ITG13
Named by IBMSuspected state sponsor: Islamic Republic of IranITG13 is IBM X-Force's designation for the Iranian MOIS-linked threat cluster known as OilRig and APT34. IBM documented ITG13 conducting espionage operations targeting government and financial organizations with infrastructure and tooling consistent with the broader OilRig cluster, including DNS-tunneling-based backdoors and credential harvesting operations. The ITG13 tracking covers the same Iranian state espionage actor that Mandiant tracks as APT34 and CrowdStrike tracks as Helix Kitten, reflecting IBM's independent threat actor naming convention for the same MOIS-attributed cluster.
Targeted Regions
Middle EastMiddle East
Sep 2019 ~ Dec 2019
Recent Indexed Reports
Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.