OopsIE APT Trojan
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Threat details
OopsIE is delivered via spear phishing email containing a direct link, with OilRig performing extensive social engineering and reconnaissance beforehand.
Once installed, the trojan creates a VBScript file to maintain persistence and run itself every three minutes if it is not already active. It then initiates communication with its command and control (C2) infrastructure using the the InternetExplorer application object over HTTP. This results in the C2 traffic appearing legitimate.
The purpose of OopsIE appears to be to collect information on the system and user, however it is also able to execute commands and transfer files.
Remediation advice
To prevent and detect a trojan infection, ensure that:Remediation steps
Last edited: 9 October 2020 1:53 pm