Threats Feed
- Public
Iranian Threat Actors Breach 12 Omani Ministries, Exposing 26,000 Records
An Iranian-nexus threat actor targeted 12 Omani government ministries, with a primary focus on the Ministry of Justice and Legal Affairs. Utilizing an exposed UAE-based virtual private server, the operator inadvertently revealed their entire operational toolkit, command-and-control infrastructure, and stolen data. The campaign heavily targeted Oman's government, judicial, law enforcement, and administrative sectors to extract citizen identity data, immigration details, and judicial records. The attackers achieved access via ProxyShell and DotNetNuke vulnerabilities, deploying custom webshells and tools like GodPotato for persistent access and privilege escalation. Ultimately, the operation successfully exfiltrated over 26,000 citizen records and critical system registry hives.
read more about Iranian Threat Actors Breach 12 Omani Ministries, Exposing 26,000 Records - Public
Multi-Stage Attack Chain: How OilRig Targets Global Sectors Using Telegram and Google Drive
APT-C-49 (OilRig), an Iranian state-sponsored threat group, recently launched a sophisticated phishing campaign utilizing Iranian protest-themed Excel lures. Targeting government, finance, energy, telecommunications, and military sectors across the Middle East, US, Europe, and Asia, the group deployed a highly covert, multi-stage attack chain. The infection begins with macro-driven C# compilation, progressing to dead-drop resolving via GitHub. The payload utilizes LSB steganography on Google Drive-hosted images to extract encrypted configurations. Subsequently, it dynamically loads fileless modules into memory for data theft and remote execution, leveraging the Telegram Bot API for encrypted command and control (C2). This campaign highlights OilRig's evolution toward cloud service abuse and in-memory execution to evade detection.
read more about Multi-Stage Attack Chain: How OilRig Targets Global Sectors Using Telegram and Google Drive - Public
OilRig Supply Chain Attack: Stolen Thai IT Vendor Certificates Hide Karkoff Backdoor
PolySwarm researchers have uncovered previously unreported cyberespionage activity by the Iranian state-sponsored threat actor OilRig (APT34). The campaign leverages a stolen Extended Validation (EV) code signing certificate from a legitimate Thai IT vendor, MOSCII Corporation, to sign malicious payloads, including the custom Karkoff backdoor. By masquerading as legitimate vendor tooling, OilRig targeted Thailand’s energy sector, specifically the Electricity Generating Authority of Thailand (EGAT). The attackers employed advanced defense evasion techniques, such as spoofing compile timestamps to 2014 and padding binaries to 10 MB to bypass automated sandbox environments. This supply chain intrusion highlights OilRig’s continued evolution in targeting critical infrastructure and government agencies through trusted vendor relationships across Southeast Asia and the Middle East.
read more about OilRig Supply Chain Attack: Stolen Thai IT Vendor Certificates Hide Karkoff Backdoor - Public
APT34 Targets Iraqi Government with Dual-Channel C2 and Obfuscated Backdoors
APT34 (OilRig) has launched a targeted cyber espionage campaign against Iraqi government entities since 2024, using spearphishing emails with forged documents to deploy custom C# malware disguised as PDF files. The malware performs system reconnaissance, anti-VM checks, and sets up persistence via scheduled tasks. It communicates with command-and-control infrastructure through both HTTP and compromised Iraqi government email accounts (SMTP/IMAP). The group also utilizes European-hosted infrastructure with deceptive 404 pages and obfuscated communication protocols. Targeted sectors include government, energy, finance, defense, and telecommunications, indicating a continued focus on intelligence gathering in the Middle East.
read more about APT34 Targets Iraqi Government with Dual-Channel C2 and Obfuscated Backdoors - Public
OilRig: Cyber-Espionage Targeting Global Critical Sectors
SOCRadar's January 2025 dark web profile on OilRig (APT34) documents the group as one of Iran's most persistent and sophisticated state-sponsored threat actors, active since at least 2016. OilRig targets government agencies, energy and oil & gas companies, telecommunications providers, financial institutions, universities, and research institutions — primarily across the Middle East, with confirmed extensions to Europe, North America, and Asia. The group follows a full kill chain methodology: reconnaissance using Netstat and Systeminfo; weaponization with custom tools including BondUpdater and Helminth; spearphishing delivery via email attachments, links, and LinkedIn (T1566.001/002/003); exploitation via Mimikatz for credential dumping and CVE-2017-11774 to abuse Outlook Home Page for persistence; C2 via DNS tunneling, encrypted channels, and fallback HTTP; and exfiltration over FTP (T1048.003). Post-compromise tools include LaZagne, ISMInjector, BONDUPDATER, PAExec, KEYPUNCH, LONGWATCH, VALUEVAULT, PICKPOCKET, and GOLDIRONY. OilRig also abuses Plink for tunnel creation and uses web shells for persistence. In destructive operations, the group has deployed ZeroCleare — a disk-wiping malware — demonstrating capability beyond espionage. The group regularly updates its toolset and evades detection through base64 obfuscation, AV testing, file deletion, and domain generation algorithms. OilRig's targeting aligns consistently with Iranian geopolitical and economic interests.
read more about OilRig: Cyber-Espionage Targeting Global Critical Sectors - Public
OilRig's Cyber Tactics: Targeting Middle East Sectors with Stealthy Attacks
OilRig (APT34) has targeted the government, technology and energy sectors across the Middle East. Its operations include spearphishing campaigns, PowerShell-based backdoors (Helminth, QUADAGENT), and exploitation of vulnerabilities such as CVE-2024-30088. The group relies on obfuscation techniques to evade detection and uses tools such as STEALHOOK for privilege escalation, lateral movement and data exfiltration. Key targets include Saudi Arabian organisations and Middle Eastern government agencies, highlighting OilRig's focus on geopolitical intelligence gathering. The campaigns demonstrate advanced persistence, stealth and adaptability in line with state-sponsored objectives.
read more about OilRig's Cyber Tactics: Targeting Middle East Sectors with Stealthy Attacks - Public
Earth Simnavaz Targets UAE and Persian Gulf Energy Sector with Advanced Cyber Espionage
Earth Simnavaz, also known as APT34 or OilRig, has been targeting governmental entities in the UAE and Gulf region, focusing on the energy sector and critical infrastructure. The group uses sophisticated tactics, including the exploitation of Microsoft Exchange servers for credential theft and privilege escalation via CVE-2024-30088. They employ custom .NET tools, PowerShell scripts, and IIS-based malware to avoid detection. Additionally, the attackers utilize ngrok for persistent access and lateral movement, and manipulate password filters to extract plain-text credentials. These credentials are used for supply chain attacks, with a focus on exfiltrating sensitive data through compromised email servers.
read more about Earth Simnavaz Targets UAE and Persian Gulf Energy Sector with Advanced Cyber Espionage - Public
Veaty and Spearal Malware Used in Targeted Iraqi Government Attacks
Check Point Research has discovered new malware, Veaty and Spearal, used in Iran-linked cyber attacks against Iraqi government infrastructure. The malware uses techniques such as passive IIS backdoors, DNS tunneling, and compromised email accounts for C2 communications. The attackers also used social engineering tactics and double-extension files to trigger infections. Spearal communicates via DNS queries, while Veaty uses compromised email accounts within the gov-iq.net domain. The campaign targets Iraqi government agencies with ties to the APT34 group, demonstrating a sophisticated and persistent threat to Iraqi infrastructure.
read more about Veaty and Spearal Malware Used in Targeted Iraqi Government Attacks - Public
Menorah Malware: APT34’s Espionage Tool in Middle East Campaigns
The Menorah malware, used by the APT34 threat group to target organisations in the Middle East, creates a mutex to ensure single-instance operation. The malware exfiltrates data and executes commands from a hardcoded command and control (C2) server. These commands include creating processes, listing files, downloading files and exfiltrating arbitrary data. The analysis provides technical details, including SHA256 hashes, mutex identifiers and the address of the C2 server, to aid detection and response efforts.
read more about Menorah Malware: APT34’s Espionage Tool in Middle East Campaigns - Public
Analysis of OilRig's Continued Cyberattacks on Israeli Sectors Using Cloud APIs
ESET researchers identified a series of downloaders used by the OilRig group in campaigns against Israeli targets throughout 2022 and 2023. These downloaders, named SampleCheck5000 (SC5k v1-v3), OilCheck, ODAgent, and OilBooster, utilize legitimate cloud service APIs such as Microsoft Graph OneDrive, Outlook, and Office Exchange Web Services for command and control (C&C) communication and data exfiltration. Sharing a common OilRig-operated account, these downloaders enable the exchange of messages, commands, and data uploads between victims and operators. Notably, the same account is often used by multiple victims. The tools are part of OilRig's ongoing efforts to re-compromise persistently targeted entities in Israel, including a manufacturing company, a governmental organization, and a healthcare entity. The use of cloud services helps the downloaders blend into regular network traffic, making detection more challenging.
read more about Analysis of OilRig's Continued Cyberattacks on Israeli Sectors Using Cloud APIs - Public
Crambus Unveils New Malware in Multi-Stage, Multi-Tool Cyber Attack
Crambus launched a sophisticated attack involving multiple malware strains, including three new ones: Tokel, Dirps, and Infostealer.Clipog, along with the known PowerExchange backdoor. The malware provided a wide range of functionalities from executing arbitrary PowerShell commands to information stealing and email monitoring. Living-off-the-land tools like Mimikatz and Plink were also deployed to dump credentials and configure port-forwarding for RDP access, respectively. The attackers displayed an advanced level of evasion, execution, and command-and-control techniques. The malicious activities spanned over several months, indicating a well-coordinated and persistent attack strategy.
read more about Crambus Unveils New Malware in Multi-Stage, Multi-Tool Cyber Attack - Public
APT34's Menorah Malware: A Look at the New Cyber Threat Targeting Saudi Arabia
Trend Micro researchers identified APT34 using a new custom backdoor named Menorah — a .NET-based malware delivered via a malicious Word document ("MyCv.doc") disguised as a Seychelles government license registration form. The document contained hidden macros that dropped Menorah into the system's %ALLUSERSPROFILE%\Office365 directory and established persistence through a scheduled task named "OneDriveStandaloneUpdater." Once installed, Menorah fingerprinted the victim machine using a hashed combination of machine name and username, communicated with a remote C2 server over HTTP using Base64-encoded, XOR-obfuscated traffic, and supported commands for file listing, selective file upload, shell command execution, and file download. The pricing in the lure document was denominated in Saudi Riyal, strongly suggesting the targeted victim was an organization in Saudi Arabia. Trend Micro noted functional similarities to APT34's earlier SideTwist backdoor, particularly in C2 communication and machine fingerprinting logic, though Menorah is a .NET reimplementation with enhanced sandbox evasion and traffic obfuscation.
read more about APT34's Menorah Malware: A Look at the New Cyber Threat Targeting Saudi Arabia - Public
OilRig's Dual Campaigns Against Israeli Organizations: A Deep Dive
ESET's September 2023 report analyzes two OilRig (APT34/Lyceum) cyberespionage campaigns that exclusively targeted Israeli organizations: Outer Space (2021) and Juicy Mix (2022). Both campaigns followed the same playbook — OilRig compromised legitimate Israeli websites to serve as C2 servers, then used VBS droppers (likely distributed via spearphishing) to install custom C#/.NET backdoors. In Outer Space, the backdoor was Solar, deployed against an Israeli human resources company; in Juicy Mix, the upgraded Mango backdoor was deployed against a healthcare organization, using a compromised Israeli job portal as C2. Solar is a basic XOR-encrypted backdoor supporting file operations, command execution, and automated data staging. Mango is a more capable successor that adds TLS encryption, native API usage (CreateProcess via DllImport), symbol name obfuscation, and string stacking. Post-compromise tooling included SC5k (a downloader using Microsoft Exchange Web Services draft emails for covert C2), CDumper and EDumper (Chrome and Edge browser credential and cookie stealers), IDumper (a PowerShell-based Windows Credential Manager stealer), and MKG (a C/C++ Chrome data dumper reused from earlier OilRig campaigns). A Mango v1.1.1 variant uploaded to VirusTotal in July 2023 under the name Menorah.exe was also identified, using tecforsc-001-site1.gtempurl[.]com as its C2. ESET notified the Israeli national CERT about all compromised websites identified in the research.
read more about OilRig's Dual Campaigns Against Israeli Organizations: A Deep Dive - Public
APT34 Targets U.S. Enterprises with New SideTwist Trojan Variant
APT34 has launched a new phishing campaign, using a decoy file named “GGMS Overview.doc” to target U.S.-based enterprises. The campaign employs a variant of the SideTwist Trojan for long-term control over victim hosts. Malicious macros in the document deploy the Trojan, which communicates with a C&C server. Interestingly, the C&C IP address is associated with the United States Department of Defense Network Information Center. The Trojan is capable of executing commands from the C&C and exfiltrating local files. It suggests the APT34 group might be conducting a test operation to preserve attack resources.
read more about APT34 Targets U.S. Enterprises with New SideTwist Trojan Variant - Public
PowerExchange Campaign: APT34's Persistent Threat to UAE Government
The PowerExchange campaign, attributed to APT34, targeted Microsoft Exchange servers of a UAE government entity using a PowerShell backdoor. Delivered via phishing emails, the backdoor used the MicrosoftEdgeUpdateService for persistence, enabling frequent execution. The attackers used the Exchange Web Services API for command-and-control, deploying further payloads like Invoke-TheHash modules for lateral movement and webshells for credential harvesting.
read more about PowerExchange Campaign: APT34's Persistent Threat to UAE Government - Public
APT34 Suspected in Coordinated Attack on UAE Government Infrastructure
FortiEDR's research lab discovered a series of attacks on a government entity in the United Arab Emirates. The attacks involved a novel PowerShell-based backdoor dubbed PowerExchange. The backdoor's command and control (C2) protocol used the victim's Exchange server for communication. Further investigations revealed additional implants and a new web shell named ExchangeLeech that could harvest credentials. Iranian threat actor APT34 is suspected to be behind the attacks, which involved phishing emails for initial access, lateral movement within the network, and using scheduled tasks for persistence.
read more about APT34 Suspected in Coordinated Attack on UAE Government Infrastructure - Public
Breaking Down OilRig's August 2022 Attack: A Detailed Look at Techniques Used
The Iranian state-sponsored threat actor, OilRig, known for targeting global sectors such as Government, Financial Services, Energy, Telecommunications, and Technology, carried out an attack in August 2022 using a malicious Word document. This document contained embedded macros that dropped additional payloads for discovery, collection, and exfiltration routines. The payloads used PowerShell scripts and Windows utilities for information gathering and established persistence with a scheduled task named "WindowsUpdate". OilRig used multiple techniques in this attack such as Process Discovery, System Information Discovery, File and Directory Discovery, System Network Configuration Discovery, and others.
read more about Breaking Down OilRig's August 2022 Attack: A Detailed Look at Techniques Used - Public
New APT34 Malware Variant Abuses Exchange Servers for Data Exfiltration
Trend Micro researchers identified a December 2022 cyberespionage campaign attributed to APT34 targeting government entities in the Middle East. The attack used a custom .NET dropper (Trojan.MSIL.REDCAP.AD) to deploy four components: a malicious Password Filter DLL (psgfilter.dll) registered into the Windows LSA to intercept plaintext credentials on every password change, a backdoor (Backdoor.MSIL.REDCAP.A) that authenticated to victim Exchange Servers using stolen credentials via Exchange Web Services (EWS), configuration files, and the Microsoft Exchange WebServices library. Stolen credentials and files were exfiltrated as email attachments through compromised government mailboxes to six external attacker-controlled addresses at Proton Mail and Gmail. The campaign's novelty lies in combining password filter abuse for persistent credential harvesting with Exchange-based exfiltration over legitimate mail traffic — a technique first observed for APT34. Hardcoded Exchange server domains and attacker email addresses inside the samples, along with code-level overlap with APT34's prior Karkoff and Saitama implants, formed the basis of attribution. Researchers noted evidence of a deep foothold across a government Active Directory forest, suggesting this was one component of a larger ongoing campaign.
read more about New APT34 Malware Variant Abuses Exchange Servers for Data Exfiltration - Public
Saitama Malware Uses DNS for Stealthy C2 Communications
The Saitama implant, uncovered by Malwarebytes, uses DNS for Command and Control (C2) communications. Targeting the Jordan government, this malware employs domain randomization and long sleep times to evade detection. It encodes data using a shared key and a pseudo-random number generator, making detection challenging. The implant’s hardcoded sleep values and unique DNS queries ensure stealth, though the data transfer rate is slow.
read more about Saitama Malware Uses DNS for Stealthy C2 Communications - Public
OilRig Campaigns: Phishing and PowerShell Attacks on Global Sectors
AttackIQ has released attack graphs emulating OilRig’s operations against global sectors, based on reports from Mandiant, Intezer, and Palo Alto Networks. The 2020 social media phishing campaign used LinkedIn to distribute malicious documents, leading to the Tonedeaf backdoor installation, persistence via scheduled tasks, and credential dumping with tools like LaZagne. The 2018 QuadAgent campaign targeted technology service providers and government agencies with PowerShell malware, establishing persistence, and utilizing multi-channel command-and-control communication, including SSL, HTTP, and DNS.
read more about OilRig Campaigns: Phishing and PowerShell Attacks on Global Sectors - Public
APT34’s Saitama Agent: Phishing and DNS Tunneling in Jordan
APT34's Saitama Agent employs a spear phishing email with a malicious Excel attachment to deliver malware using unique DNS tunneling and stateful programming techniques. The Excel document contains a VBA macro that hides its activities and communicates with the C2 server using DNS requests. The macro checks for mouse connections, drops multiple files, and uses a scheduled task for persistence. The campaign appears to be targeting Jordan, leveraging a Jordanian government ministry's logo to deceive victims.
read more about APT34’s Saitama Agent: Phishing and DNS Tunneling in Jordan - Public
Understanding Saitama: The Latest Weapon in APT34's Cyber Arsenal
Renato Marinho of Morphus Labs (SANS ISC) provides a technical decoder analysis of Saitama's novel DNS tunneling C2 mechanism, complementing the Malwarebytes discovery reports. Saitama's key innovation is encoding attacker commands directly inside IPv4 address octets returned by the C2 nameserver — rather than using DNS TXT records or other large-payload record types. The first octet carries a control code (indicating whether a command or payload is being issued), and the subsequent three octets encode three ASCII characters of the command. For example, to issue 'whoami', the server returns two IPs: 70.119.104.111 (control byte 70; w=119, h=104, o=111) and 97.109.105.49 (control byte 97; a=109, m=105, i=49). This approach makes commands indistinguishable from ordinary A-record DNS responses in environments that do not inspect IPv4 address content. Data exfiltration flows in the opposite direction: the victim encodes command output in chunked subdomain strings of attacker-controlled domains (joexpediagroup[.]com, uber-asia[.]com), reassembled by the C2. Marinho captured a live 'ver' exfiltration session reconstructing "Microsoft Windows [Version 10.0.18363.418]" across four DNS queries. The Saitama binary is a .NET assembly that can be readily decompiled, and Morphus Labs released an open-source decoder tool (saitama_translator) on GitHub to help defenders translate captured DNS sessions from infected hosts. The author notes the accessibility of Saitama's implementation could encourage other threat actors to adopt similar IPv4-encoding DNS tunneling techniques.
read more about Understanding Saitama: The Latest Weapon in APT34's Cyber Arsenal - Public
APT34 Uses Saitama Backdoor to Attack Jordanian Government through DNS Tunnelling
Malwarebytes Threat Intelligence details the complete four-step DNS tunneling state machine used by the Saitama backdoor in APT34's attack on Jordan's Foreign Ministry. The maldoc was an Excel file named "Confirmation Receive Document.xls" — a spearphishing attachment that, when opened, installed Saitama (update.exe) and established persistence via Office template macros. All C2 communication runs over DNS using three interchangeable lookalike domains (uber-asia[.]com, asiaworldremit[.]com, joexpediagroup[.]com). Saitama's key evasion design addresses two DNS-specific problems: unencrypted traffic (solved with message obfuscation) and aggressive caching (solved by incrementing a counter with every request, which generates a unique custom base36 alphabet per message via substitution cipher, ensuring no two DNS queries look the same). The four-stage protocol works as follows: (1) Make Contact — Saitama picks a random counter (0–46655), encodes an initial beacon including the string "aharuto" using the counter-derived alphabet, and receives a unique agent ID in the last octet of the C2's A-record response; (2) Ask for Command — Saitama encodes its agent ID and signals readiness; the C2 responds with the payload size encoded in the final three octets of the IP address (first octet 129–255 acts as a signal byte); (3) Get Command — Saitama retrieves the encoded command, with the first IP octet identifying one of five functions (43=Static, 70=Cmd, 71=CompressedCmd, 95=File, 96=CompressedFile) and remaining octets carrying ASCII command bytes; (4) Run Command — output is chunked into 12-byte segments, individually encoded, and exfiltrated via further DNS queries. The C2 domain is chosen at random from the three root domains at each step, further varying the traffic profile.
read more about APT34 Uses Saitama Backdoor to Attack Jordanian Government through DNS Tunnelling - Public
Unveiling APT34’s Advanced Attack Tactics: From Excel Macros to DNS Tunneling
FortiGuard Labs provides the most detailed technical analysis of the Saitama campaign against a Jordanian diplomat, identifying unique techniques across both the Excel macro and the dropped backdoor. The spearphishing email posed as a colleague from the target's own IT department, using the real employee's first and last name — an insider-impersonation lure rather than a generic government spoofing attempt. The Excel macro uses a sheet visibility toggle as an anti-emulation technique (targeting tools like ViperMonkey that may not support all Excel features), and beacons nine distinct execution states to the C2 via WMI Win32_PingStatus queries with unique subdomain prefixes per step, allowing the attacker to monitor macro progress in real time through their DNS logs. Three payload files are decoded from base64 UserForm label captions: update.exe (malware), update.exe.config (configuration), and a signed Microsoft.Exchange.WebServices.dll (clean, for legitimacy). The scheduled task "MicrosoftUpdate" runs every 4 hours using deprecated IdleSettings (10-minute idle requirement) for up to 20 days. The Saitama backdoor uses a Mersenne Twister PRNG seeded with an agent ID to generate DGA subdomains across three lookalike C2 domains; it validates DNS A-record responses by requiring the first octet to be ≥ 128 before treating the response as valid C2 data. Exfiltration uses Base32 encoding (consistent with APT34's DNSpionage tool) compressed before encoding. A mutex (726a06ad-475b-4bc6-8466-f08960595f1e) prevents concurrent execution. The C2 IP 193.239.84.207 has historical associations with NSO Group Pegasus, APT34, and GoziIFSB infrastructure. Fortinet assesses the 6–8 hour sleep is deliberately timed for a diplomat's work schedule, and the hardcoded internal network commands suggest prior limited access to the target network before this spearphishing attempt was made.
read more about Unveiling APT34’s Advanced Attack Tactics: From Excel Macros to DNS Tunneling