RDAT is a Windows backdoor associated with OilRig-linked cyberespionage activity and has been observed in operations targeting government environments in the Middle East, including Kurdistan Regional Government systems. It is used for covert command-and-control, task execution, surveillance, and data theft, and reflects OilRig’s long-running pattern of abusing legitimate Microsoft-hosted services and resilient multi-channel communications.
RDAT supports multiple command-and-control mechanisms. Reported variants have exchanged commands and results through Exchange Web Services email messages, used DNS-based command-and-control with data embedded in encoded subdomains, and fallen back to HTTP when DNS communications were unavailable. Its network traffic has used AES-encrypted content, including non-standard Base64 variants with character substitutions and Base32-encoded subdomains to hinder detection. RDAT can also deobfuscate and decrypt payloads or files received from operators, including content protected with Base64 and AES.
Functionally, RDAT provides typical espionage backdoor capabilities. It can capture screenshots from infected systems, exfiltrate collected data through its established command-and-control channel, upload and download files in fixed-size chunks, and issue SOAP requests in support of its email-based communications. It has also been documented deleting already processed command messages from the remote mailbox and deleting itself from the compromised host, indicating anti-forensic and operational cleanup behavior.
For persistence, RDAT has created a Windows service on victim machines. It has also used masquerading, including posing as VMware-related software, to reduce suspicion. Reporting has noted code and tradecraft relationships between RDAT and other OilRig or OilRig-adjacent tooling, and RDAT has been cited alongside newer tools developed after public exposure of earlier OilRig capabilities. ESET has also noted code similarities between RDAT and PrimeCache and assessed BladedFeline as a subgroup of OilRig partly based on the presence of RDAT on compromised systems.
Overall, RDAT is best characterized as a modular espionage backdoor for Windows environments, emphasizing stealthy communications, surveillance, file transfer, persistence, and exfiltration in support of long-term intelligence collection.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
We discovered a previously unreported version of the OilRig backdoor RDAT on two KRG victim systems.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe ... APT1 ... used ... AcroRD32.exe ... as a name for malware ... APT28 ... changed extensions on files containing exfiltrated data to make them appear benign ... APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update.
Akira has used legitimate names and locations for files to evade defenses.
Eset first observed it in 2023, when it planted a backdoor into systems used by government diplomats from the Kurdistan Regional Government.
Many entries explicitly describe deleting artifacts 'to cover tracks,' 'evade detection,' 'remove evidence,' 'reduce their footprint,' or as part of 'post-intrusion cleanup process.' Examples include APT28 deleting files to cover tracks, FIN5 using SDelete to clean up the environment, and Dragonfly deleting operational files as part of cleanup.
APT41 used the Steam community page as a fallback mechanism for C2. Bazar has the ability to use an alternative C2 server if the primary server fails. BISCUIT malware contains a secondary fallback command and control server that is contacted after the primary command and control server.
Several entries describe broader use of HTTP/HTTPS and related web mechanisms for C2, including "Crutch has conducted C2 communications with a Dropbox account using the HTTP API," "BLUELIGHT can use HTTP/S for C2 using the Microsoft Graph API," and "Small Sieve can contact actor-controlled C2 servers by using the Telegram API over HTTPS."
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
FIN7's Harpy backdoor malware can use DNS as a backup channel for C2 if HTTP fails. OilRig malware ISMAgent falls back to its DNS tunneling mechanism if it is unable to reach the C2 server over HTTP. QUADAGENT uses multiple protocols (HTTPS, HTTP, DNS) for its C2 server as fallback channels if communication with one is unsuccessful.
The content repeatedly describes malware and threat actors that can "download files from C2," "download additional payloads," "upload and download files," "retrieve payloads from the C2 server," and "copy files to remote machines."
ADVSTORESHELL C2 traffic is encrypted, then encoded with Base64 encoding. APT19 HTTP malware variant used Base64 to encode communications to the C2 server. APT33 has used base64 to encode command and control traffic.
Adversaries may encode data with a non-standard data encoding system to make the content of command and control traffic more difficult to detect. Command and control (C2) information can be encoded using a non-standard data encoding system that diverges from existing protocol specifications.
AppleSeed has divided files if the size is 0x1000000 bytes or more. APT28 has split archived exfiltration files into chunks smaller than 1MB. APT41 transfers post-exploitation files dividing the payload into fixed-size chunks to evade detection.
ADVSTORESHELL exfiltrates data over the same channel used for C2.
Ebury can exfiltrate SSH credentials through custom DNS queries.
Crutch can exfiltrate data over the primary C2 channel (Dropbox HTTP API)... ODAgent can use an attacker-controlled OneDrive account to receive C2 commands and to exfiltrate files... OilBooster can use an actor-controlled OneDrive account for C2 communication and exfiltration... ZIRCONIUM has exfiltrated files via the Dropbox API C2.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
38 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as an example of malware previously using Microsoft-hosted services for C2 in comparison to Cavern.
Malware cited as prior OilRig tooling that used Microsoft-hosted services for command-and-control via EWS email messages.
Backdoor cité comme point de comparaison pour l’usage de services Microsoft hébergés comme canal C2.
Malware previously associated with OilRig that used EWS email messages for command-and-control.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.