Actors Insights|Latest update29/07/2026

Helix Kitten

Named by CrowdStrikeSuspected state sponsor: Islamic Republic of Iran

Helix Kitten is CrowdStrike's designation for the Iranian MOIS-linked threat cluster known as OilRig and APT34. Active since at least 2016, CrowdStrike documented Helix Kitten's persistent targeting of energy, government, and financial sector organizations across the Middle East using spear phishing and custom backdoors. The cluster is characterized by its extensive DNS tunneling infrastructure for command and control and its consistent focus on Saudi Arabian and Gulf state targets. Helix Kitten's sustained activity since 2016 demonstrates the group's operational continuity despite repeated public exposure.

First Seen:Jan 2016
Last Seen:Apr 2026
Indexed Reports:1
Public IOCs:0
Cluster: OilRigMitre: OilRigMisp: OilRig
also known as:
Twisted Kitten (CrowdStrike)COBALT GYPSY (SecureWorks)Crambus (Symantec)Helix Kitten (CrowdStrike)APT 34IRN2 (Area 1)ATK40 (Thales)G0049 (Mitre)Evasive SerpensHazel Sandstorm (Microsoft)EUROPIUM (Microsoft)TA452 (Proofpoint)Earth Simnavaz (Trend Micro)OilRig (Palo Alto)ITG13 (IBM)

Targeted Regions

Bahrain
BH
Bahrain
Bahrain
Jun 2018 ~ Nov 2018
Jun 2018 ~ Nov 2018
Kuwait
KW
Kuwait
Kuwait
Jun 2018 ~ Nov 2018
Jun 2018 ~ Nov 2018
Jan 2018Aug 2026

Targeted Sectors

Information TechnologyTelecommunication

Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.