ODAgent is a C#/.NET downloader first detected in February 2022 and attributed in the provided reporting to the Iranian state-sponsored cyber espionage actor OilRig (also tracked as APT34; later reporting places this activity under the OilRig subgroup Lyceum/HEXANE/Storm-0133). It uses the Microsoft OneDrive API via Microsoft Graph for command-and-control communications with an attacker-controlled OneDrive account. Its documented capabilities are limited to retrieving backdoor commands and payloads, downloading and executing payloads, and exfiltrating staged files to the actor-controlled OneDrive account. The malware was observed as part of OilRig campaigns in 2022 against previously compromised organizations in Israel, including a manufacturing company, while broader related activity targeted healthcare, manufacturing, and local government sectors. The reporting states that OilRig used legitimate Microsoft cloud APIs and shared attacker-operated cloud accounts to blend malicious traffic with normal enterprise cloud activity and conceal infrastructure. The initial access vector for the compromises was not identified in the provided content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
ODAgent, first detected in February 2022, is a C#/.NET downloader that utilizes Microsoft OneDrive API for command-and-control (C2) communications, allowing the threat actor to download and execute payloads, and exfiltrate staged files.
In February 2022, we detected a new OilRig downloader... ODAgent is a C#/.NET downloader... uses the Microsoft OneDrive API for C&C communications.
In February 2022, we detected a new OilRig downloader... ODAgent is a C#/.NET downloader... uses the Microsoft OneDrive API for C&C communications.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
During the 2016 Ukraine Electric Power Attack, Sandworm Team used the xp_cmdshell command in MS-SQL. During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run cmd.exe commands on multiple victim machines. Numerous malware families and groups are described as using cmd.exe, cmd /c, Windows command shell, or command-line interfaces to execute commands, payloads, reconnaissance, persistence, cleanup, and ransomware actions.
The content repeatedly describes adversaries and malware deleting files, directories, droppers, scripts, logs, archives, staged data, and other artifacts from compromised systems, e.g., 'APT29 has used SDelete to remove artifacts from victim networks' and 'Lazarus Group malware has deleted files in various ways, including "suicide scripts" to delete malware binaries from the victim.'
The content repeatedly describes malware and threat actors decoding, decrypting, or deobfuscating payloads, strings, configuration data, commands, and C2 traffic prior to execution or use, e.g., 'APT28 macro uses the command certutil -decode to decode contents of a .txt file storing the base64 encoded payload' and 'Action RAT can use Base64 to decode actor-controlled C2 server communications.'
These lightweight downloaders [...] are notable for using one of several legitimate cloud service APIs for [command-and-control] communication and data exfiltration: the Microsoft Graph OneDrive or Outlook APIs, and the Microsoft Office Exchange Web Services (EWS) API. | ODAgent, first detected in February 2022, is a C#/.NET downloader that utilizes Microsoft OneDrive API for command-and-control (C2) communications.
"Magic Hound malware can use a SOAP Web service to communicate with its C2 server."; "OilCheck can use a REST-based Microsoft Graph API ... used for C2 communication."
The adversaries had communicated to both Dropbox and Pastebin. APT28 has used Google Drive for C2. APT37 leverages social networking sites and cloud platforms (AOL, Twitter, Yandex, Mediafire, pCloud, Dropbox, and Box) for C2.
"APT39 has communicated with C2 through files uploaded to and downloaded from DropBox."; "RIFLESPINE can retrieve C2 commands from an encrypted file on Google Drive then upload the results ... back to Google Drive."; "CloudDuke uses a Microsoft OneDrive account to exchange commands and stolen data"
Clambling can use Dropbox to download malicious payloads, send commands, and receive information. ODAgent can use the Microsoft Graph API to access an attacker-controlled OneDrive account and retrieve payloads and backdoor commands. OilBooster uses the Microsoft Graph API to connect to an actor-controlled OneDrive account to download and execute files and shell commands.
ADVSTORESHELL exfiltrates data over the same channel used for C2... Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers... numerous malware and groups sent victim data, files, credentials, or host information over existing C2 channels.
Crutch can exfiltrate data over the primary C2 channel (Dropbox HTTP API)... ODAgent can use an attacker-controlled OneDrive account to receive C2 commands and to exfiltrate files... OilBooster can use an actor-controlled OneDrive account for C2 communication and exfiltration... ZIRCONIUM has exfiltrated files via the Dropbox API C2.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A C#/.NET downloader used by OilRig that communicates via the Microsoft OneDrive API to receive commands, download and execute payloads, and exfiltrate staged files.
C#/.NET OneDrive/Graph-based downloader (precursor to OilBooster) using an attacker-controlled OneDrive account with victim-specific folders; supports limited command execution, payload download/decrypt/decompress, and exfiltration of staged files; deletes processed remote files.
Malware that uses attacker-controlled OneDrive accounts for data exfiltration.
Backdoor that uses Microsoft Graph API/OneDrive for payload retrieval and command-and-control.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.