Helix Kitten
Named by CrowdStrikeSuspected state sponsor: Islamic Republic of IranHelix Kitten is CrowdStrike's designation for the Iranian MOIS-linked threat cluster known as OilRig and APT34. Active since at least 2016, CrowdStrike documented Helix Kitten's persistent targeting of energy, government, and financial sector organizations across the Middle East using spear phishing and custom backdoors. The cluster is characterized by its extensive DNS tunneling infrastructure for command and control and its consistent focus on Saudi Arabian and Gulf state targets. Helix Kitten's sustained activity since 2016 demonstrates the group's operational continuity despite repeated public exposure.
Targeted Regions
BahrainBahrain
Jun 2018 ~ Nov 2018
Jun 2018 ~ Nov 2018
KuwaitKuwait
Jun 2018 ~ Nov 2018
Jun 2018 ~ Nov 2018
Targeted Sectors
Recent Indexed Reports
Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.