Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors OilRig

Also known as: COBALT GYPSY, IRN2, APT34, Helix Kitten, Evasive Serpens, Hazel Sandstorm, EUROPIUM, ITG13, Earth Simnavaz, Crambus, TA452, Twisted Kitten, Chrysene, APT 34, ATK40, G0049, OilRig, Greenbug, TG-2889, Ghambar, Cutting Kitten, ITsecTeam, SOLAR ION

Description

OilRig is a suspected Iranian threat group that has targeted Middle Eastern and international victims since at least 2014. The group has targeted a variety of sectors, including financial, government, energy, chemical, and telecommunications. It appears the group carries out supply chain attacks, leveraging the trust relationship between organizations to attack their primary targets. The group works on behalf of the Iranian government based on infrastructure details that contain references to Iran, use of Iranian infrastructure, and targeting that aligns with nation-state interests.(Citation: FireEye APT34 Dec 2017)(Citation: Palo Alto OilRig April 2017)(Citation: ClearSky OilRig Jan 2017)(Citation: Palo Alto OilRig May 2016)(Citation: Palo Alto OilRig Oct 2016)(Citation: Unit42 OilRig Playbook 2023)(Citation: Unit 42 QUADAGENT July 2018)

Goals & Targeting

Targeted Sectors

Energy
Government

Targeted Countries / Regions

SA
US

AI Analysis

· 2 months ago

Executive Summary

OilRig is a suspected Iranian threat group that has been active since at least 2014, primarily targeting energy and government sectors in the Middle East and internationally. Their motivations appear to be espionage-driven, leveraging supply chain attacks to compromise their targets. The group's operations align with nation-state interests, utilizing Iranian infrastructure and referencing Iran in their tactics.

Goals & Targeting

OilRig's strategic objectives appear to be strongly aligned with the interests of the Iranian government, focusing on sectors such as energy and government that could provide valuable intelligence for national security, economic, and political purposes. Their targeting profile suggests a calculated approach, selecting victims based on their potential to yield sensitive information or disrupt critical infrastructure. Typical victims include organizations within the energy sector, government institutions, and entities involved in critical infrastructure, reflecting the group's intent to gather intelligence that supports Iranian geopolitical goals.

Enhanced Description

OilRig's operations are characterized by a blend of traditional cyber espionage techniques and more innovative tactics, such as exploiting trust relationships within supply chains. This approach allows them to bypass conventional security measures, potentially gaining access to sensitive information and systems that would be difficult to reach through direct attack. By analyzing the group's activities and tactics, it becomes clear that their primary goal is to gather strategic intelligence that could benefit Iranian national interests, whether through economic, political, or military means.

Key Capabilities

  • Supply chain attacks
  • Social engineering
  • Network exploitation
  • Malware development
  • C2 communications over various protocols

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion

ATT&CK Techniques

T1059.003
T1055
T1566.001

Software / Tooling

Custom malware
Exploit kits
Social engineering tools

Campaigns & Victims

OilRig's campaign patterns indicate a sophisticated and patient approach, often involving extensive reconnaissance and planning before executing an attack. Their operational tempo is characterized by a blend of high-profile, targeted operations and lower-level, opportunistic attacks, suggesting a flexible and adaptive strategy. Notable past operations have included large-scale phishing campaigns, targeted attacks against energy and government sectors, and the use of supply chain attacks to compromise intended victims. The group's ability to maintain a low profile and adapt to changing security landscapes underscores their professionalism and dedication to their objectives.

IOC Patterns

  • Spear-phishing with malicious attachments or links
  • Use of proxy servers for C2 communications
  • Exploitation of known vulnerabilities in software
  • Unusual DNS query patterns

Recommended Actions

  • Implement robust email filtering and security awareness training
  • Regularly update and patch software vulnerabilities
  • Monitor network traffic for suspicious patterns
  • Enhance supply chain security through vendor risk assessments and security audits

Suggested Tags

APT
espionage
nation-state
supply chain attack

Confidence Assessment

The confidence level in the available data on OilRig is moderate to high, given the extensive documentation by reputable cybersecurity firms and the consistency of their observed tactics and targeting. However, information gaps exist regarding the full extent of their capabilities, the specifics of their organizational structure, and the complete list of their past operations. Further research and intelligence gathering are necessary to fully understand the scope and potential of this threat actor.

ATT&CK Techniques

Collection
6 techniques
Command & Control
7 techniques
Credential Access
8 techniques
Discovery
14 techniques
Execution
9 techniques
Initial Access
4 techniques
Persistence
4 techniques
Resource Development
6 techniques
Stealth
10 techniques

Software / Tooling

Campaigns / Victims

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 18 URL 2

References

  1. Check Point APT34 April 2021 — Check Point. (2021, April 8). Iran’s APT34 Returns with an Updated Arsenal. Retrieved May 5, 2021.
  2. ClearSky OilRig Jan 2017 — ClearSky Cybersecurity. (2017, January 5). Iranian Threat Agent OilRig Delivers Digitally Signed Malware, Impersonates University of Oxford. Retrieved May 3, 2017.
  3. Trend Micro Earth Simnavaz October 2024 — Fahmy, M. et al. (2024, October 11). Earth Simnavaz (aka APT34) Levies Advanced Cyberattacks Against Middle East. Retrieved November 27, 2024.
  4. Palo Alto OilRig May 2016 — Falcone, R. and Lee, B.. (2016, May 26). The OilRig Campaign: Attacks on Saudi Arabian Organizations Deliver Helminth Backdoor. Retrieved May 3, 2017.
  5. Palo Alto OilRig April 2017 — Falcone, R.. (2017, April 27). OilRig Actors Provide a Glimpse into Development and Testing Efforts. Retrieved May 3, 2017.
  6. Palo Alto OilRig Oct 2016 — Grunzweig, J. and Falcone, R.. (2016, October 4). OilRig Malware Campaign Updates Toolset and Expands Targets. Retrieved May 3, 2017.
  7. IBM ZeroCleare Wiper December 2019 — Kessem, L. (2019, December 4). New Destructive Wiper ZeroCleare Targets Energy Sector in the Middle East. Retrieved September 4, 2024.
  8. Unit 42 QUADAGENT July 2018 — Lee, B., Falcone, R. (2018, July 25). OilRig Targets Technology Service Provider and Government Agency with QUADAGENT. Retrieved August 9, 2018.
  9. Crowdstrike Helix Kitten Nov 2018 — Meyers, A. (2018, November 27). Meet CrowdStrike’s Adversary of the Month for November: HELIX KITTEN. Retrieved December 18, 2018.
  10. Microsoft Threat Actor Naming July 2023 — Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.
  11. Proofpoint Iranian Aligned Attacks JAN 2020 — Proofpoint. (2020, January 10). Iranian State-Sponsored and Aligned Attacks: What You Need to Know and Steps to Protect Yourself. Retrieved January 16, 2025.
  12. FireEye APT34 Dec 2017 — Sardiwal, M, et al. (2017, December 7). New Targeted Attack in the Middle East by APT34, a Suspected Iranian Threat Group, Using CVE-2017-11882 Exploit. Retrieved December 20, 2017.
  13. Secureworks COBALT GYPSY Threat Profile — Secureworks. (n.d.). COBALT GYPSY Threat Profile. Retrieved April 14, 2021.
  14. Symantec Crambus OCT 2023 — Symantec Threat Hunter Team. (2023, October 19). Crambus: New Campaign Targets Middle Eastern Government. Retrieved November 27, 2024.
  15. Unit 42 Playbook Dec 2017 — Unit 42. (2017, December 15). Unit 42 Playbook Viewer. Retrieved December 20, 2017.
  16. Unit42 OilRig Playbook 2023 — Unit42. (2016, May 1). Evasive Serpens Unit 42 Playbook Viewer. Retrieved February 6, 2023.

Intel Summary

76

Techniques

35

Tools

1

Campaigns

35

IOCs

0

Observed Data

13

Tactics

Tags

APT
Supply Chain Attack
Government Targeting

Details

MITRE ID
G0049
Type
Unknown
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
Iran (IR)
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--4ca1929c-7d64-4aab-b849-badbfc0c760d
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.