechanism for C2. Bazar has the ability to use an alternative C2 server if the primary server fails. BISCUIT malware contains a secondary fallback command and control server that is contacted after the primary command and control server.
FIN7's Harpy backdoor malware can use DNS as a backup channel for C2 if HTTP fails. OilRig malware ISMAgent falls back to its DNS tunneling mechanism if it is unable to reach the C2 server over HTTP. QUADAGENT uses multiple protocols (HTTPS, HTTP, DNS) for its C2 server as fallback channels if communication with one is unsuccessful.
70 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
ISMAgent is a malware sample detected in the analysis, but specific details are not provided in the content.
Backdoor malware used by OilRig to support stealthy command and control operations.
An embedded next-stage malware payload loaded from ISMInjector through .NET Assembly.Load.
Malware that uses DNS tunneling as a fallback C2 mechanism when HTTP fails.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.