OilCheck

MITRE
Malware Type:
Other
First seen:
Unknown
Last seen:
Unknown
Details:

[OilCheck](https://attack.mitre.org/software/S1171) is a C#/.NET downloader that has been used by [OilRig](https://attack.mitre.org/groups/G0049) since at least 2022 including against targets in Israel. [OilCheck](https://attack.mitre.org/software/S1171) uses draft messages created in a shared email account for C2 communication.(Citation: ESET OilRig Downloaders DEC 2023)

Associated Techniques (3)
ID ATT&CK Tactics
T1102.002 Bidirectional Communication -
T1105 Ingress Tool Transfer -
T1567 Exfiltration Over Web Service -
Used by Actors (1)
Metadata
ID: 464
Created: 13/01/2026 17:48
Updated: 06/03/2026 16:00