TA452
Named by ProofpointSuspected state sponsor: Islamic Republic of IranTA452 is Proofpoint's tracking designation for the Iranian MOIS-linked threat cluster widely known as OilRig and APT34, active since at least 2014. The group targets government, aviation, energy, financial, telecommunications, and technology organizations primarily across the Middle East, using spear phishing with macro-enabled Office documents as its primary initial access method. Documented campaigns leveraged PowerShell and AutoHotkey scripting for post-compromise execution and persistence, consistent with OilRig's established tradecraft of custom tooling combined with living-off-the-land techniques. The group is one of Iran's most extensively documented espionage actors, separately tracked as Helix Kitten (CrowdStrike), Cobalt Gypsy (Secureworks), Hazel Sandstorm (Microsoft), and Crambus (Symantec). DNS tunneling-based command and control remains a signature characteristic across TA452/OilRig campaigns, with the group continuously developing new custom backdoors including BONDUPDATER, VEATY, and SPEARAL to maintain persistent access across targeted networks.
Recent Indexed Reports
Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.