OilBooster

Malware

⚠️ Overview

OilBooster is a modular backdoor malware first documented in 2017 by Palo Alto Networks Unit 42, primarily used by the Iranian threat group APT33 (Elfin) for cyber espionage against energy, aerospace, and government sectors. It belongs to the category of remote access trojans (RATs) with capabilities for persistent control and data theft, operating as part of a multi‑stage implant toolset.

🔧 Technical Capabilities

OilBooster propagates via spear‑phishing emails containing malicious Microsoft Office documents that exploit CVE‑2017‑0199 (Microsoft Office Equation Editor buffer overflow) to drop the payload. It establishes command‑and‑control (C2) communication over HTTP/HTTPS using encrypted channels, often mimicking legitimate traffic to evade network detection. Persistence is achieved through Windows registry run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun) and scheduled tasks under MicrosoftWindowsRas. The malware employs evasion techniques such as anti‑debugging, sandbox detection via CPU and disk checks, and obfuscated PowerShell scripts for in‑memory execution. It can steal credentials, exfiltrate files, and deploy additional payloads like the Bonkers downloader, as observed by CrowdStrike in 2018.

📜 History & Notable Incidents

First identified in July 2017 targeting Saudi Arabian energy companies, OilBooster was later linked to APT33’s 2018 campaign against the U.S. aviation sector (CVEs CVE‑2017‑0199 and CVE‑2017‑11882 exploited). In 2019, the malware was used in attacks on Japanese defense contractors, as reported by JPCERT/CC. No major law enforcement actions have been publicly recorded, though the group’s infrastructure has been dismantled in part by industry takedown efforts.

🔍 Detection Indicators

Known file hashes (SHA‑256) include a3f5c9b8e1d2... (example) from Unit 42's 2017 report; behavioral indicators include outbound HTTPS connections to IP ranges 185.130.5.x and domains using the .top TLD. Registry persistence keys under HKCU...RunOilBooster and mutex names starting with OilB# are common. User‑Agent strings often spoof Mozilla/5.0 (Windows NT 6.1; Win64; x64) with non‑standard ordering.

☠️ Risk & Impact

OilBooster enables full remote control of infected hosts, leading to exfiltration of intellectual property, critical infrastructure schematics, and credentials. Losses are estimated in the millions of dollars per campaign, primarily affecting the energy, aerospace, and defense industries. According to Dragos’ 2020 report, the malware has been used to compromise industrial control system (ICS) environments in the Middle East.

🛡️ Mitigation

Apply patches for CVE‑2017‑0199 and CVE‑2017‑11882; enable macro‑blocking via Group Policy and use behavioral detection rules for suspicious PowerShell execution. Deploy network‑based IPS signatures for OilBooster C2 traffic patterns as documented in MITRE ATT&CK technique T1071.001, and restrict run‑key and scheduled‑task creation using Windows Defender Attack Surface Reduction rules.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.