OilRig — APT Profile
OilRig is a suspected Iranian threat group that has targeted Middle Eastern and international victims since at least 2014. The group has targeted a variety of sectors, including financial, government, energy, chemical, and telecommunications. It appears the group carries out supply chain attacks, leveraging the trust relationship between organizations to attack their primary targets. The group works on behalf of the Iranian government based on infrastructure details that contain references to Iran, use of Iranian infrastructure, and targeting that aligns with nation-state interests.Description reproduced from MITRE ATT&CK. © The MITRE Corporation, reproduced and distributed with permission.
Also tracked as
COBALT GYPSY, IRN2, APT34, Helix Kitten, Evasive Serpens, Hazel Sandstorm, EUROPIUM, ITG13, Earth Simnavaz, Crambus, TA452, Twisted Kitten, ATK40, G0049, SOLAR ION, CHRYSENE
IntelFusions coverage (8)
- Spyware on Israeli targets routes commands through Google 2026-08-11 · Nation-State
- Kaspersky links Israel calendar spyware to Iran's OilRig hackers 2026-07-21 · Nation-State
- Stealthy spies hit Middle East governments by hiding in Telegram traffic 2026-07-20 · Nation-State
- New spy malware hides its commands inside Microsoft 365 calendars 2026-07-20 · Nation-State
- Iran-linked group targets Israeli firms with a stealthy new spy toolkit 2026-07-06 · Nation-State
- OilRig Outer Space and Juicy Mix Campaigns: Solar and Mango C#/.NET Backdoors Target Israeli Organizations with XOR Encryption, Compromised Israeli Websites as C2 2026-02-16 · Nation-State
- OilRig's RDAT Backdoor Deploys Novel Steganographic Email C2 via Exchange Web Services: BMP-Hidden Commands Against Middle Eastern Telecom 2026-02-16 · Nation-State
- APT39: Iran's Personal Data Harvesting Machine Targets Telecom and Travel Industries for Surveillance Operations 2026-02-16 · Nation-State
Tools & malware
- BONDUPDATER Backdoor
- certutil LOLBin
- ftp Exfiltration
- Helminth Backdoor
- ipconfig Network Reconnaissance
- ISMInjector Dropper
- LaZagne Credential Harvesting
- Mango Mobile Malware
- Mimikatz Credential Harvesting
- Net Network Reconnaissance
- netstat Network Reconnaissance
- ngrok Tunneling Tool
- ODAgent Backdoor
- OilBooster Backdoor
- OilCheck Backdoor
- OopsIE Backdoor
- PowerExchange Backdoor
- POWRUNER Backdoor
- PsExec Remote Execution
- QUADAGENT Backdoor
- RDAT Backdoor
- Reg LOLBin
- RGDoor Backdoor
- SampleCheck5000 Discovery
- SEASHARPEE Web Shell
- SideTwist Backdoor
- Solar Backdoor
- Systeminfo Discovery
- Tasklist Discovery
- ZeroCleare Wiper
Vendor research
- New Targeted Attack in the Middle East by APT34, a Suspected Iranian Threat Group, Using CVE-2017-11882 Exploit Sardiwal, M, et al
- COBALT GYPSY Threat Profile Secureworks
- new analysis from Kaspersky's GReAT team Kaspersky
- Unit 42 (Palo Alto Networks) Unit 42
- ESET Research ESET
- How Microsoft names threat actors Microsoft
- Evasive Serpens Unit 42 Playbook Viewer Unit42
- Unit 42 Playbook Viewer Unit 42
- Meet CrowdStrike’s Adversary of the Month for November: HELIX KITTEN Crowdstrike
- Iranian State-Sponsored and Aligned Attacks: What You Need to Know and Steps to Protect Yourself Proofpoint
- Secureworks. (n.d.). COBALT GYPSY Threat Profile Secureworks
- Crambus: New Campaign Targets Middle Eastern Government Symantec
- Evasive Serpens Unit 42 Playbook Viewer Unit42
- Iran’s APT34 Returns with an Updated Arsenal Check Point
- New Targeted Attack in the Middle East by APT34, a Suspected Iranian Threat Group, Using CVE-2017-11882 Exploit FireEye
- Iranian Threat Agent OilRig Delivers Digitally Signed Malware, Impersonates University of Oxford ClearSky
- Earth Simnavaz (aka APT34) Levies Advanced Cyberattacks Against Middle East Trend Micro
- The OilRig Campaign: Attacks on Saudi Arabian Organizations Deliver Helminth Backdoor Palo Alto
- OilRig Actors Provide a Glimpse into Development and Testing Efforts Palo Alto
- OilRig Malware Campaign Updates Toolset and Expands Targets Palo Alto
- New Destructive Wiper ZeroCleare Targets Energy Sector in the Middle East IBM
- OilRig Targets Technology Service Provider and Government Agency with QUADAGENT Unit 42
Countries linked to this actor
- United Arab Emirates targets
- Albania targets
- Iran origin
- Saudi Arabia targets
- Iraq targets
- Kuwait targets
- Jordan targets
- Qatar targets
- Yemen targets
- Lebanon targets