Mango — Malware Profile
Mango is a first-stage backdoor written in C#/.NET that was used by OilRig during the Juicy Mix campaign. Mango is the successor to Solar and includes additional exfiltration capabilities, the use of native APIs, and added detection evasion code.
MITRE ATT&CK techniques (13)
- T1027.013 Encrypted/Encoded File
- T1033 System Owner/User Discovery
- T1041 Exfiltration Over C2 Channel
- T1053.005 Scheduled Task
- T1071.001 Web Protocols
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1106 Native API
- T1132.001 Standard Encoding
- T1204.002 Malicious File
- T1573.001 Symmetric Cryptography
- T1573.002 Asymmetric Cryptography
- T1685 Disable or Modify Tools