Mango is a custom backdoor associated with the Iran-aligned threat actor OilRig, also tracked in the provided content as APT34 and linked to the Lyceum subgroup. The content states that OilRig developed Mango as an improvement over its earlier Solar backdoor and used Solar and Mango in operations against organizations in Israel in 2022 and 2023, including local government and healthcare entities. Mango is also referenced as one of the major tools attributed to Lyceum.
Observed capabilities include receiving Base64-encoded commands from command-and-control infrastructure, using TLS to encrypt C2 communications, and using its HTTP C2 channel for data exfiltration. Mango can create a scheduled task that runs every 32 seconds to communicate with C2 and execute received commands. The malware also contains an unused capability intended to block endpoint security solutions from loading user-mode code hooks via a DLL in a specified process.
For delivery and persistence, the content states that Mango has been executed through a Microsoft Word document containing a malicious macro, and that during the Juicy Mix campaign OilRig used VBS droppers to deliver the Mango backdoor and establish persistence, including via scheduled tasks. Juicy Mix also involved HTTP POST-based registration activity and Base64-encoded host identification, and the campaign used compromised infrastructure, including an Israeli job portal as a C2 server. Overall, the available content supports classifying Mango as an OilRig backdoor used for long-term intrusion activity and post-compromise command execution, persistence, encrypted C2, and exfiltration.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Major tools we attribute to Lyceum include ... Solar and Mango ...
Major tools we attribute to Lyceum include ... Solar and Mango ...
20 distinct techniques documented for this family, organized by ATT&CK tactic.
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.
The content repeatedly describes threat actors and malware using VBScript, VBS, VBA macros, and Visual Basic code for execution, payload delivery, persistence, reconnaissance, and command execution.
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
The content repeatedly describes malware and threat actors collecting usernames, identifying logged-in users, running whoami/query user/quser, checking admin status, and enumerating user sessions.
The content repeatedly describes malware and threat actors collecting host details such as OS version, hostname, architecture, CPU, memory, BIOS, domain, language, and other configuration data; e.g., "APT41 uses multiple built-in commands such as systeminfo and net config Workstation to enumerate victim system basic configuration information."
The content repeatedly describes threat actors, malware, and campaigns using HTTP and/or HTTPS for command and control, including examples such as BlackEnergy communicating with C2 over HTTP POST requests and many other families using HTTP/S for C2.
C2 traffic from ADVSTORESHELL is encrypted, then encoded with Base64 encoding... APT19 HTTP malware variant used Base64 to encode communications to the C2 server... APT33 has used base64 to encode command and control traffic.
The content repeatedly describes malware and threat actors using SSL, TLS, HTTPS, RSA, AES, Blowfish, RC4, ECIES, Diffie-Hellman, OpenSSL, WolfSSL, and mutual TLS to protect command and control traffic.
Multiple malware families and intrusion sets are described as encrypting C2 traffic using SSL/TLS/HTTPS (e.g., "used HTTPS for command and control", "encrypts C2 communications with TLS", "uses SSL for encrypting C2 communications", "TLS-encrypted WebSocket Protocol (WSS) for C2").
ADVSTORESHELL exfiltrates data over the same channel used for C2... Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers... numerous malware and groups sent victim data, files, credentials, or host information over existing C2 channels.
The content repeatedly describes threat actors and malware disabling or modifying security tools, EDR/AV, logging, firewall rules, integrity checkers, and security settings; e.g., 'Agrius used several mechanisms to try to disable security tools' and 'BlackByte disabled security tools such as Windows Defender and the Raccine anti-ransomware tool during operations.'
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Lyceum/OilRig malware family referenced as part of the subgroup's cloud-service-enabled C2 tooling.
A novel malware family referenced as used by OilRig.
Backdoor attributed to OilRig used in 2022–2023 targeting Israeli local government and healthcare (no further technical detail here).
Backdoor that uses a frequent scheduled task for C2 communication and command execution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.