Threats Feed
- Public
Iranian Threat Actors Breach 12 Omani Ministries, Exposing 26,000 Records
An Iranian-nexus threat actor targeted 12 Omani government ministries, with a primary focus on the Ministry of Justice and Legal Affairs. Utilizing an exposed UAE-based virtual private server, the operator inadvertently revealed their entire operational toolkit, command-and-control infrastructure, and stolen data. The campaign heavily targeted Oman's government, judicial, law enforcement, and administrative sectors to extract citizen identity data, immigration details, and judicial records. The attackers achieved access via ProxyShell and DotNetNuke vulnerabilities, deploying custom webshells and tools like GodPotato for persistent access and privilege escalation. Ultimately, the operation successfully exfiltrated over 26,000 citizen records and critical system registry hives.
read more about Iranian Threat Actors Breach 12 Omani Ministries, Exposing 26,000 Records - Public
Multi-Stage Attack Chain: How OilRig Targets Global Sectors Using Telegram and Google Drive
APT-C-49 (OilRig), an Iranian state-sponsored threat group, recently launched a sophisticated phishing campaign utilizing Iranian protest-themed Excel lures. Targeting government, finance, energy, telecommunications, and military sectors across the Middle East, US, Europe, and Asia, the group deployed a highly covert, multi-stage attack chain. The infection begins with macro-driven C# compilation, progressing to dead-drop resolving via GitHub. The payload utilizes LSB steganography on Google Drive-hosted images to extract encrypted configurations. Subsequently, it dynamically loads fileless modules into memory for data theft and remote execution, leveraging the Telegram Bot API for encrypted command and control (C2). This campaign highlights OilRig's evolution toward cloud service abuse and in-memory execution to evade detection.
read more about Multi-Stage Attack Chain: How OilRig Targets Global Sectors Using Telegram and Google Drive - Public
Multi-Stage Attack Chain: How OilRig Targets Global Sectors Using Telegram and Google Drive
APT-C-49 (OilRig), an Iranian state-sponsored threat group, recently launched a sophisticated phishing campaign utilizing Iranian protest-themed Excel lures. Targeting government, finance, energy, telecommunications, and military sectors across the Middle East, US, Europe, and Asia, the group deployed a highly covert, multi-stage attack chain. The infection begins with macro-driven C# compilation, progressing to dead-drop resolving via GitHub. The payload utilizes LSB steganography on Google Drive-hosted images to extract encrypted configurations. Subsequently, it dynamically loads fileless modules into memory for data theft and remote execution, leveraging the Telegram Bot API for encrypted command and control (C2). This campaign highlights OilRig's evolution toward cloud service abuse and in-memory execution to evade detection.
read more about Multi-Stage Attack Chain: How OilRig Targets Global Sectors Using Telegram and Google Drive - Public
Multi-Stage Attack Chain: How OilRig Targets Global Sectors Using Telegram and Google Drive
APT-C-49 (OilRig), an Iranian state-sponsored threat group, recently launched a sophisticated phishing campaign utilizing Iranian protest-themed Excel lures. Targeting government, finance, energy, telecommunications, and military sectors across the Middle East, US, Europe, and Asia, the group deployed a highly covert, multi-stage attack chain. The infection begins with macro-driven C# compilation, progressing to dead-drop resolving via GitHub. The payload utilizes LSB steganography on Google Drive-hosted images to extract encrypted configurations. Subsequently, it dynamically loads fileless modules into memory for data theft and remote execution, leveraging the Telegram Bot API for encrypted command and control (C2). This campaign highlights OilRig's evolution toward cloud service abuse and in-memory execution to evade detection.
read more about Multi-Stage Attack Chain: How OilRig Targets Global Sectors Using Telegram and Google Drive - Public
OilRig Supply Chain Attack: Stolen Thai IT Vendor Certificates Hide Karkoff Backdoor
PolySwarm researchers have uncovered previously unreported cyberespionage activity by the Iranian state-sponsored threat actor OilRig (APT34). The campaign leverages a stolen Extended Validation (EV) code signing certificate from a legitimate Thai IT vendor, MOSCII Corporation, to sign malicious payloads, including the custom Karkoff backdoor. By masquerading as legitimate vendor tooling, OilRig targeted Thailand’s energy sector, specifically the Electricity Generating Authority of Thailand (EGAT). The attackers employed advanced defense evasion techniques, such as spoofing compile timestamps to 2014 and padding binaries to 10 MB to bypass automated sandbox environments. This supply chain intrusion highlights OilRig’s continued evolution in targeting critical infrastructure and government agencies through trusted vendor relationships across Southeast Asia and the Middle East.
read more about OilRig Supply Chain Attack: Stolen Thai IT Vendor Certificates Hide Karkoff Backdoor - Public
OilRig Supply Chain Attack: Stolen Thai IT Vendor Certificates Hide Karkoff Backdoor
PolySwarm researchers have uncovered previously unreported cyberespionage activity by the Iranian state-sponsored threat actor OilRig (APT34). The campaign leverages a stolen Extended Validation (EV) code signing certificate from a legitimate Thai IT vendor, MOSCII Corporation, to sign malicious payloads, including the custom Karkoff backdoor. By masquerading as legitimate vendor tooling, OilRig targeted Thailand’s energy sector, specifically the Electricity Generating Authority of Thailand (EGAT). The attackers employed advanced defense evasion techniques, such as spoofing compile timestamps to 2014 and padding binaries to 10 MB to bypass automated sandbox environments. This supply chain intrusion highlights OilRig’s continued evolution in targeting critical infrastructure and government agencies through trusted vendor relationships across Southeast Asia and the Middle East.
read more about OilRig Supply Chain Attack: Stolen Thai IT Vendor Certificates Hide Karkoff Backdoor - Public
OilRig Supply Chain Attack: Stolen Thai IT Vendor Certificates Hide Karkoff Backdoor
PolySwarm researchers have uncovered previously unreported cyberespionage activity by the Iranian state-sponsored threat actor OilRig (APT34). The campaign leverages a stolen Extended Validation (EV) code signing certificate from a legitimate Thai IT vendor, MOSCII Corporation, to sign malicious payloads, including the custom Karkoff backdoor. By masquerading as legitimate vendor tooling, OilRig targeted Thailand’s energy sector, specifically the Electricity Generating Authority of Thailand (EGAT). The attackers employed advanced defense evasion techniques, such as spoofing compile timestamps to 2014 and padding binaries to 10 MB to bypass automated sandbox environments. This supply chain intrusion highlights OilRig’s continued evolution in targeting critical infrastructure and government agencies through trusted vendor relationships across Southeast Asia and the Middle East.
read more about OilRig Supply Chain Attack: Stolen Thai IT Vendor Certificates Hide Karkoff Backdoor - Public
OilRig Supply Chain Attack: Stolen Thai IT Vendor Certificates Hide Karkoff Backdoor
PolySwarm researchers have uncovered previously unreported cyberespionage activity by the Iranian state-sponsored threat actor OilRig (APT34). The campaign leverages a stolen Extended Validation (EV) code signing certificate from a legitimate Thai IT vendor, MOSCII Corporation, to sign malicious payloads, including the custom Karkoff backdoor. By masquerading as legitimate vendor tooling, OilRig targeted Thailand’s energy sector, specifically the Electricity Generating Authority of Thailand (EGAT). The attackers employed advanced defense evasion techniques, such as spoofing compile timestamps to 2014 and padding binaries to 10 MB to bypass automated sandbox environments. This supply chain intrusion highlights OilRig’s continued evolution in targeting critical infrastructure and government agencies through trusted vendor relationships across Southeast Asia and the Middle East.
read more about OilRig Supply Chain Attack: Stolen Thai IT Vendor Certificates Hide Karkoff Backdoor - Public
Unmasking Iranian Cyber Operations: Threat Actors Target Global Critical Infrastructure
Amid escalating geopolitical tensions, Iranian state-aligned and hacktivist threat groups, including MuddyWater, VoidManticore, APT42, APT35, and Infy, are actively pre-positioning infrastructure for cyber operations. By analyzing ASN patterns, TLS fingerprints, and hosting clusters, defenders can proactively track these adversaries. The groups deploy a mix of custom backdoors, public malware, and Cloudflare-fronted C2 servers to obscure their origins. Campaigns utilize spear-phishing, compromised government mailboxes, and modular scripts to target energy, financial, government, defense, and critical infrastructure sectors. Geographically, these operations focus heavily on the U.S., Israel, the MENA region, Oman, and the UAE, alongside targeting Iranian dissidents and global defense personnel.
read more about Unmasking Iranian Cyber Operations: Threat Actors Target Global Critical Infrastructure - Public
BladedFeline Targets Iraq and Kurdistan Governments with Custom Malware Arsenal
BladedFeline, an Iran-aligned APT group likely linked to OilRig (APT34), has conducted a multi-year cyberespionage campaign targeting Kurdish and Iraqi government officials as well as a telecommunications provider in Uzbekistan. Active since at least 2017, the group deployed various custom tools—including the Shahmaran and Whisper backdoors, the PrimeCache IIS module, reverse tunnels (Laret and Pinar), and several post-compromise implants—to maintain long-term access. Whisper abuses Microsoft Exchange email infrastructure for covert C2, while PrimeCache leverages malicious IIS components. This activity highlights Iran’s strategic interest in regional political and telecommunications sectors.
read more about BladedFeline Targets Iraq and Kurdistan Governments with Custom Malware Arsenal - Public
APT34 Targets Iraqi Government with Dual-Channel C2 and Obfuscated Backdoors
APT34 (OilRig) has launched a targeted cyber espionage campaign against Iraqi government entities since 2024, using spearphishing emails with forged documents to deploy custom C# malware disguised as PDF files. The malware performs system reconnaissance, anti-VM checks, and sets up persistence via scheduled tasks. It communicates with command-and-control infrastructure through both HTTP and compromised Iraqi government email accounts (SMTP/IMAP). The group also utilizes European-hosted infrastructure with deceptive 404 pages and obfuscated communication protocols. Targeted sectors include government, energy, finance, defense, and telecommunications, indicating a continued focus on intelligence gathering in the Middle East.
read more about APT34 Targets Iraqi Government with Dual-Channel C2 and Obfuscated Backdoors - Public
OilRig: Cyber-Espionage Targeting Global Critical Sectors
SOCRadar's January 2025 dark web profile on OilRig (APT34) documents the group as one of Iran's most persistent and sophisticated state-sponsored threat actors, active since at least 2016. OilRig targets government agencies, energy and oil & gas companies, telecommunications providers, financial institutions, universities, and research institutions — primarily across the Middle East, with confirmed extensions to Europe, North America, and Asia. The group follows a full kill chain methodology: reconnaissance using Netstat and Systeminfo; weaponization with custom tools including BondUpdater and Helminth; spearphishing delivery via email attachments, links, and LinkedIn (T1566.001/002/003); exploitation via Mimikatz for credential dumping and CVE-2017-11774 to abuse Outlook Home Page for persistence; C2 via DNS tunneling, encrypted channels, and fallback HTTP; and exfiltration over FTP (T1048.003). Post-compromise tools include LaZagne, ISMInjector, BONDUPDATER, PAExec, KEYPUNCH, LONGWATCH, VALUEVAULT, PICKPOCKET, and GOLDIRONY. OilRig also abuses Plink for tunnel creation and uses web shells for persistence. In destructive operations, the group has deployed ZeroCleare — a disk-wiping malware — demonstrating capability beyond espionage. The group regularly updates its toolset and evades detection through base64 obfuscation, AV testing, file deletion, and domain generation algorithms. OilRig's targeting aligns consistently with Iranian geopolitical and economic interests.
read more about OilRig: Cyber-Espionage Targeting Global Critical Sectors - Public
OilRig: Cyber-Espionage Targeting Global Critical Sectors
SOCRadar's January 2025 dark web profile on OilRig (APT34) documents the group as one of Iran's most persistent and sophisticated state-sponsored threat actors, active since at least 2016. OilRig targets government agencies, energy and oil & gas companies, telecommunications providers, financial institutions, universities, and research institutions — primarily across the Middle East, with confirmed extensions to Europe, North America, and Asia. The group follows a full kill chain methodology: reconnaissance using Netstat and Systeminfo; weaponization with custom tools including BondUpdater and Helminth; spearphishing delivery via email attachments, links, and LinkedIn (T1566.001/002/003); exploitation via Mimikatz for credential dumping and CVE-2017-11774 to abuse Outlook Home Page for persistence; C2 via DNS tunneling, encrypted channels, and fallback HTTP; and exfiltration over FTP (T1048.003). Post-compromise tools include LaZagne, ISMInjector, BONDUPDATER, PAExec, KEYPUNCH, LONGWATCH, VALUEVAULT, PICKPOCKET, and GOLDIRONY. OilRig also abuses Plink for tunnel creation and uses web shells for persistence. In destructive operations, the group has deployed ZeroCleare — a disk-wiping malware — demonstrating capability beyond espionage. The group regularly updates its toolset and evades detection through base64 obfuscation, AV testing, file deletion, and domain generation algorithms. OilRig's targeting aligns consistently with Iranian geopolitical and economic interests.
read more about OilRig: Cyber-Espionage Targeting Global Critical Sectors - Public
OilRig: Cyber-Espionage Targeting Global Critical Sectors
SOCRadar's January 2025 dark web profile on OilRig (APT34) documents the group as one of Iran's most persistent and sophisticated state-sponsored threat actors, active since at least 2016. OilRig targets government agencies, energy and oil & gas companies, telecommunications providers, financial institutions, universities, and research institutions — primarily across the Middle East, with confirmed extensions to Europe, North America, and Asia. The group follows a full kill chain methodology: reconnaissance using Netstat and Systeminfo; weaponization with custom tools including BondUpdater and Helminth; spearphishing delivery via email attachments, links, and LinkedIn (T1566.001/002/003); exploitation via Mimikatz for credential dumping and CVE-2017-11774 to abuse Outlook Home Page for persistence; C2 via DNS tunneling, encrypted channels, and fallback HTTP; and exfiltration over FTP (T1048.003). Post-compromise tools include LaZagne, ISMInjector, BONDUPDATER, PAExec, KEYPUNCH, LONGWATCH, VALUEVAULT, PICKPOCKET, and GOLDIRONY. OilRig also abuses Plink for tunnel creation and uses web shells for persistence. In destructive operations, the group has deployed ZeroCleare — a disk-wiping malware — demonstrating capability beyond espionage. The group regularly updates its toolset and evades detection through base64 obfuscation, AV testing, file deletion, and domain generation algorithms. OilRig's targeting aligns consistently with Iranian geopolitical and economic interests.
read more about OilRig: Cyber-Espionage Targeting Global Critical Sectors - Public
OilRig's Cyber Tactics: Targeting Middle East Sectors with Stealthy Attacks
OilRig (APT34) has targeted the government, technology and energy sectors across the Middle East. Its operations include spearphishing campaigns, PowerShell-based backdoors (Helminth, QUADAGENT), and exploitation of vulnerabilities such as CVE-2024-30088. The group relies on obfuscation techniques to evade detection and uses tools such as STEALHOOK for privilege escalation, lateral movement and data exfiltration. Key targets include Saudi Arabian organisations and Middle Eastern government agencies, highlighting OilRig's focus on geopolitical intelligence gathering. The campaigns demonstrate advanced persistence, stealth and adaptability in line with state-sponsored objectives.
read more about OilRig's Cyber Tactics: Targeting Middle East Sectors with Stealthy Attacks - Public
OilRig's Cyber Tactics: Targeting Middle East Sectors with Stealthy Attacks
OilRig (APT34) has targeted the government, technology and energy sectors across the Middle East. Its operations include spearphishing campaigns, PowerShell-based backdoors (Helminth, QUADAGENT), and exploitation of vulnerabilities such as CVE-2024-30088. The group relies on obfuscation techniques to evade detection and uses tools such as STEALHOOK for privilege escalation, lateral movement and data exfiltration. Key targets include Saudi Arabian organisations and Middle Eastern government agencies, highlighting OilRig's focus on geopolitical intelligence gathering. The campaigns demonstrate advanced persistence, stealth and adaptability in line with state-sponsored objectives.
read more about OilRig's Cyber Tactics: Targeting Middle East Sectors with Stealthy Attacks - Public
Earth Simnavaz Targets UAE and Persian Gulf Energy Sector with Advanced Cyber Espionage
Earth Simnavaz, also known as APT34 or OilRig, has been targeting governmental entities in the UAE and Gulf region, focusing on the energy sector and critical infrastructure. The group uses sophisticated tactics, including the exploitation of Microsoft Exchange servers for credential theft and privilege escalation via CVE-2024-30088. They employ custom .NET tools, PowerShell scripts, and IIS-based malware to avoid detection. Additionally, the attackers utilize ngrok for persistent access and lateral movement, and manipulate password filters to extract plain-text credentials. These credentials are used for supply chain attacks, with a focus on exfiltrating sensitive data through compromised email servers.
read more about Earth Simnavaz Targets UAE and Persian Gulf Energy Sector with Advanced Cyber Espionage - Public
Analysis of OilRig's Continued Cyberattacks on Israeli Sectors Using Cloud APIs
ESET researchers identified a series of downloaders used by the OilRig group in campaigns against Israeli targets throughout 2022 and 2023. These downloaders, named SampleCheck5000 (SC5k v1-v3), OilCheck, ODAgent, and OilBooster, utilize legitimate cloud service APIs such as Microsoft Graph OneDrive, Outlook, and Office Exchange Web Services for command and control (C&C) communication and data exfiltration. Sharing a common OilRig-operated account, these downloaders enable the exchange of messages, commands, and data uploads between victims and operators. Notably, the same account is often used by multiple victims. The tools are part of OilRig's ongoing efforts to re-compromise persistently targeted entities in Israel, including a manufacturing company, a governmental organization, and a healthcare entity. The use of cloud services helps the downloaders blend into regular network traffic, making detection more challenging.
read more about Analysis of OilRig's Continued Cyberattacks on Israeli Sectors Using Cloud APIs - Public
Crambus Unveils New Malware in Multi-Stage, Multi-Tool Cyber Attack
Crambus launched a sophisticated attack involving multiple malware strains, including three new ones: Tokel, Dirps, and Infostealer.Clipog, along with the known PowerExchange backdoor. The malware provided a wide range of functionalities from executing arbitrary PowerShell commands to information stealing and email monitoring. Living-off-the-land tools like Mimikatz and Plink were also deployed to dump credentials and configure port-forwarding for RDP access, respectively. The attackers displayed an advanced level of evasion, execution, and command-and-control techniques. The malicious activities spanned over several months, indicating a well-coordinated and persistent attack strategy.
read more about Crambus Unveils New Malware in Multi-Stage, Multi-Tool Cyber Attack - Public
OilRig's Dual Campaigns Against Israeli Organizations: A Deep Dive
ESET's September 2023 report analyzes two OilRig (APT34/Lyceum) cyberespionage campaigns that exclusively targeted Israeli organizations: Outer Space (2021) and Juicy Mix (2022). Both campaigns followed the same playbook — OilRig compromised legitimate Israeli websites to serve as C2 servers, then used VBS droppers (likely distributed via spearphishing) to install custom C#/.NET backdoors. In Outer Space, the backdoor was Solar, deployed against an Israeli human resources company; in Juicy Mix, the upgraded Mango backdoor was deployed against a healthcare organization, using a compromised Israeli job portal as C2. Solar is a basic XOR-encrypted backdoor supporting file operations, command execution, and automated data staging. Mango is a more capable successor that adds TLS encryption, native API usage (CreateProcess via DllImport), symbol name obfuscation, and string stacking. Post-compromise tooling included SC5k (a downloader using Microsoft Exchange Web Services draft emails for covert C2), CDumper and EDumper (Chrome and Edge browser credential and cookie stealers), IDumper (a PowerShell-based Windows Credential Manager stealer), and MKG (a C/C++ Chrome data dumper reused from earlier OilRig campaigns). A Mango v1.1.1 variant uploaded to VirusTotal in July 2023 under the name Menorah.exe was also identified, using tecforsc-001-site1.gtempurl[.]com as its C2. ESET notified the Israeli national CERT about all compromised websites identified in the research.
read more about OilRig's Dual Campaigns Against Israeli Organizations: A Deep Dive - Public
Breaking Down OilRig's August 2022 Attack: A Detailed Look at Techniques Used
The Iranian state-sponsored threat actor, OilRig, known for targeting global sectors such as Government, Financial Services, Energy, Telecommunications, and Technology, carried out an attack in August 2022 using a malicious Word document. This document contained embedded macros that dropped additional payloads for discovery, collection, and exfiltration routines. The payloads used PowerShell scripts and Windows utilities for information gathering and established persistence with a scheduled task named "WindowsUpdate". OilRig used multiple techniques in this attack such as Process Discovery, System Information Discovery, File and Directory Discovery, System Network Configuration Discovery, and others.
read more about Breaking Down OilRig's August 2022 Attack: A Detailed Look at Techniques Used - Public
TA452 Utilizes PowerShell and AutoHotkey in its Intrusion
TA452's August 2022 intrusion involved a malicious Word document with a VBA macro that established persistence and C2 communication. The threat actors used AutoHotkey for keylogging, PowerShell scripts for discovery, and exfiltrated data using makecab.exe. They employed sophisticated techniques such as base64 encoding, obfuscation, and scheduled tasks to maintain access and evade detection. The campaign is linked to OilRig group and targeted organizations with custom-tailored malware, hinting at state-sponsored activity. Data was exfiltrated over encrypted channels, with evidence pointing to an organized and targeted approach.
read more about TA452 Utilizes PowerShell and AutoHotkey in its Intrusion - Public
Iranian Cyberattacks Disrupt Albanian Government Systems and Border Operations
Iranian state-sponsored actors launched a series of cyberattacks against Albania, a NATO ally, targeting government systems. The initial attack on July 15, 2022, likely stemmed from Albania’s harboring of the Mujahedeen-e-Khalq (MEK) group. Subsequent attacks disrupted Albania’s Total Information Management System (TIMS), causing delays at borders and ports. Microsoft attributed the attack to Iranian-affiliated APTs, including EUROPIUM (APT34), using tools like ZeroCleare and Jason.exe for ransomware, data exfiltration, and disk wiping. The attacks leveraged vulnerabilities in public-facing applications and brute-force techniques. Albania severed diplomatic ties with Iran as a response, while the US condemned the attacks as a threat to NATO.
read more about Iranian Cyberattacks Disrupt Albanian Government Systems and Border Operations - Public
OilRig Campaigns: Phishing and PowerShell Attacks on Global Sectors
AttackIQ has released attack graphs emulating OilRig’s operations against global sectors, based on reports from Mandiant, Intezer, and Palo Alto Networks. The 2020 social media phishing campaign used LinkedIn to distribute malicious documents, leading to the Tonedeaf backdoor installation, persistence via scheduled tasks, and credential dumping with tools like LaZagne. The 2018 QuadAgent campaign targeted technology service providers and government agencies with PowerShell malware, establishing persistence, and utilizing multi-channel command-and-control communication, including SSL, HTTP, and DNS.
read more about OilRig Campaigns: Phishing and PowerShell Attacks on Global Sectors