Also known as: OilRig, Greenbug, is a sophisticated, other aliases, APT34, Helix Kitten, several other aliases, Earth Simnavaz, Shamoon, first identified in 2014, 0mid16B, Cobalt Gang, Slayer Kitten, GOLD HERON, Phantom Panda, Alloy Taurus, Granite Typhoon, Callisto, SEABORGIUM, TA446, Evil Corp, the Latrodectus downloader, the Lotus loader family, Transparent Tribe, APT36, Gold Southfield, SideWinder, APT-C-17, Rattlesnake, APT39, Chafer, Sodinokibi, first observed in 2019, APT37, Selective Pisces, governments, MuddyWater, Seedworm, TEMP.Zagros, Mercury, APT26, Volt Typhoon, ALPHV, Gleaming Pisces, BokBot, PlayCrypt, Bronze Silhouette, DEV-0391, Turla, Snake, Uroboros, DEV-0832, Vanilla Tempest, is a notorious ransomware, APT15, Ke3chang, COBALT GYPSY, APT 34, the threat actor, the ALPHV Ransomware Group, ALPHV Blackcat, Jumpy Pisces, Comment Crew, MenuPass, Red Apollo, Stone Panda, Gothic Panda, UPS Team, Pirate Panda, Buckeye, Reaper, ScarCruft, APT35, Phosphorus, Ajax Security Team, ITG18, Cozy Bear, APT28, Carbon Spider, GOLD NIAGARA, Sangria Tempest, ITG14
Chrysene is a multifaceted threat actor that has repeatedly blended conventional cyber espionage with destructive operations. Their operations begin with precisely targeted spear‑phishing that delivers digitally signed malware via Office documents such as Clayslide, leveraging publicly known vulnerabilities (CVE‑2017-11882) or zero‑day Windows flaws (e.g., CVE‑2024‑30088). The group demonstrates a deep capability set: they develop custom supply‑chain backdoors like ISMAgent and Agent Injector, deploy IIS backdoors (RGDoor), and exploit stolen code‑signing certificates to masquerade malware as legitimate. Once access is achieved, Chrysene employs an arsenal of Windows administrative tools (Plink, PsExec, PowerShell, VBScript) for lateral movement, credential harvesting through net user/domain queries or Mimikatz/LaZagne dumps, and persistence via scheduled tasks, registry edits, Outlook Home Page abuse, and web shells. A recent evolution introduced a .NET Native C2 module that leverages Microsoft Graph API to exchange commands in Outlook calendar entries—an innovative method that falls back on DNS AAAA tunneling when authentication fails. Beyond data theft, Chrysene has deployed destructive wipers (DistTrack/ZeroCleare) primarily against energy and utility sectors, indicating a dual motive of espionage coupled with sabotage. Their operations frequently incorporate supply‑chain compromise steps, fake VPN portals, and sophisticated encryption practices to evade detection.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Chrysene—also known as OilRig (APT34) and several other aliases—is a sophisticated Iranian state-sponsored threat group active since at least 2014. It focuses on espionage against financial, governmental, energy and industrial control sectors across the Middle East and the United States, while also deploying destructive wiper malware such as DistTrack. The group uses highly polished delivery techniques—including spear‑phishing with malicious Office attachments, stolen code‑signing certificates and supply‑chain compromises—to gain initial footholds before persisting and exfiltrating data.
Goals & Targeting
Chrysene’s strategic objectives appear two‑fold: first, the long‐term acquisition of politically or economically valuable information from governments, financial institutions, nuclear facilities and critical infrastructure; second, intermittent destructive campaigns that undermine key sector operations and create bargaining leverage. The targeting focus on Middle Eastern entities coupled with attacks on U.S. corporate and financial targets suggests a regional agenda aligned with Iranian geopolitical interests. The actor’s broad victim portfolio—including government agencies, banks, energy firms, defense contractors, universities, NGOs, and entertainment companies—reflects an opportunistic threat model that adapts to available high‑value data flows rather than strictly adhering to a single industry. Operationally Chrysene maintains persistence over months or years in compromised environments; it frequently harvests credentials for lateral movement or exfiltration and occasionally leverages compromised third‑party platforms via supply‑chain infiltration.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Chrysene’s campaign patterns are characterized by slow‑burn, multi‑stage operations that exploit the same delivery channels over successive years. The actor frequently uses supply chain compromise as an initial foothold—delivering malicious documents or web‑server backdoors that allow long‑term persistence—and then expands lateral reach through stolen credentials and native Windows tooling. Victim types range from high‑value government agencies and financial institutions in the Middle East to U.S. defense contractors and energy utilities, suggesting a focus on both geopolitical intelligence gathering and industrial sabotage. Notable past operations include the 2016 Clayslide spear‑phishing campaigns against Iraqi banks, the 2020 DistTrack wiper attacks that crippled power grid controllers in Jordan, and the newer .NET Native C2 channel that exchanges Outlook calendar commands via Microsoft Graph API. These campaigns consistently demonstrate Chrysene’s ability to blend sophisticated social engineering with advanced malware development. The actor’s operational tempo appears episodic: periods of intense activity (e.g., 2019–2020) are followed by quieter phases, possibly reflecting resource reallocation or shifts in strategic objectives. Nonetheless, the persistence of technical capabilities and recurring supply‑chain strategies indicates a well‑resourced, state‑backed entity.
IOC Patterns
Recommended Actions
No campaigns linked yet.
No observed data linked yet.
55
Techniques
54
Tools
0
Campaigns
39
IOCs
0
Observed Data
14
Tactics