Karkoff

Aliases: CACTUSPIPE, MailDropper, OILYFACE

First seen
2019-06-01 00:00:00
Malware type
dropper, spyware
Family
Malware family
Last IoC activity
2026-07-13 00:04:34
Profile updated
2026-07-07 12:54:40

Targeted industries: government-and-public-sector financial-services energy-and-utilities

Context

Karkoff, also known by its aliases CACTUSPIPE, MailDropper, and OILYFACE, is a malware family typically used in cyber-espionage campaigns. It primarily functions as a dropper and spyware, targeting government and financial sectors globally.

Reports & references

  • Cisco Talos — Dnspionage Brings Out Karkoff (report)
  • secureworks.com — Cobalt Edgewater (report)
  • cyware.com — Apt34 The Helix Kitten Cybercriminal Group Loves To Meow Middle Eastern And International Organizations 48Ae (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Karkoff (report)
  • Trend Micro — New Apt34 Malware Targets The Middle East (report)
  • blog.yoroi.company — Karkoff 2020 A New Apt34 Espionage Operation Involves Lebanon Government (report)
  • blog.telsy.com — Apt34 Aka Oilrig Attacks Lebanon Government Entities With Maildropper Implant (report)
  • mp.weixin.qq.com — O Evjbvn2Sq1Q7Cl4Ruxoq (report)

External references