Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
the 2023 attacks targeting organizations in the Middle East with the PowerExchange and MrPerfectionManager backdoors
2 distinct techniques documented for this family, organized by ATT&CK tactic.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A backdoor used in 2023 attacks attributed to OilRig against Middle Eastern organizations.
A backdoor associated with OilRig that uses email-based command-and-control protocols for data exfiltration.
Email-based C2 backdoor attributed to OilRig; uses victim organization’s Exchange server to transmit messages to/from attacker accounts for exfiltration/C2 (contrasted with draft-based attacker-controlled mailbox approach).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.