QUADAGENT is a PowerShell-based backdoor associated with the Iranian state-aligned threat group OilRig, also tracked as APT34. It has been used in espionage operations targeting organizations including government entities and technology service providers, with reporting also linking it to campaigns against healthcare organizations in the Middle East. The malware is executed through PowerShell and also uses VBScript components as part of its operation. Reported delivery includes spearphishing campaigns in which QUADAGENT was distributed alongside other OilRig tooling.
On an infected Windows host, QUADAGENT establishes persistence by creating a scheduled task and stores operational state in the current user Registry hive, including a unique session identifier for the compromised system and a pre-shared key used to protect command-and-control traffic. It checks for the presence of Registry values associated with its scheduled-task-based persistence and includes cleanup functionality to remove its Registry artifacts and scheduled task.
QUADAGENT performs basic host reconnaissance, including collecting the current username and the domain to which the system belongs. Its command-and-control design emphasizes resilience and obfuscation: communications are encoded with Base64, strings and scripts are protected with AES using a pre-shared key, and the malware can fall back across multiple C2 protocols, including HTTPS, HTTP, and DNS, if one channel is unavailable. These characteristics align with OilRig tradecraft focused on stealthy, script-driven persistence and flexible communications on compromised Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
OilRig Targets Technology Service Provider and Government Agency with QUADAGENT.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
In July 2018, they launched multiple attacks using spearphishing email ... Their initial infection paths were based on watering hole attacks using compromised web servers.
They use phishing emails to deliver weaponized Microsoft Excel documents... Between 2014 to 2016, the group's attack campaigns targeted banks and technology organizations in Saudi Arabia with phishing emails that included weaponized Microsoft Excel attachments.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
most of their malware infect the target system with VisualBasic and PowerShell (.ps1) scripts.
The content repeatedly describes threat actors and malware using PowerShell to execute payloads, run commands, download additional malware, perform lateral movement, evade defenses, and execute scripts in memory. | Examples include: 'APT28 downloads and executes PowerShell scripts and performs PowerShell commands'; 'APT3 has used PowerShell on victim systems to download and run payloads after exploitation'; 'TA505 has used PowerShell to download and execute malware and reconnaissance scripts.'
actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe ... APT1 ... used ... AcroRD32.exe ... as a name for malware ... APT28 ... changed extensions on files containing exfiltrated data to make them appear benign ... APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update.
Akira has used legitimate names and locations for files to evade defenses.
Many examples describe post-intrusion cleanup, anti-forensics, and removal of artifacts such as logs, scripts, malware components, scheduled tasks, registry keys, and temporary files.
The content repeatedly describes malware and threat actors deleting files, directories, droppers, logs, scripts, temporary files, exfiltrated archives, and uninstalling themselves to cover tracks or reduce forensic artifacts.
QUADAGENT has a command to delete its Registry key and scheduled task. Silence has deleted artifacts, including scheduled tasks.
The content repeatedly describes malware and threat actors querying, enumerating, opening, and reading Windows Registry keys and values, e.g., "APT41 queried registry values to determine items such as configured RDP ports and network configurations" and "Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface."
APT41 used the Steam community page as a fallback mechanism for C2. Bazar has the ability to use an alternative C2 server if the primary server fails. BISCUIT malware contains a secondary fallback command and control server that is contacted after the primary command and control server.
Machete has sent data over HTTP if FTP failed. Mis-Type first attempts to use a Base64-encoded network protocol over a raw TCP socket for C2, and if that method fails, falls back to a secondary HTTP-based protocol. NETEAGLE will send beacons via an HTTP POST request if the infected host is configured to a proxy.
FIN7's Harpy backdoor malware can use DNS as a backup channel for C2 if HTTP fails. OilRig malware ISMAgent falls back to its DNS tunneling mechanism if it is unable to reach the C2 server over HTTP. QUADAGENT uses multiple protocols (HTTPS, HTTP, DNS) for its C2 server as fallback channels if communication with one is unsuccessful.
31 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
57 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom backdoor used in OilRig intrusions for remote access and persistence (as described).
Uses VBScripts.
Backdoor that gathers the victim username.
Malware that uses PowerShell scripts for execution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.