ISMDoor is a Windows remote access Trojan associated with the Iranian-linked threat actors Greenbug and OilRig (APT34). It supports remote command execution, credential theft, keylogging, and data exfiltration. Its command interface can launch PowerShell scripts and auxiliary tools for credential harvesting and keystroke collection. ISMAgent is a variant of ISMDoor used by OilRig in cyberespionage operations.
Earlier ISMDoor versions used HTTP for command and control, while later versions implemented a custom bidirectional DNS channel using AAAA queries. The infected host initiates communications, sends data through specially crafted query names, and receives command-and-control data encoded in returned IPv6 addresses. This mechanism conceals command traffic and exfiltration within DNS communications. Observed samples include 64-bit Windows builds.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
OilRig Uses ISMDoor Variant; Possibly Linked to Greenbug Threat Group.
On 15 October 2017 a sample of ISMdoor was submitted to VirusTotal from Iraq.
CHRYSENE ... CAPABILITIES: Watering holes, 64-bit malware, covert C2 via IPv6 DNS, ISMDOOR
6 distinct techniques documented for this family, organized by ATT&CK tactic.
Two domains were used for command and control: thetareysecurityupdate[.]com securepackupdater[.]com
"Greenbug has shifted away from HTTP-based C2 communication with Ismdoor. It’s now relying on a new DNS-based attack technique... using DNS TXT record queries and responses to create a bidirectional command and control channel." Also: "custom covert channel using AAAA DNS queries for IPv6 addresses."
33 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor malware used by OilRig for persistent access and command and control.
Mentioned as the Trojan family from which ISMAgent is derived. Its own capabilities and direct deployment are not described.
Backdoor/trojan mentioned in a reference title related to OilRig activity.
ISMdoor is discussed as malware used by Iranian threat agent Greenbug, with samples submitted to VirusTotal and command-and-control domains tied to a broader domain-registration campaign impersonating Israeli high-tech and cybersecurity companies.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.