Threats Feed
- Public
Unraveling OilRig's Cyber Operations: Israel and Middle East in the Crosshairs
Palo Alto Networks Unit 42's September 2017 report documents OilRig's adversary infrastructure by tracing activity from a previously discovered TwoFace web shell. Researchers identified a network of 14 C2 IP addresses and 7 credential-harvesting domains — all designed to spoof the webmail portals of specific Israeli targets, including Tel Aviv University, Hebrew University of Jerusalem, Bezeq International, Macro Advisory Partners, Tidhar Group, and the Institute for National Security Studies. The harvesters were exact replicas of the legitimate login pages, indicating a targeted credential theft mission against Israel-connected organizations. Analysis of tools uploaded to compromised web servers revealed OilRig's post-exploitation toolkit: Mimikatz (credential dumping), PsExec (remote execution), PuTTY Link/Plink (SSH tunneling for lateral movement), and RGDoor (a custom IIS backdoor for persistent fallback access). Two additional web shells — RunningBee (password-protected) and LittleFace (command execution via HTTP POST) — were also identified. A shared Mimikatz sample linked TwoFace and OilRig infrastructure, establishing tactical overlap between the two campaigns. Targeted sectors included think tanks, universities, strategic consulting firms, real estate companies, and telecommunications providers across the Middle East, with a heavy focus on Israeli interests.
read more about Unraveling OilRig's Cyber Operations: Israel and Middle East in the Crosshairs - Public
OilRig's Developmental Tactics: Evading Antivirus Through Rigorous Testing
Palo Alto Unit42 documents the earliest known example of OilRig's systematic AV evasion testing process, conducted in June and November 2016 against their ClaySlide delivery documents — the same organized methodology Unit42 would later observe again in the 2018 BONDUPDATER campaign. In June 2016, OilRig created a base test file on June 13 and then ran 17 iterative modifications over a 2-hour window on June 15, starting at 4 AV detections and ending at 0. In November 2016, a second testing session generated 7 iterations in approximately 30 minutes on November 15 (following a base file on November 14), reducing detections from 5 to 2. Both sessions used the same pattern: upload to a public AV scanning service, measure the detection count, make one targeted change, re-upload, repeat. The June testing covered: payload removal (to isolate macro detection), removal and re-addition of the scheduled task creation block, command encoding experiments (base64, hexadecimal), intentional misspellings of key strings ("poawearshell", "scshtassks"), use of a FireEye blog URL as a base64 filler to test string-based detection, keyboard mashing, variable/function renaming, folder path changes, and reverting to the base document to restart the process. The November testing focused on decoy worksheet modifications (changing worksheet name, content, and sheet hash), function name obfuscation (Doom_Init → Doon_Init → Ini), variable name changes (BackupVbs → Backup_Vbs), string concatenation of the scheduled task creation command, and moving payload storage locations within the spreadsheet cells. The June campaign used C2 domain update-kernal[.]net; the November campaign used updateorg[.]com with the same Helminth payload. Unit42 assesses this testing behavior reflects a professionally organized operations model in which delivery documents are extended for as long as possible through iterative evasion refinement.
read more about OilRig's Developmental Tactics: Evading Antivirus Through Rigorous Testing - Public
OilRig Campaign Resurfaces: Iranian Hackers Target Israel with Helminth Trojan
Between April 19-24, 2017, several Israeli organizations, including high-tech development companies, medical entities, and educational institutions were targeted by a politically motivated campaign attributed to the Iranian hacker group responsible for the OilRig malware campaigns. The fileless attack was delivered through compromised email accounts at Ben-Gurion University using Microsoft Word documents exploiting the CVE-2017-0199 vulnerability. The Helminth Trojan was installed as a result, bearing a striking similarity to the OilRig campaign conducted against Middle Eastern financial institutions the previous year. The threat actors exploited the gap between patch release and rollout, with active C&C servers still operational at the time of report publication.
read more about OilRig Campaign Resurfaces: Iranian Hackers Target Israel with Helminth Trojan - Public
Stolen Code Signatures Fuel OilRig's Multi-Nation Cyber Attacks
The Iranian threat agent OilRig, active since the end of 2015, has been implicated in a wave of cyber attacks targeting several countries, namely Israel, Turkey, Qatar, Kuwait, UAE, Saudi Arabia, and Lebanon. In their most recent campaigns, they have leveraged advanced strategies, setting up fake VPN portals, counterfeit websites, and using stolen code signing certificates to give their malware an appearance of authenticity. This not only illustrates their high technical capability, but also underscores the complexity and effectiveness of their operations. These attacks have largely targeted IT and financial institutions, causing significant concerns in these sectors.
read more about Stolen Code Signatures Fuel OilRig's Multi-Nation Cyber Attacks - Public
OilRig Campaign: Malware Updates and Expanded Global Targets
The OilRig cyberattack campaign, first analyzed in May 2016, continues to evolve, targeting government organizations and companies in Saudi Arabia, Qatar, Turkey, Israel, and the United States. Using spear-phishing emails with malicious Microsoft Excel documents, the attackers have updated their toolset, including Clayslide delivery documents and the Helminth backdoor. The malware communicates with remote servers via HTTP and DNS for command and control. Despite its lack of sophistication, the malware successfully operates under the radar in many establishments due to techniques like DNS command and control.
read more about OilRig Campaign: Malware Updates and Expanded Global Targets - Public
OilRig Group Unleashes Coordinated Cyber Campaigns on Saudi Arabian Industries
Palo Alto Unit42 introduces the OilRig campaign — naming both the threat group and the Helminth backdoor based on the Persian word "Nafti" (نفتی, meaning "oily") found hardcoded alongside philosopher names (Plato, Arasto, ALAfghani) in malware samples. The report documents two waves of targeted attacks on Saudi Arabian organizations across the financial, technology, defense, and telecommunications sectors: an August 2015 wave using fake job offers to deliver the Helminth executable variant, and a May 2016 wave using a service-provider social engineering theme to deliver the Helminth script variant via Clayslide Excel macro documents. The Clayslide delivery documents display a fake "Incompatible" worksheet instructing the user to enable macros, after which they show legitimate-looking decoy content (internal IP status tables) while installing Helminth's two-component script variant: update.vbs (HTTP C2 for batch script download and output upload) and dns.ps1 (DNS-based C2 using IP address octets as data transport, with 33.33.x.x as a start marker and 35.35.x.x as a stop marker). Both scripts create a fully functional remote shell. The executable variant, delivered via the HerHer dropper Trojan, adds a keylogger module (wintrust.hlm DLL) that monitors keystrokes and clipboard contents. Both variants beacon hardcoded per-sample "Group" (targeted organization name) and "Name" (philosopher/Persian word) values in C2 traffic, confirming deliberate pre-operational targeting. WHOIS registrant data for C2 domains included Iranian email addresses (chmail.ir provider, Tehran geolocation), consistent with Iranian-based operators. The scheduled task "GoogleUpdateTaskMachineUI" ran update.vbs every three minutes.
read more about OilRig Group Unleashes Coordinated Cyber Campaigns on Saudi Arabian Industries