Actors Insights|Latest update19/05/2025

TA452

Named by ProofpointSuspected state sponsor: Islamic Republic of Iran
First Seen:Aug 2022
Last Seen:Feb 2023
Indexed Reports:1
Public IOCs:32
Cluster: OilRigMisp: OilRig
also known as:
Twisted Kitten (CrowdStrike)COBALT GYPSY (SecureWorks)Crambus (Symantec)Helix Kitten (CrowdStrike)APT 34 (Mandiant)IRN2 (Area 1)ATK40 (Thales)G0049 (Mitre)Evasive SerpensHazel Sandstorm (Microsoft)EUROPIUM (Microsoft)TA452 (Proofpoint)OilRig (Palo Alto)

Recent Indexed Reports

  1. Public
    TA452 Utilizes PowerShell and AutoHotkey in its Intrusion

Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.