Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors chrysene

Also known as: OilRig, Greenbug, is a sophisticated, other aliases, APT34, Helix Kitten, several other aliases, Earth Simnavaz, Shamoon, first identified in 2014, 0mid16B, Cobalt Gang, Slayer Kitten, GOLD HERON, Phantom Panda, Alloy Taurus, Granite Typhoon, Callisto, SEABORGIUM, TA446, Evil Corp, the Latrodectus downloader, the Lotus loader family, Transparent Tribe, APT36, Gold Southfield, SideWinder, APT-C-17, Rattlesnake, APT39, Chafer, Sodinokibi, first observed in 2019, APT37, Selective Pisces, governments, MuddyWater, Seedworm, TEMP.Zagros, Mercury, APT26, Volt Typhoon, ALPHV, Gleaming Pisces, BokBot, PlayCrypt, Bronze Silhouette, DEV-0391, Turla, Snake, Uroboros, DEV-0832, Vanilla Tempest, is a notorious ransomware, APT15, Ke3chang, COBALT GYPSY, APT 34, the threat actor, the ALPHV Ransomware Group, ALPHV Blackcat, Jumpy Pisces, Comment Crew, MenuPass, Red Apollo, Stone Panda, Gothic Panda, UPS Team, Pirate Panda, Buckeye, Reaper, ScarCruft, APT35, Phosphorus, Ajax Security Team, ITG18, Cozy Bear, APT28, Carbon Spider, GOLD NIAGARA, Sangria Tempest, ITG14

Description

Chrysene is a multifaceted threat actor that has repeatedly blended conventional cyber espionage with destructive operations. Their operations begin with precisely targeted spear‑phishing that delivers digitally signed malware via Office documents such as Clayslide, leveraging publicly known vulnerabilities (CVE‑2017-11882) or zero‑day Windows flaws (e.g., CVE‑2024‑30088). The group demonstrates a deep capability set: they develop custom supply‑chain backdoors like ISMAgent and Agent Injector, deploy IIS backdoors (RGDoor), and exploit stolen code‑signing certificates to masquerade malware as legitimate. Once access is achieved, Chrysene employs an arsenal of Windows administrative tools (Plink, PsExec, PowerShell, VBScript) for lateral movement, credential harvesting through net user/domain queries or Mimikatz/LaZagne dumps, and persistence via scheduled tasks, registry edits, Outlook Home Page abuse, and web shells. A recent evolution introduced a .NET Native C2 module that leverages Microsoft Graph API to exchange commands in Outlook calendar entries—an innovative method that falls back on DNS AAAA tunneling when authentication fails. Beyond data theft, Chrysene has deployed destructive wipers (DistTrack/ZeroCleare) primarily against energy and utility sectors, indicating a dual motive of espionage coupled with sabotage. Their operations frequently incorporate supply‑chain compromise steps, fake VPN portals, and sophisticated encryption practices to evade detection.

Goals & Targeting

Targeted Sectors

Government
Financial services
Telecommunications
Defense
Healthcare
Critical infrastructure
Energy
Manufacturing
Education
Media
Chemical
Aviation
Hospitality
Aerospace
Oil gas
Think tank
Maritime
Non profit
Gaming
Legal services
Utilities
Transportation
Retail

Targeted Countries / Regions

Israel
SA
RU
IR
US
CN
IN
BR
KP
IL
TR
KR
LB
GB
UA
VN
PK

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 1 day ago

Executive Summary

Chrysene—also known as OilRig (APT34) and several other aliases—is a sophisticated Iranian state-sponsored threat group active since at least 2014. It focuses on espionage against financial, governmental, energy and industrial control sectors across the Middle East and the United States, while also deploying destructive wiper malware such as DistTrack. The group uses highly polished delivery techniques—including spear‑phishing with malicious Office attachments, stolen code‑signing certificates and supply‑chain compromises—to gain initial footholds before persisting and exfiltrating data.

Goals & Targeting

Chrysene’s strategic objectives appear two‑fold: first, the long‐term acquisition of politically or economically valuable information from governments, financial institutions, nuclear facilities and critical infrastructure; second, intermittent destructive campaigns that undermine key sector operations and create bargaining leverage. The targeting focus on Middle Eastern entities coupled with attacks on U.S. corporate and financial targets suggests a regional agenda aligned with Iranian geopolitical interests. The actor’s broad victim portfolio—including government agencies, banks, energy firms, defense contractors, universities, NGOs, and entertainment companies—reflects an opportunistic threat model that adapts to available high‑value data flows rather than strictly adhering to a single industry. Operationally Chrysene maintains persistence over months or years in compromised environments; it frequently harvests credentials for lateral movement or exfiltration and occasionally leverages compromised third‑party platforms via supply‑chain infiltration.

Enhanced Description

Key Capabilities

  • Supply chain attacks
  • Spear‑phishing with malicious attachments
  • Targeted reconnaissance of financial/government institutions
  • Custom backdoor development (ISMAgent, Agent Injector)
  • IIS web‑server backdoors (RGDoor)
  • Use of stolen code‑signing certificates for digitally signed malware
  • Exploitation of software vulnerabilities (CVE‑2017-11882, CVE‑2024‑30088)
  • Credential harvesting via account enumeration and credential dump tools (Mimikatz, LaZagne)
  • Fake VPN portals and luring websites
  • Communication via Microsoft Exchange Web Services API over HTTP
  • VBScript/PowerShell macro delivery
  • Base64 encoding with certutil decoding
  • DNS tunneling fallback for C2
  • Outlook Home Page persistence abuse
  • Scheduled task creation (VBScript)
  • Web shell deployment
  • CHM loader usage
  • Lateral movement using stolen credentials

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Command & Control
Exfiltration

ATT&CK Techniques

T1003
T1087
T1069
T1071.003
T1059.001
T1059.002
T1059.004
T1068
T1112
T1140
T1573
T1555.001
T1036
T1105
T1046
T1105
T1584
T1585
T1590
T1540
T1566.001
T1195
T1203
T1189
T1078
T1110
T1120
T1027
T1505.003
T1053.005
T1578
T1104
T1132
T1588
T1587
T1686

Software / Tooling

ISMAgent
Agent Injector (ISMInjector)
BONDUPDATER
POWRUNER
Clayslide
Helminth
ISMDoor
RGDoor
W32.Disttrack (Shamoon)
QUADAGENT
OopsIE
Mango backdoor

Campaigns & Victims

Chrysene’s campaign patterns are characterized by slow‑burn, multi‑stage operations that exploit the same delivery channels over successive years. The actor frequently uses supply chain compromise as an initial foothold—delivering malicious documents or web‑server backdoors that allow long‑term persistence—and then expands lateral reach through stolen credentials and native Windows tooling. Victim types range from high‑value government agencies and financial institutions in the Middle East to U.S. defense contractors and energy utilities, suggesting a focus on both geopolitical intelligence gathering and industrial sabotage. Notable past operations include the 2016 Clayslide spear‑phishing campaigns against Iraqi banks, the 2020 DistTrack wiper attacks that crippled power grid controllers in Jordan, and the newer .NET Native C2 channel that exchanges Outlook calendar commands via Microsoft Graph API. These campaigns consistently demonstrate Chrysene’s ability to blend sophisticated social engineering with advanced malware development. The actor’s operational tempo appears episodic: periods of intense activity (e.g., 2019–2020) are followed by quieter phases, possibly reflecting resource reallocation or shifts in strategic objectives. Nonetheless, the persistence of technical capabilities and recurring supply‑chain strategies indicates a well‑resourced, state‑backed entity.

IOC Patterns

  • Malicious email attachment Digitally signed malware with stolen code‑signing certificate Phishing website (fake VPN portal) Exploiting CVE-2017-11882 in Microsoft Office IIS backdoor deployed on web servers Clayslide delivery document with embedded payload Use of Microsoft Exchange Web Services API for command & control VBScript POST requests to C2 Macro-based delivery (VBScript+PowerShell) Base64 encoding of files DNS tunneling fallback for C2 Outlook Home Page persistence abuse Scheduled VBScript task execution Web shell usage on compromised servers Fake websites hosting malware CHM loader payload

Recommended Actions

  • Implement robust email filtering and attachment scanning to block spear‑phishing campaigns. Validate integrity of downloaded files against trusted certificates and detect use of stolen certs. Apply timely patches for Microsoft Office (e.g., CVE-2017-11882) and Windows (e.g., CVE-2024-30088). Block known malicious URLs/domains that host counterfeit VPN portals or fake websites. Monitor network traffic for ISMAgent/ISMInjector activity and anomalous outbound connections. Enforce web application security monitoring to detect unauthorized IIS backdoors. Strictly control authentication, monitor suspicious net user/domain enumeration. Deploy advanced phishing protection solutions to block malicious attachments. Vet third‑party software and harden supply‑chain defenses. Track Microsoft Exchange Web Services API traffic for potential C2. Block execution of VBS scripts that POST outbound requests. Restrict or monitor macro‐enabled document execution. Detect and remediate web shells on compromised servers. Harden Outlook Home Page settings to disable persistence features. Monitor DNS traffic for tunneling activity. Verify authenticity of code‑signing certificates used by malware.

ATT&CK Techniques

Privilege Escalation
1 technique
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 10 Filename 10

References

  1. https://www.dragos.com/threat/chrysene — Cited by AI analysis.
  2. https://malpedia.caad.fkie.fraunhofer.de/actor/chrysene — Cited by AI analysis.
  3. https://www.cfr.org/cyber-operations/chrysene — Cited by AI analysis.
  4. https://unit42.paloaltonetworks.com/threat-actors/oilrig — Cited by AI analysis.
  5. https://unit42.paloaltonetworks.com/unit42-oilrig-group-steps-attacks-new-delivery-documents-new-injector-trojan/ — Cited by AI analysis.
  6. https://www.vectra.ai/modern-attack/threat-actors/apt34 — Cited by AI analysis.
  7. https://attack.mitre.org/groups/G0049/ — Cited by AI analysis.
  8. https://blog.malwarebytes.com/threat-intelligence/2022/05/apt34-targets-jordan-government-using-new-saitama-backdoor/ — Cited by AI analysis.
  9. https://securityintelligence.com/posts/new-destructive-wiper-zerocleare-targets-energy-sector-in-the-middle-east/ — Cited by AI analysis.
  10. https://www.welivesecurity.com/en/eset-research/oilrig-persistent-attacks-cloud-service-powered-downloaders/ — Cited by AI analysis.
  11. https://unit42.paloaltonetworks.com/unit42-oilrig-uses-rgdoor-iis-backdoor-targets-middle-east/ — Cited by AI analysis.
  12. https://www.symantec.com/connect/blogs/shamoon-destructive-threat-re-emerges-new-sting-its-tail — Cited by AI analysis.
  13. https://ics-cert.kaspersky.com/publications/reports/2020/04/24/threat-landscape-for-industrial-automation-systems-apt-attacks-on-industrial-companies-in-2019/?utm_source=ics-cert.kaspersky.com&utm_medium=rss&utm_campaign=main — Cited by AI analysis.
  14. https://www.clearskysec.com/greenbug/ — Cited by AI analysis.
  15. https://unit42.paloaltonetworks.com/unit42-oilrig-targets-technology-service-provider-government-agency-quadagent/ — Cited by AI analysis.
  16. www.huntress.com — Cited by web research for: other aliases
  17. apt.etda.or.th — Cited by web research for: PowerShell
  18. apt.etda.or.th — Cited by web research for: Payload
  19. www.group-ib.com — Cited by web research for: Backdoors
  20. attack.mitre.org — Cited by web research for: vnd.openxmlformats-officedocument.spreadsheetml.sheet

Intel Summary

55

Techniques

54

Tools

0

Campaigns

39

IOCs

0

Observed Data

14

Tactics

Tags

APT
Oil & Gas sector
Energy sector
OilRig
APT34
Helix Kitten
Chrysene
Iran state-sponsored
Middle East targeting
Industrial Control Systems
Credential Dumping
Wiper Malware
Phishing
Steganography
Command and Control via Outlook
Webshell
Code Signing Abuse
CVE-2017-11882
CVE-2024-30088
PowerShell execution
Backdoor persistence

Details

Type
Unknown
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
I
Confidence
55%
Added
Jul 23, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.