ISMAgent is a Windows backdoor associated with the Iranian threat group APT34, also known as OilRig or GreenBug. It has been used in espionage-oriented intrusions against organizations in the Middle East, including government environments, and is described as having a relatively sophisticated architecture with anti-analysis features.
ISMAgent supports resilient command-and-control by using HTTP communications with fallback to DNS tunneling when direct HTTP connectivity is unavailable. In DNS mode, it issues DNS AAAA queries and exchanges tasking and data through crafted subdomains and IPv6 responses. The malware generates a unique session identifier from a GUID, encodes host data for transmission, receives commands through DNS responses, and can upload command output or other collected data back to the operator through the tunnel. This design reflects OilRig’s broader preference for covert DNS-based C2 channels.
Observed delivery has included spearphishing campaigns using weaponized Microsoft Office documents that exploited CVE-2017-0199. In one documented infection chain, a malicious Office lure retrieved a secondary payload, launched PowerShell, and used certutil to decode content disguised as a base64-encoded digital certificate into the ISMAgent executable. ISMAgent has also been installed by a dedicated companion malware referred to as Agent Injector.
The malware is part of OilRig’s broader custom toolset alongside families such as Helminth, BONDUPDATER, QUADAGENT, and ALMA Communicator. Its role is consistent with persistent remote access and post-compromise operator control on infected Windows hosts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Sample change managment.dot (812d3c4fddf9bb81d507397345a29bb0) exploits CVE-2017-0199 and calls the following URL: http://www.msoffice-cdn[.]com/updatecdnsrv/prelocated/owa/auth/template.rtf | Recently we detected new samples and Infrastructure of ISMAgent, a trojan in use by Iranian Threat Group GreenBug. Interestingly, as part of the delivery mechanism, the malware is disguised as a base64 digital certificate and decoded via certutil.exe.
In Oct. 2017, the group developed the 'Agent Injector' (Trojan with the specific purpose of installing the ISMAgent backdoor)... ISMAgent - A backdoor which has a sophisticated architecture and contains anti-analysis techniques.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
OilRig malware ISMAgent falls back to its DNS tunneling mechanism if it is unable to reach the C2 server over HTTP.
Recently we detected new samples and Infrastructure of ISMAgent, a trojan in use by Iranian Threat Group GreenBug. Interestingly, as part of the delivery mechanism, the malware is disguised as a base64 digital certificate and decoded via certutil.exe.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
"The two encoding methods used by these tools... base16 and base64"; "...custom base64 encoder to strip out non-alphanumeric characters"; "...encoding mechanism... splits each hexadecimal byte into two nibbles..."
APT41 used the Steam community page as a fallback mechanism for C2. Bazar has the ability to use an alternative C2 server if the primary server fails. BISCUIT malware contains a secondary fallback command and control server that is contacted after the primary command and control server.
FIN7's Harpy backdoor malware can use DNS as a backup channel for C2 if HTTP fails. OilRig malware ISMAgent falls back to its DNS tunneling mechanism if it is unable to reach the C2 server over HTTP. QUADAGENT uses multiple protocols (HTTPS, HTTP, DNS) for its C2 server as fallback channels if communication with one is unsuccessful.
70 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
ISMAgent is a malware sample detected in the analysis, but specific details are not provided in the content.
Backdoor malware used by OilRig to support stealthy command and control operations.
Malware that uses DNS tunneling as a fallback C2 mechanism when HTTP fails.
A sophisticated backdoor with anti-analysis techniques, installed by Agent Injector in APT34 spearphishing attacks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.