OilRig

MITRE ATT&CK: G0049 View on attack.mitre.org

Aliases: COBALT GYPSY, IRN2, APT34, Helix Kitten, Evasive Serpens, Hazel Sandstorm, EUROPIUM, ITG13, Earth Simnavaz, Crambus, TA452, Twisted Kitten, Cobalt Gypsy, APT 34, ATK40, OilRig, HELIX KITTEN

First seen
2014-01-01 00:00:00
Origin
IR
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
Espionage
Related IoCs
112 (104 malicious)
Last IoC activity
2026-09-02 00:39:36
Profile updated
2026-07-07 12:33:05

Targeted industries: financial-services government-and-public-sector energy-and-utilities technology-and-telecommunications

Targeted regions: country_code:ae country_code:sa country_code:qa country_code:us

Context

OilRig is a suspected Iranian threat group that has targeted Middle Eastern and international victims since at least 2014. The group has targeted a variety of sectors, including financial, government, energy, chemical, and telecommunications. It appears the group carries out supply chain attacks, leveraging the trust relationship between organizations to attack their primary targets. The group works on behalf of the Iranian government based on infrastructure details that contain references to Iran, use of Iranian infrastructure, and targeting that aligns with nation-state interests.

Recent IoC activity

104 malicious indicators in Maltiverse are attributed to OilRig (G0049). The 20 most recently updated:

TypeIndicatorUpdatedSources
hostname maill-support.com 2026-09-03 1
hostname msn-service.co 2026-09-02 1
hostname twittsupport.com 2026-09-02 2
hostname mail-updateservice.info 2026-09-02 2
hostname astrazencea.com 2026-09-02 1
hostname fuschia-rhinestone.cleverapps.io 2026-09-02 1
hostname live-redirect-system.top 2026-08-25 1
hostname malcolmrifkind.site 2026-08-24 2
hostname mailupdate.info 2026-08-19 1
hostname review-status-plan.online 2026-08-13 1
file sample 37f9b131926abb483d407fd4d3058d0efe1ac7cf88f9964cf0e6ad7502dbc769f6e7367ea78f8... 2026-04-13 2
hostname mailupdate.com 2026-03-31 1
file sample 29318f46476dc0cfd7b928a2861fea1b761496eb5d6a26040e481c3bd655051a 2025-11-24 1
file sample file 2025-11-24 2
file sample 595a54f0bbf297041ce259461ae8a12f37fb29e5180705eafb3668b4a491cecc.exe 2025-10-11 2
hostname deersharpfork.info 2024-10-16 1
hostname cfunc.save 2024-10-16 1
file sample Win32.Turla.v1.bin 2024-09-11 2
hostname subinfralab.info 2024-06-05 1
file sample 991620817274d4031889134d40294cc6e086cf56e738a8ea78c49860c6dccdce 2023-07-05 1

Detection coverage

  • 18 YARA rules
  • 982 Sigma rules

Malware & tools used

  • Windows Credential Manager (attack-pattern)
  • System Information Discovery (attack-pattern)
  • LSASS Memory (attack-pattern)
  • Fallback Channels (attack-pattern)
  • Web Protocols (attack-pattern)
  • Data from Local System (attack-pattern)
  • Windows Host Firewall (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Remote Desktop Protocol (attack-pattern)
  • Web Shell (attack-pattern)
  • Malware (attack-pattern)
  • Upload Malware (attack-pattern)
  • Masquerading (attack-pattern)
  • Remote Access Tools (attack-pattern)
  • Compiled HTML File (attack-pattern)
  • Network Service Discovery (attack-pattern)
  • Local Account (attack-pattern)
  • Outlook Home Page (attack-pattern)
  • Domain Groups (attack-pattern)
  • Screen Capture (attack-pattern)
  • Data from Removable Media (attack-pattern)
  • System Service Discovery (attack-pattern)
  • Password Filter DLL (attack-pattern)
  • PowerShell (attack-pattern)
  • File Deletion (attack-pattern)

Related threat objects

Reports & references

  • cloud.google.com — Updated Cyber Threat Actor Naming System (report)
  • blog.morphisec.com — Iranian Fileless Cyberattack On Israel Word Vulnerability (report)
  • Palo Alto Unit 42 — Unit42 Striking Oil Closer Look Adversary Infrastructure (report)
  • Palo Alto Unit 42 — Unit42 Introducing The Adversary Playbook First Up Oilrig (report)
  • Palo Alto Unit 42 — Unit42 Oopsie Oilrig Uses Threedollars Deliver New Trojan (report)
  • Palo Alto Unit 42 — Unit42 Oilrig Uses Rgdoor Iis Backdoor Targets Middle East (report)
  • Palo Alto Unit 42 — Unit42 Twoface Webshell Persistent Access Point Lateral Movement (report)
  • Palo Alto Unit 42 — Unit42 Oilrig Actors Provide Glimpse Development Testing Efforts (report)
  • Palo Alto Unit 42 — Unit42 Analyzing Oilrigs Ops Tempo Testing Weaponization Delivery (report)
  • Palo Alto Unit 42 — Unit42 Oilrig Malware Campaign Updates Toolset And Expands Targets (report)
  • Palo Alto Unit 42 — Unit42 Oilrig Uses Updated Bondupdater Target Middle Eastern Government (report)
  • Palo Alto Unit 42 — Unit42 Oilrig Group Steps Attacks New Delivery Documents New Injector Trojan (report)
  • Palo Alto Unit 42 — Unit42 Oilrig Targets Technology Service Provider Government Agency Quadagent (report)
  • Palo Alto Unit 42 — The Oilrig Campaign Attacks On Saudi Arabian Organizations Deliver Helminth Backdoor (report)
  • pan-unit42.github.io — Playbook Viewer (report)
  • Mandiant — Targeted Attacksaga (report)
  • Mandiant — Targeted Attack In Middle East By Apt34 (report)
  • gov.il — Cert Il Alert W 120 (report)
  • forbes.com — Oilrig Iran Hackers Cyberespionage Us Turkey Saudi Arabia (report)
  • raw.githubusercontent.com — Oilrig (report)
  • cfr.org — Oilrig (report)
  • cfr.org — Apt 34 (report)
  • CrowdStrike — Meet Crowdstrikes Adversary Of The Month For November Helix Kitten (report)
  • Broadcom/Symantec — Shamoon Destructive Threat Re Emerges New Sting Its Tail (report)
  • web.archive.org — Shamoon Attacks (report)

Attributed from

  • Juicy Mix (campaign)
  • Outer Space (campaign)

External references