OilCheck is a C#/.NET downloader associated with the Iranian cyber-espionage actor OilRig, also tracked as APT34 and, for this activity cluster, Lyceum. It was observed in 2022 in intrusions targeting previously compromised organizations in Israel, including entities in healthcare, manufacturing, and local government. The malware is part of a broader set of lightweight OilRig tools that abuse trusted Microsoft cloud services for command-and-control and data theft in order to blend malicious traffic with normal enterprise activity.
OilCheck uses the REST-based Microsoft Graph API to access a shared Microsoft Office 365 Outlook account and conducts bidirectional command-and-control through draft messages. It retrieves commands embedded in Outlook drafts and can upload documents from compromised hosts back to the shared mailbox for exfiltration. This tradecraft parallels earlier OilRig tooling that used Exchange Web Services and draft-message workflows, but OilCheck specifically leverages Microsoft Graph for network communications. The malware’s role is consistent with a downloader used to maintain access, receive operator tasking, and support follow-on payload delivery and collection.
OilCheck has been linked to repeated targeting of the same victim organizations, reflecting OilRig’s long-running focus on persistent espionage access in the Middle East. The exact initial access vector for the observed compromises has not been publicly established.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
OilCheck, a C#/.NET downloader discovered in April 2022... uses the REST-based Microsoft Graph API to access a shared Microsoft Office 365 Outlook email account... communicating by creating email drafts.
OilCheck, a C#/.NET downloader discovered in April 2022... uses the REST-based Microsoft Graph API to access a shared Microsoft Office 365 Outlook email account... communicating by creating email drafts.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
ComRAT has the ability to use the Gmail web UI to receive commands and exfiltrate information. OilCheck can use a REST-based Microsoft Graph API to access draft messages in a shared Microsoft Office 365 Outlook email account used for C2 communication. SampleCheck5000 can use the Microsoft Office Exchange Web Services API to access an actor-controlled account and retrieve C2 commands and payloads placed in Draft messages.
ODAgent, first detected in February 2022, is a C#/.NET downloader that utilizes Microsoft OneDrive API for command-and-control (C2) communications. | These lightweight downloaders [...] are notable for using one of several legitimate cloud service APIs for [command-and-control] communication and data exfiltration: the Microsoft Graph OneDrive or Outlook APIs, and the Microsoft Office Exchange Web Services (EWS) API.
"Magic Hound malware can use a SOAP Web service to communicate with its C2 server."; "OilCheck can use a REST-based Microsoft Graph API ... used for C2 communication."
The adversaries had communicated to both Dropbox and Pastebin. APT28 has used Google Drive for C2. APT37 leverages social networking sites and cloud platforms (AOL, Twitter, Yandex, Mediafire, pCloud, Dropbox, and Box) for C2.
"APT39 has communicated with C2 through files uploaded to and downloaded from DropBox."; "RIFLESPINE can retrieve C2 commands from an encrypted file on Google Drive then upload the results ... back to Google Drive."; "CloudDuke uses a Microsoft OneDrive account to exchange commands and stolen data"
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware referenced as prior OilRig tooling that used Microsoft Graph with Outlook drafts for C2.
Malware cited as using Microsoft Graph to access Outlook drafts for command-and-control.
A downloader used by OilRig that retrieves commands from draft messages and uses the Microsoft Graph API for command-and-control communications.
C#/.NET downloader that uses Microsoft Graph (Outlook) API and draft messages in an attacker-controlled Office 365 mailbox for bidirectional C2 and exfiltration; manually constructs Graph API requests; downloads/executes payloads and exfiltrates data via the same account.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.