ISMdoor is a Windows remote access trojan associated with the Iranian threat actor Greenbug, also tracked within broader OilRig activity, and has been linked to credential theft operations against organizations in the Middle East, including activity assessed as supporting Shamoon-related intrusion chains. It has been described as a credential-stealing RAT used to obtain access ahead of disruptive or destructive follow-on operations.
The malware supports remote command execution and has been observed evolving from conventional HTTP-based command and control to a more covert DNS-based channel. Reported variants use specially crafted DNS queries, including TXT-based exchanges and AAAA/IPv6-related mechanisms, to create a bidirectional command channel in which the infected host drives communications, receives commands, and can return data to the operator. This tradecraft is notable for stealth rather than speed and is consistent with long-term espionage-oriented operations.
Observed functionality includes credential theft and keylogging. Reported commands indicate execution of tooling likely intended to dump credentials and bypass user account controls, including use of Mimikatz-related functionality, as well as separate keylogger execution. ISMdoor has also been associated with data exfiltration over its covert DNS channel.
Infrastructure linked to ISMdoor has been tied to lookalike domains impersonating Israeli technology and cybersecurity companies and at least one Saudi industrial company, suggesting preparation for targeted operations, although public reporting did not establish that the impersonated firms were successfully compromised. ISMdoor has also been referenced alongside other malware used in OilRig operations, including ISMAgent, Helminth, PICKPOCKET, and ZeroCleare. Public reporting specifically characterizes ISMdoor as 64-bit malware and highlights its covert IPv6-over-DNS command-and-control design as a distinguishing feature.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
OilRig Uses ISMDoor Variant; Possibly Linked to Greenbug Threat Group.
On 15 October 2017 a sample of ISMdoor was submitted to VirusTotal from Iraq.
CHRYSENE ... CAPABILITIES: Watering holes, 64-bit malware, covert C2 via IPv6 DNS, ISMDOOR
6 distinct techniques documented for this family, organized by ATT&CK tactic.
Two domains were used for command and control: thetareysecurityupdate[.]com securepackupdater[.]com
"Greenbug has shifted away from HTTP-based C2 communication with Ismdoor. It’s now relying on a new DNS-based attack technique... using DNS TXT record queries and responses to create a bidirectional command and control channel." Also: "custom covert channel using AAAA DNS queries for IPv6 addresses."
33 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor malware used by OilRig for persistent access and command and control.
Backdoor/trojan mentioned in a reference title related to OilRig activity.
ISMdoor is discussed as malware used by Iranian threat agent Greenbug, with samples submitted to VirusTotal and command-and-control domains tied to a broader domain-registration campaign impersonating Israeli high-tech and cybersecurity companies.
Backdoor malware used by Iranian threat agent Greenbug, with observed command-and-control domains including thetaraysecurityupdate[.]com and securepackupdater[.]com in a campaign involving lookalike domains impersonating Israeli high-tech and cybersecurity companies.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.