Actors Insights|Latest update24/07/2026

TA452

Named by ProofpointSuspected state sponsor: Islamic Republic of Iran

TA452 is Proofpoint's tracking designation for the Iranian MOIS-linked threat cluster widely known as OilRig and APT34, active since at least 2014. The group targets government, aviation, energy, financial, telecommunications, and technology organizations primarily across the Middle East, using spear phishing with macro-enabled Office documents as its primary initial access method. Documented campaigns leveraged PowerShell and AutoHotkey scripting for post-compromise execution and persistence, consistent with OilRig's established tradecraft of custom tooling combined with living-off-the-land techniques. The group is one of Iran's most extensively documented espionage actors, separately tracked as Helix Kitten (CrowdStrike), Cobalt Gypsy (Secureworks), Hazel Sandstorm (Microsoft), and Crambus (Symantec). DNS tunneling-based command and control remains a signature characteristic across TA452/OilRig campaigns, with the group continuously developing new custom backdoors including BONDUPDATER, VEATY, and SPEARAL to maintain persistent access across targeted networks.

First Seen:Aug 2022
Last Seen:Feb 2023
Indexed Reports:1
Public IOCs:32
Cluster: UnclassifiedMitre: OilRigMisp: OilRig
also known as:
Twisted Kitten (CrowdStrike)COBALT GYPSY (SecureWorks)Crambus (Symantec)Helix Kitten (CrowdStrike)APT 34IRN2 (Area 1)ATK40 (Thales)G0049 (Mitre)Evasive SerpensHazel Sandstorm (Microsoft)EUROPIUM (Microsoft)TA452 (Proofpoint)Earth Simnavaz (Trend Micro)OilRig (Palo Alto)ITG13 (IBM)

Recent Indexed Reports

  1. Public
    TA452 Utilizes PowerShell and AutoHotkey in its Intrusion

Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.