OilCheck is a C#/.NET downloader associated with the Iranian cyber-espionage actor OilRig, including activity later tracked under the Lyceum subgroup. It was identified in 2022 in operations targeting previously compromised organizations in Israel, including entities in healthcare, manufacturing, and local government. The malware is part of a broader cluster of lightweight OilRig downloaders that shifted command-and-control traffic into legitimate Microsoft cloud services to blend with normal enterprise activity and reduce infrastructure exposure.
OilCheck uses the Microsoft Graph API to access a shared Microsoft Office 365 Outlook account and exchanges tasking through draft messages. It follows the same general draft-based command retrieval pattern seen in related OilRig tooling, but uses Microsoft Graph rather than Exchange Web Services for network communications. Commands are embedded in Outlook drafts, and the malware can retrieve those commands from the shared mailbox. OilCheck also supports uploading documents from compromised hosts to the same shared Outlook account, providing an exfiltration channel over trusted Microsoft-hosted services.
The malware’s observed role is as a downloader and cloud-backed command relay within post-compromise espionage operations. Its use of shared attacker-operated cloud accounts across multiple victims is consistent with OilRig tradecraft and with the group’s long-running preference for covert C2 mechanisms built on legitimate email and cloud platforms. OilCheck has been discussed alongside related families such as SampleCheck5000, ODAgent, and OilBooster, which collectively illustrate a campaign pattern centered on persistent access, payload delivery, and data theft in Israeli networks.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
OilCheck, a C#/.NET downloader discovered in April 2022... uses the REST-based Microsoft Graph API to access a shared Microsoft Office 365 Outlook email account... communicating by creating email drafts.
OilCheck, a C#/.NET downloader discovered in April 2022... uses the REST-based Microsoft Graph API to access a shared Microsoft Office 365 Outlook email account... communicating by creating email drafts.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
ComRAT has the ability to use the Gmail web UI to receive commands and exfiltrate information. OilCheck can use a REST-based Microsoft Graph API to access draft messages in a shared Microsoft Office 365 Outlook email account used for C2 communication. SampleCheck5000 can use the Microsoft Office Exchange Web Services API to access an actor-controlled account and retrieve C2 commands and payloads placed in Draft messages.
ODAgent, first detected in February 2022, is a C#/.NET downloader that utilizes Microsoft OneDrive API for command-and-control (C2) communications. | These lightweight downloaders [...] are notable for using one of several legitimate cloud service APIs for [command-and-control] communication and data exfiltration: the Microsoft Graph OneDrive or Outlook APIs, and the Microsoft Office Exchange Web Services (EWS) API.
"Magic Hound malware can use a SOAP Web service to communicate with its C2 server."; "OilCheck can use a REST-based Microsoft Graph API ... used for C2 communication."
The adversaries had communicated to both Dropbox and Pastebin. APT28 has used Google Drive for C2. APT37 leverages social networking sites and cloud platforms (AOL, Twitter, Yandex, Mediafire, pCloud, Dropbox, and Box) for C2.
"APT39 has communicated with C2 through files uploaded to and downloaded from DropBox."; "RIFLESPINE can retrieve C2 commands from an encrypted file on Google Drive then upload the results ... back to Google Drive."; "CloudDuke uses a Microsoft OneDrive account to exchange commands and stolen data"
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as an example of malware previously using Microsoft-hosted services for C2 in comparison to Cavern.
Malware referenced as prior OilRig tooling that used Microsoft Graph with Outlook drafts for C2.
Backdoor cité comme point de comparaison pour l’usage de Microsoft Graph/Outlook drafts comme canal C2.
Malware cited as using Microsoft Graph to access Outlook drafts for command-and-control.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.