OilBooster is a Windows malware family used in OilRig cyberespionage operations against organizations in Israel, including healthcare, manufacturing, and local government entities. It has been described as a 64-bit portable executable written in Visual C/C++ and linked with OpenSSL and Boost libraries. The malware is associated with campaigns attributed to OilRig, also tracked as APT34, with later reporting placing the activity under the Lyceum subgroup.
OilBooster uses legitimate Microsoft cloud services as its command-and-control and exfiltration channel. It authenticates to Microsoft services with OAuth and uses the Microsoft Graph API to interact with an actor-controlled Microsoft 365 OneDrive account. The malware organizes activity in victim-specific OneDrive folders, retrieves commands and additional payloads, executes downloaded content and shell commands on the compromised host, and uploads results or stolen files back to the cloud account. It can stage files locally prior to exfiltration and can capture command execution output through an unnamed pipe connected to the spawned process.
The malware includes multiple stealth and resilience features. It can hide its console window during execution and can encrypt command-and-control traffic using the OpenSSL library. If repeated attempts to communicate with the primary OneDrive-based channel fail, OilBooster can use a backup mechanism to obtain a replacement OAuth refresh token from a secondary server, allowing it to restore access to the cloud C2 channel.
OilBooster is part of a broader OilRig tradecraft pattern of abusing trusted Microsoft cloud APIs, including OneDrive, Outlook, and Exchange Web Services, to blend malicious traffic with normal enterprise activity and reduce infrastructure exposure. In observed operations, the same actor-controlled cloud account could be shared across multiple victims, reinforcing its role as a lightweight downloader and cloud-backed espionage implant rather than a standalone destructive payload.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
ESET previously documented OilBooster, which retrieved a replacement OAuth refresh token from a likely compromised website after repeated failures communicating with Microsoft OneDrive.
OilBooster is a 64-bit portable executable (PE) written in Microsoft Visual C/C++... uses the Microsoft Graph API to interact with a OneDrive... account controlled by the attackers for C&C communication and exfiltration.
OilBooster is a 64-bit portable executable (PE) written in Microsoft Visual C/C++... uses the Microsoft Graph API to interact with a OneDrive... account controlled by the attackers for C&C communication and exfiltration.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
During the 2016 Ukraine Electric Power Attack, Sandworm Team used the xp_cmdshell command in MS-SQL. During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run cmd.exe commands on multiple victim machines. Numerous malware families and groups are described as using cmd.exe, cmd /c, Windows command shell, or command-line interfaces to execute commands, payloads, reconnaissance, persistence, cleanup, and ransomware actions.
The content repeatedly describes malware and threat actors decoding, decrypting, or deobfuscating payloads, strings, configuration data, commands, and C2 traffic prior to execution or use, e.g., 'APT28 macro uses the command certutil -decode to decode contents of a .txt file storing the base64 encoded payload' and 'Action RAT can use Base64 to decode actor-controlled C2 server communications.'
The content repeatedly describes malware and threat actors collecting usernames, identifying logged-in users, running whoami/query user/quser, checking admin status, and enumerating user sessions.
The content repeatedly describes malware and threat actors collecting host details such as OS version, hostname, architecture, CPU, memory, BIOS, domain, language, and other configuration data; e.g., "APT41 uses multiple built-in commands such as systeminfo and net config Workstation to enumerate victim system basic configuration information."
ODAgent, first detected in February 2022, is a C#/.NET downloader that utilizes Microsoft OneDrive API for command-and-control (C2) communications. | These lightweight downloaders [...] are notable for using one of several legitimate cloud service APIs for [command-and-control] communication and data exfiltration: the Microsoft Graph OneDrive or Outlook APIs, and the Microsoft Office Exchange Web Services (EWS) API.
The content repeatedly describes threat actors, malware, and campaigns using HTTP and/or HTTPS for command and control, including examples such as BlackEnergy communicating with C2 over HTTP POST requests and many other families using HTTP/S for C2.
The adversaries had communicated to both Dropbox and Pastebin. APT28 has used Google Drive for C2. APT37 leverages social networking sites and cloud platforms (AOL, Twitter, Yandex, Mediafire, pCloud, Dropbox, and Box) for C2.
"APT39 has communicated with C2 through files uploaded to and downloaded from DropBox."; "RIFLESPINE can retrieve C2 commands from an encrypted file on Google Drive then upload the results ... back to Google Drive."; "CloudDuke uses a Microsoft OneDrive account to exchange commands and stolen data"
Clambling can use Dropbox to download malicious payloads, send commands, and receive information. ODAgent can use the Microsoft Graph API to access an attacker-controlled OneDrive account and retrieve payloads and backdoor commands. OilBooster uses the Microsoft Graph API to connect to an actor-controlled OneDrive account to download and execute files and shell commands.
The content repeatedly describes malware and threat actors using SSL, TLS, HTTPS, RSA, AES, Blowfish, RC4, ECIES, Diffie-Hellman, OpenSSL, WolfSSL, and mutual TLS to protect command and control traffic.
Multiple malware families and intrusion sets are described as encrypting C2 traffic using SSL/TLS/HTTPS (e.g., "used HTTPS for command and control", "encrypts C2 communications with TLS", "uses SSL for encrypting C2 communications", "TLS-encrypted WebSocket Protocol (WSS) for C2").
ComRAT has the ability to use the Gmail web UI to receive commands and exfiltrate information. Crutch can use Dropbox to receive commands and upload stolen data. RIFLESPINE can retrieve C2 commands from an encrypted file on Google Drive then upload the results of command execution back to Google Drive.
Crutch can exfiltrate data over the primary C2 channel (Dropbox HTTP API)... ODAgent can use an attacker-controlled OneDrive account to receive C2 commands and to exfiltrate files... OilBooster can use an actor-controlled OneDrive account for C2 communication and exfiltration... ZIRCONIUM has exfiltrated files via the Dropbox API C2.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware referenced for comparison because it used a secondary recovery mechanism to restore access to a cloud-based C2 channel.
Malware with a secondary recovery mechanism to restore access to a cloud-based C2 channel by retrieving a replacement OAuth refresh token.
Backdoor that reads command execution results through an unnamed pipe.
A downloader used by OilRig that uses Microsoft OneDrive and Microsoft Graph API-based communications to fetch commands and payloads from actor-controlled Office 365/OneDrive infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.