RDAT is a Windows backdoor associated with OilRig activity and later observed on Kurdistan Regional Government systems in intrusions linked to the Iran-aligned BladedFeline cluster. It is used for long-term espionage access and supports multiple covert command-and-control mechanisms, including Exchange Web Services email messaging, email attachments, HTTP, and DNS-based communications using base32-encoded subdomains. RDAT has been observed creating a Windows service for persistence and masquerading as legitimate software, including use of benign-looking executable names and service names.
The malware supports bidirectional file transfer and can exfiltrate data over established command-and-control channels, including Exchange Web Services. Reported functionality includes uploading files in fixed-size chunks over HTTP POST, downloading data in chunks from command-and-control infrastructure, taking screenshots from infected systems, and embedding data within BMP images prior to exfiltration. RDAT communications have also been protected with AES-encrypted ciphertext. Similarities between RDAT and other implants linked to OilRig have been noted, including code-level overlap with the PrimeCache IIS backdoor.
RDAT is part of a broader ecosystem of OilRig tooling used against government and regional political targets in the Middle East, particularly Kurdish and Iraqi government entities. Its use of enterprise messaging infrastructure and DNS-based fallback or alternate communications reflects an emphasis on blending malicious traffic into normal administrative and cloud-connected environments while maintaining resilient access.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
RDAT malware exchanged commands and results through EWS email messages...
We discovered a previously unreported version of the OilRig backdoor RDAT on two KRG victim systems.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
During the 2016 Ukraine Electric Power Attack, DLLs and EXEs with filenames associated with common electric power sector protocols were used to masquerade files.
Akira has used legitimate names and locations for files to evade defenses.
Eset first observed it in 2023, when it planted a backdoor into systems used by government diplomats from the Kurdistan Regional Government.
Many entries explicitly describe deleting artifacts 'to cover tracks,' 'evade detection,' 'remove evidence,' 'reduce their footprint,' or as part of 'post-intrusion cleanup process.' Examples include APT28 deleting files to cover tracks, FIN5 using SDelete to clean up the environment, and Dragonfly deleting operational files as part of cleanup.
"Agent Tesla can capture screenshots of the victim’s desktop"; "AppleSeed can take screenshots on a compromised host"; "APT28 has used tools to take screenshots from victims"; "Cobalt Strike's Beacon payload is capable of capturing screenshots"; "PowerSploit's Get-TimedScreenshot Exfiltration module can take screenshots at regular intervals"; "Hydraq includes a component based on the code of VNC that can stream a live feed of the desktop"
Several entries describe broader use of HTTP/HTTPS and related web mechanisms for C2, including "Crutch has conducted C2 communications with a Dropbox account using the HTTP API," "BLUELIGHT can use HTTP/S for C2 using the Microsoft Graph API," and "Small Sieve can contact actor-controlled C2 servers by using the Telegram API over HTTPS."
The content repeatedly describes threat actors and malware using HTTP and HTTPS for command and control, such as: "Sandworm Team used BlackEnergy to communicate between compromised hosts and their command-and-control servers via HTTP post requests."
AppleSeed has divided files if the size is 0x1000000 bytes or more. APT28 has split archived exfiltration files into chunks smaller than 1MB. APT41 transfers post-exploitation files dividing the payload into fixed-size chunks to evade detection.
Helminth splits data into chunks up to 23 bytes and sends the data in DNS queries to its C2 server. Kevin can exfiltrate data to the C2 server in 27-character chunks. OopsIE exfiltrates command output and collected files to its C2 server in 1500-byte blocks.
Cannon exfiltrates collected data over email via SMTP/S and POP3/S C2 channels. CURIUM has used IMAP and SMTPS for exfiltration via tools such as IMAPLoader. Kevin can send data from the victim host through a DNS C2 channel.
Crutch can exfiltrate data over the primary C2 channel (Dropbox HTTP API)... ODAgent can use an attacker-controlled OneDrive account to receive C2 commands and to exfiltrate files... OilBooster can use an actor-controlled OneDrive account for C2 communication and exfiltration... ZIRCONIUM has exfiltrated files via the Dropbox API C2.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
24 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware cited as prior OilRig tooling that used Microsoft-hosted services for command-and-control via EWS email messages.
Malware previously associated with OilRig that used EWS email messages for command-and-control.
OilRig-associated backdoor referenced as similar to PrimeCache; specific functionality not described in the provided content.
An OilRig backdoor observed on compromised KRG systems; the report highlights code and functional similarities between RDAT and PrimeCache, including command parsing and shell command execution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.