Cobalt Gypsy
Named by SecureWorksSuspected state sponsor: Islamic Republic of IranCobalt Gypsy is Secureworks' designation for the Iranian MOIS-linked threat cluster known as OilRig and APT34. Active since at least 2016, the cluster focuses on espionage against government, energy, and financial organizations in the Middle East, using spear phishing with macro-enabled Office documents and custom backdoors for persistent access. Secureworks' tracking of Cobalt Gypsy aligns closely with Mandiant's APT34 and CrowdStrike's Helix Kitten in terms of infrastructure, tooling, and victim profile, reflecting the same underlying Iranian state espionage operation.
Targeted Regions
BangladeshBangladesh
Apr 2016 ~ Jul 2017
Apr 2016 ~ Jul 2017
Apr 2016 ~ Jul 2017
Apr 2016 ~ Jul 2017
IndiaIndia
Apr 2016 ~ Jul 2017
Apr 2016 ~ Jul 2017
Apr 2016 ~ Jul 2017
Apr 2016 ~ Jul 2017
IranIran
Apr 2016 ~ Jul 2017
Apr 2016 ~ Jul 2017
Apr 2016 ~ Jul 2017
Apr 2016 ~ Jul 2017
IraqIraq
Apr 2016 ~ Jul 2017
Apr 2016 ~ Jul 2017
Apr 2016 ~ Jul 2017
Apr 2016 ~ Jul 2017
IsraelIsrael
Apr 2016 ~ Jul 2017
Apr 2016 ~ Jul 2017
Apr 2016 ~ Jul 2017
Apr 2016 ~ Jul 2017
Saudi ArabiaSaudi Arabia
Apr 2016 ~ Jul 2017
Apr 2016 ~ Jul 2017
Jan 2017 ~ Feb 2017 Apr 2016 ~ Jul 2017
Apr 2016 ~ Jul 2017
United StatesUnited States
Apr 2016 ~ Jul 2017
Apr 2016 ~ Jul 2017
Apr 2016 ~ Jul 2017
Apr 2016 ~ Jul 2017
Targeted Sectors
Recent Indexed Reports
Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.