OilBooster is a downloader used in OilRig cyberespionage operations against previously compromised organizations in Israel, including entities in the healthcare, manufacturing, and local government sectors. It is associated with the Iranian state-linked threat actor OilRig, also tracked as APT34. The malware is a 64-bit Windows portable executable written in Microsoft Visual C/C++ and is designed to blend command-and-control traffic with legitimate enterprise cloud activity by abusing Microsoft cloud services.
OilBooster uses the Microsoft Graph API and Microsoft OneDrive as its primary command-and-control and exfiltration channel. It connects to an actor-controlled Microsoft 365 and OneDrive environment, retrieves commands and additional payloads from victim-specific folders, executes downloaded files and shell commands, and uploads stolen data back to the operator-controlled cloud account. It can stage files locally before exfiltration and capture command execution output through an unnamed pipe connected to spawned processes.
The malware includes multiple stealth and resiliency features. It can hide its console window during execution through the ShowWindow API to reduce user visibility. It can encrypt command-and-control communications using the OpenSSL library. It also implements a backup recovery mechanism for cloud access: after repeated failures communicating with its primary OneDrive channel, it can request replacement OAuth refresh tokens through a secondary channel, including retrieval from compromised web infrastructure, allowing operators to restore access to the cloud-based command-and-control account.
OilBooster is part of a broader OilRig tradecraft pattern of abusing trusted Microsoft services for covert command-and-control, payload delivery, and data theft while minimizing reliance on easily blocked attacker-owned infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Presence of secondary recovery mechanism to obtain replacement OAuth refresh tokens, as observed in OilBooster
OilBooster is a 64-bit portable executable (PE) written in Microsoft Visual C/C++... uses the Microsoft Graph API to interact with a OneDrive... account controlled by the attackers for C&C communication and exfiltration.
OilBooster is a 64-bit portable executable (PE) written in Microsoft Visual C/C++... uses the Microsoft Graph API to interact with a OneDrive... account controlled by the attackers for C&C communication and exfiltration.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
During the 2016 Ukraine Electric Power Attack, Sandworm Team used the xp_cmdshell command in MS-SQL. During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run cmd.exe commands on multiple victim machines. Numerous malware families and groups are described as using cmd.exe, cmd /c, Windows command shell, or command-line interfaces to execute commands, payloads, reconnaissance, persistence, cleanup, and ransomware actions.
The content repeatedly describes malware and threat actors decoding, decrypting, or deobfuscating payloads, strings, configuration data, commands, and C2 traffic prior to execution or use, e.g., 'APT28 macro uses the command certutil -decode to decode contents of a .txt file storing the base64 encoded payload' and 'Action RAT can use Base64 to decode actor-controlled C2 server communications.'
Agent Tesla has used ProcessWindowStyle.Hidden to hide windows. APT-C-36 has set the ShowWindow property of the Win32_ProcessStartup object to zero to hide PowerShell execution. APT19 used -W Hidden to conceal PowerShell windows by setting the WindowStyle parameter to hidden.
The content repeatedly describes malware and threat actors collecting usernames, identifying logged-in users, running whoami/query user/quser, checking admin status, and enumerating user sessions.
The content repeatedly describes malware and threat actors collecting host details such as OS version, hostname, architecture, CPU, memory, BIOS, domain, language, and other configuration data; e.g., "APT41 uses multiple built-in commands such as systeminfo and net config Workstation to enumerate victim system basic configuration information."
ODAgent, first detected in February 2022, is a C#/.NET downloader that utilizes Microsoft OneDrive API for command-and-control (C2) communications. | These lightweight downloaders [...] are notable for using one of several legitimate cloud service APIs for [command-and-control] communication and data exfiltration: the Microsoft Graph OneDrive or Outlook APIs, and the Microsoft Office Exchange Web Services (EWS) API.
The content repeatedly describes threat actors, malware, and campaigns using HTTP and/or HTTPS for command and control, including examples such as BlackEnergy communicating with C2 over HTTP POST requests and many other families using HTTP/S for C2.
The adversaries had communicated to both Dropbox and Pastebin. APT28 has used Google Drive for C2. APT37 leverages social networking sites and cloud platforms (AOL, Twitter, Yandex, Mediafire, pCloud, Dropbox, and Box) for C2.
"APT39 has communicated with C2 through files uploaded to and downloaded from DropBox."; "RIFLESPINE can retrieve C2 commands from an encrypted file on Google Drive then upload the results ... back to Google Drive."; "CloudDuke uses a Microsoft OneDrive account to exchange commands and stolen data"
Clambling can use Dropbox to download malicious payloads, send commands, and receive information. ODAgent can use the Microsoft Graph API to access an attacker-controlled OneDrive account and retrieve payloads and backdoor commands. OilBooster uses the Microsoft Graph API to connect to an actor-controlled OneDrive account to download and execute files and shell commands.
The content repeatedly describes malware and threat actors using SSL, TLS, HTTPS, RSA, AES, Blowfish, RC4, ECIES, Diffie-Hellman, OpenSSL, WolfSSL, and mutual TLS to protect command and control traffic.
Multiple malware families and intrusion sets are described as encrypting C2 traffic using SSL/TLS/HTTPS (e.g., "used HTTPS for command and control", "encrypts C2 communications with TLS", "uses SSL for encrypting C2 communications", "TLS-encrypted WebSocket Protocol (WSS) for C2").
ComRAT has the ability to use the Gmail web UI to receive commands and exfiltrate information. Crutch can use Dropbox to receive commands and upload stolen data. RIFLESPINE can retrieve C2 commands from an encrypted file on Google Drive then upload the results of command execution back to Google Drive.
Crutch can exfiltrate data over the primary C2 channel (Dropbox HTTP API)... ODAgent can use an attacker-controlled OneDrive account to receive C2 commands and to exfiltrate files... OilBooster can use an actor-controlled OneDrive account for C2 communication and exfiltration... ZIRCONIUM has exfiltrated files via the Dropbox API C2.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
23 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a comparison point for a secondary recovery mechanism used to obtain replacement OAuth refresh tokens.
Malware referenced for comparison because it used a secondary recovery mechanism to restore access to a cloud-based C2 channel.
Backdoor/outillage cité comme comparaison pour un mécanisme secondaire de récupération d’accès cloud.
Malware with a secondary recovery mechanism to restore access to a cloud-based C2 channel by retrieving a replacement OAuth refresh token.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.