Clayslide is a malicious Microsoft Excel delivery document family associated with the OilRig threat group. It has been used in targeted spearphishing operations in the Middle East, including campaigns against organizations in Saudi Arabia and at least one public utilities target. Clayslide documents rely on malicious macros and social-engineering lures, such as decoy spreadsheet content or prompts implying compatibility issues, to persuade victims to enable active content.
Once macros are enabled, Clayslide executes a staged infection chain that displays benign-looking decoy content while installing follow-on malware. Earlier observed variants deployed the script-based Helminth backdoor, using macro logic to write components to disk and establish persistence through a scheduled task. Later variants evolved to build and launch an HTA and VBScript chain that installed ALMA Communicator, a custom backdoor that uses DNS tunneling for command-and-control and exfiltration, and in at least one case also dropped a Mimikatz variant during initial compromise for credential harvesting.
Clayslide functions primarily as an initial-access and delivery mechanism rather than the final payload itself. Its role in OilRig operations demonstrates iterative development aimed at evading detection while preserving reliable execution of downstream implants. The malware family has been observed delivering multiple payloads over time, including Helminth and ALMA Communicator, and has been tied to targeted intrusion activity against financial, technology, defense-adjacent, and public utility organizations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
We observed spear-phishing emails sent between May 4 and May 12 of this year that delivered these malicious Excel spreadsheets, which we are tracking as ‘Clayslide’. ClaySlide documents contain malicious macros that display decoy content within the spreadsheet and installs a variant of a Helminth backdoor.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
In recent OilRig attacks, the threat actors purport to be legitimate service providers offering service and technical troubleshooting as a social engineering theme in their spear-phishing attacks. Earlier OilRig attacks appear to use fake job offers as a social engineering theme.
The malicious macro finishes the installation process by creating a scheduled task that is responsible for running the two scripts at regular intervals.
The .HTA file contains HTML that will run a VBScript that finally installs the malicious payload for this attack. | If the user clicks "Enable Content", a malicious macro will run
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as another OilRig tool previously analyzed for testing and evasion-related modifications to delivery documents.
Malicious delivery document used in spear-phishing attacks. It uses malicious Excel macros and an HTA/VBScript chain to install payloads including ALMA Communicator and Mimikatz, and establishes persistence via a scheduled task.
Clayslide refers to malicious Excel delivery documents with embedded macros used to install the script variant of Helminth after socially engineering victims to enable macros.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.