Actors Insights|Latest update29/07/2026

Earth Simnavaz

Named by Trend MicroSuspected state sponsor: Islamic Republic of Iran

Earth Simnavaz is Trend Micro's designation for the Iranian MOIS-linked threat cluster known as OilRig and APT34. Trend Micro documented Earth Simnavaz conducting cyberespionage operations against government and critical infrastructure organizations in the UAE and Gulf region, using Exchange server exploitation and a novel backdoor that abuses the Windows IIS server for command and control. Earth Simnavaz operations show the group's continued capability development and persistent focus on Gulf state government targets consistent with the broader OilRig cluster's MOIS-attributed mission.

First Seen:Jan 2016
Last Seen:Mar 2025
Indexed Reports:1
Public IOCs:17
Cluster: OilRigMitre: OilRigMisp: OilRig
also known as:
Twisted Kitten (CrowdStrike)COBALT GYPSY (SecureWorks)Crambus (Symantec)Helix Kitten (CrowdStrike)APT 34IRN2 (Area 1)ATK40 (Thales)G0049 (Mitre)Evasive SerpensHazel Sandstorm (Microsoft)EUROPIUM (Microsoft)TA452 (Proofpoint)Earth Simnavaz (Trend Micro)OilRig (Palo Alto)ITG13 (IBM)

Targeted Regions

Middle East
ME
Middle East
Middle East
Sep 2024 ~ Oct 2024
Sep 2024 ~ Oct 2024
United Arab Emirates
AE
United Arab Emirates
United Arab Emirates
Sep 2024 ~ Oct 2024
Sep 2024 ~ Oct 2024
Jan 2024Nov 2026

Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.