Karkoff
Aliases: CACTUSPIPE, MailDropper, OILYFACE
- First seen
- 2019-06-01 00:00:00
- Malware type
- dropper, spyware
- Family
- Malware family
- Last IoC activity
- 2026-07-13 00:04:34
- Profile updated
- 2026-07-07 12:54:40
Targeted industries: government-and-public-sector financial-services energy-and-utilities
Context
Karkoff, also known by its aliases CACTUSPIPE, MailDropper, and OILYFACE, is a malware family typically used in cyber-espionage campaigns. It primarily functions as a dropper and spyware, targeting government and financial sectors globally.
Reports & references
- Cisco Talos — Dnspionage Brings Out Karkoff (report)
- secureworks.com — Cobalt Edgewater (report)
- cyware.com — Apt34 The Helix Kitten Cybercriminal Group Loves To Meow Middle Eastern And International Organizations 48Ae (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Karkoff (report)
- Trend Micro — New Apt34 Malware Targets The Middle East (report)
- blog.yoroi.company — Karkoff 2020 A New Apt34 Espionage Operation Involves Lebanon Government (report)
- blog.telsy.com — Apt34 Aka Oilrig Attacks Lebanon Government Entities With Maildropper Implant (report)
- mp.weixin.qq.com — O Evjbvn2Sq1Q7Cl4Ruxoq (report)