Actors Insights|Latest update29/07/2026

ITG13

Named by IBMSuspected state sponsor: Islamic Republic of Iran

ITG13 is IBM X-Force's designation for the Iranian MOIS-linked threat cluster known as OilRig and APT34. IBM documented ITG13 conducting espionage operations targeting government and financial organizations with infrastructure and tooling consistent with the broader OilRig cluster, including DNS-tunneling-based backdoors and credential harvesting operations. The ITG13 tracking covers the same Iranian state espionage actor that Mandiant tracks as APT34 and CrowdStrike tracks as Helix Kitten, reflecting IBM's independent threat actor naming convention for the same MOIS-attributed cluster.

First Seen:Sep 2019
Last Seen:Dec 2019
Indexed Reports:1
Public IOCs:14
Cluster: OilRigMitre: OilRig
also known as:
OilRig (Palo Alto)COBALT GYPSY (SecureWorks)IRN2 (Area 1)APT34 (Mandiant)Helix Kitten (CrowdStrike)Evasive SerpensHazel Sandstorm (Microsoft)EUROPIUM (Microsoft)ITG13 (IBM)Earth Simnavaz (Trend Micro)Crambus (Symantec)TA452 (Proofpoint)G0049 (Mitre)

Targeted Regions

Middle East
ME
Middle East
Middle East
Sep 2019 ~ Dec 2019
Jan 2019Sep 2026

Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.