OilRig
MITRE ATT&CK: G0049 View on attack.mitre.org
Aliases: COBALT GYPSY, IRN2, APT34, Helix Kitten, Evasive Serpens, Hazel Sandstorm, EUROPIUM, ITG13, Earth Simnavaz, Crambus, TA452, Twisted Kitten, Cobalt Gypsy, APT 34, ATK40, OilRig, HELIX KITTEN
- First seen
- 2014-01-01 00:00:00
- Origin
- IR
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- Espionage
- Related IoCs
- 112 (104 malicious)
- Last IoC activity
- 2026-09-02 00:39:36
- Profile updated
- 2026-07-07 12:33:05
Targeted industries: financial-services government-and-public-sector energy-and-utilities technology-and-telecommunications
Targeted regions: country_code:ae country_code:sa country_code:qa country_code:us
Context
OilRig is a suspected Iranian threat group that has targeted Middle Eastern and international victims since at least 2014. The group has targeted a variety of sectors, including financial, government, energy, chemical, and telecommunications. It appears the group carries out supply chain attacks, leveraging the trust relationship between organizations to attack their primary targets. The group works on behalf of the Iranian government based on infrastructure details that contain references to Iran, use of Iranian infrastructure, and targeting that aligns with nation-state interests.
Recent IoC activity
104 malicious indicators in Maltiverse are attributed to OilRig (G0049). The 20 most recently updated:
Detection coverage
- 18 YARA rules
- 982 Sigma rules
Malware & tools used
- Windows Credential Manager (attack-pattern)
- System Information Discovery (attack-pattern)
- LSASS Memory (attack-pattern)
- Fallback Channels (attack-pattern)
- Web Protocols (attack-pattern)
- Data from Local System (attack-pattern)
- Windows Host Firewall (attack-pattern)
- Windows Command Shell (attack-pattern)
- Remote Desktop Protocol (attack-pattern)
- Web Shell (attack-pattern)
- Malware (attack-pattern)
- Upload Malware (attack-pattern)
- Masquerading (attack-pattern)
- Remote Access Tools (attack-pattern)
- Compiled HTML File (attack-pattern)
- Network Service Discovery (attack-pattern)
- Local Account (attack-pattern)
- Outlook Home Page (attack-pattern)
- Domain Groups (attack-pattern)
- Screen Capture (attack-pattern)
- Data from Removable Media (attack-pattern)
- System Service Discovery (attack-pattern)
- Password Filter DLL (attack-pattern)
- PowerShell (attack-pattern)
- File Deletion (attack-pattern)
Related threat objects
- CHRYSENE (threat-actor)
- Cutting Kitten (threat-actor)
- Charming Kitten (threat-actor)
- Rocket Kitten (threat-actor)
- Clever Kitten (threat-actor)
- Magic Hound (threat-actor)
- APT34 (threat-actor)
- Cleaver (threat-actor)
Reports & references
- cloud.google.com — Updated Cyber Threat Actor Naming System (report)
- blog.morphisec.com — Iranian Fileless Cyberattack On Israel Word Vulnerability (report)
- Palo Alto Unit 42 — Unit42 Striking Oil Closer Look Adversary Infrastructure (report)
- Palo Alto Unit 42 — Unit42 Introducing The Adversary Playbook First Up Oilrig (report)
- Palo Alto Unit 42 — Unit42 Oopsie Oilrig Uses Threedollars Deliver New Trojan (report)
- Palo Alto Unit 42 — Unit42 Oilrig Uses Rgdoor Iis Backdoor Targets Middle East (report)
- Palo Alto Unit 42 — Unit42 Twoface Webshell Persistent Access Point Lateral Movement (report)
- Palo Alto Unit 42 — Unit42 Oilrig Actors Provide Glimpse Development Testing Efforts (report)
- Palo Alto Unit 42 — Unit42 Analyzing Oilrigs Ops Tempo Testing Weaponization Delivery (report)
- Palo Alto Unit 42 — Unit42 Oilrig Malware Campaign Updates Toolset And Expands Targets (report)
- Palo Alto Unit 42 — Unit42 Oilrig Uses Updated Bondupdater Target Middle Eastern Government (report)
- Palo Alto Unit 42 — Unit42 Oilrig Group Steps Attacks New Delivery Documents New Injector Trojan (report)
- Palo Alto Unit 42 — Unit42 Oilrig Targets Technology Service Provider Government Agency Quadagent (report)
- Palo Alto Unit 42 — The Oilrig Campaign Attacks On Saudi Arabian Organizations Deliver Helminth Backdoor (report)
- pan-unit42.github.io — Playbook Viewer (report)
- Mandiant — Targeted Attacksaga (report)
- Mandiant — Targeted Attack In Middle East By Apt34 (report)
- gov.il — Cert Il Alert W 120 (report)
- forbes.com — Oilrig Iran Hackers Cyberespionage Us Turkey Saudi Arabia (report)
- raw.githubusercontent.com — Oilrig (report)
- cfr.org — Oilrig (report)
- cfr.org — Apt 34 (report)
- CrowdStrike — Meet Crowdstrikes Adversary Of The Month For November Helix Kitten (report)
- Broadcom/Symantec — Shamoon Destructive Threat Re Emerges New Sting Its Tail (report)
- web.archive.org — Shamoon Attacks (report)
Attributed from
- Juicy Mix (campaign)
- Outer Space (campaign)
External references
- mitre-attack — G0049
- IRN2
- ITG13
- Hazel Sandstorm
- EUROPIUM
- OilRig
- TA452
- COBALT GYPSY
- Crambus
- Earth Simnavaz
- Helix Kitten
- Evasive Serpens
- Check Point APT34 April 2021
- ClearSky OilRig Jan 2017
- Trend Micro Earth Simnavaz October 2024
- Palo Alto OilRig May 2016
- Palo Alto OilRig April 2017
- Palo Alto OilRig Oct 2016
- IBM ZeroCleare Wiper December 2019
- Unit 42 QUADAGENT July 2018