ISMAgent is a Windows backdoor and variant of ISMDoor used by the Iranian-linked threat group OilRig (APT34), with deployments also attributed to Greenbug. Introduced in 2017, it supports cyberespionage operations against Middle Eastern organizations, including government entities, Israeli IT vendors, and financial institutions. It provides remote command execution and data exfiltration and incorporates anti-analysis techniques.
ISMAgent communicates with its command-and-control server over HTTP and falls back to DNS tunneling when HTTP connectivity fails. Its DNS implementation uses the Windows DnsQuery_A API to issue AAAA queries, transmitting encoded system information and other data through crafted subdomains and receiving commands through IPv6 responses. The protocol uses GUID-based session identifiers, acknowledgments, and transfer-control messages. Received commands can invoke PowerShell, and file contents can be uploaded through the DNS tunnel.
Deployment mechanisms include spearphishing and malicious Microsoft Office documents exploiting CVE-2017-0199. An observed infection chain retrieved an RTF payload that launched hidden PowerShell, downloaded ISMAgent disguised as a Base64-encoded digital certificate, and decoded it using the Windows Certutil utility. ISMAgent has also been deployed through ISMInjector, a packed .NET loader that accesses its embedded payload using Assembly.Load, enabling in-memory loading and reducing exposure to file-based detection.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Sample change managment.dot (812d3c4fddf9bb81d507397345a29bb0) exploits CVE-2017-0199 and calls the following URL: http://www.msoffice-cdn[.]com/updatecdnsrv/prelocated/owa/auth/template.rtf | Recently we detected new samples and Infrastructure of ISMAgent, a trojan in use by Iranian Threat Group GreenBug. Interestingly, as part of the delivery mechanism, the malware is disguised as a base64 digital certificate and decoded via certutil.exe.
In Oct. 2017, the group developed the 'Agent Injector' (Trojan with the specific purpose of installing the ISMAgent backdoor)... ISMAgent - A backdoor which has a sophisticated architecture and contains anti-analysis techniques.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The group further improved its capabilities by adding a new Trojan called ISMAgent, a variant of the ISMDoor Trojan.
Recently we detected new samples and Infrastructure of ISMAgent, a trojan in use by Iranian Threat Group GreenBug. Interestingly, as part of the delivery mechanism, the malware is disguised as a base64 digital certificate and decoded via certutil.exe.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
The OilRig APT Group used a packed .NET malware sample known as ISMInjector to evade signature based detection. During the unpacking routine, the sample uses the Assembly.Load function to access the embedded next stage malware known as ISMAgent.
Interestingly, as part of the delivery mechanism, the malware is disguised as a base64 digital certificate and decoded via certutil.exe.
APT41 used the Steam community page as a fallback mechanism for C2. Bazar has the ability to use an alternative C2 server if the primary server fails. BISCUIT malware contains a secondary fallback command and control server that is contacted after the primary command and control server.
FIN7's Harpy backdoor malware can use DNS as a backup channel for C2 if HTTP fails. OilRig malware ISMAgent falls back to its DNS tunneling mechanism if it is unable to reach the C2 server over HTTP. QUADAGENT uses multiple protocols (HTTPS, HTTP, DNS) for its C2 server as fallback channels if communication with one is unsuccessful.
70 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
ISMAgent is a malware sample detected in the analysis, but specific details are not provided in the content.
Backdoor malware used by OilRig to support stealthy command and control operations.
ISMDoor variant introduced into APT34's espionage toolkit in 2017. Deployed using ISMInjector; the surrounding discussion highlights anti-analysis measures in the group's tools.
An embedded next-stage malware payload loaded from ISMInjector through .NET Assembly.Load.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.