Latest Update27/08/2026

Threats Feed

  1. Public

    OilRig Continues Assault on Middle Eastern Governments and Businesses with BONDUPDATER

    The OilRig group has continued its cyber attacks, mainly in the Middle East. The group targeted governmental organizations using spear-phishing emails, delivering an updated Trojan known as BONDUPDATER. The Trojan allows threat actors to upload and download files, execute commands, and uses DNS tunneling for C2 communications. It also employs a new technique of DNS tunneling protocol via DNS TXT records. The continued onslaught of OilRig attacks into 2018 is of concern, with variations of previous tools being reused, capitalizing on their prior success.

    read more about OilRig Continues Assault on Middle Eastern Governments and Businesses with BONDUPDATER
  2. Public

    Time-Zone Specific OopsIE Variant Reinforces OilRig’s Targeted Approach

    Palo Alto Unit42 documents an evolved OopsIE variant deployed by OilRig against a Middle Eastern government agency in mid-2018, adding nine anti-analysis and anti-VM checks to an otherwise functionally similar trojan. The spearphishing email used an Arabic subject line ("Business continuity management training") sent to a group email address whose members had publicly published documents on that topic — indicating deliberate target research. The nine evasion checks (executed before any functional code runs) query for: CPU fan presence (Win32_Fan WMI — novel at time of publication), CPU temperature (MSAcpi_ThermalZoneTemperature — also seen in GravityRAT), mouse pointer manufacturer strings (Win32_PointingDevice — checks for VMware/VBox/Oracle), hard disk model strings (Win32_DiskDrive), motherboard manufacturer strings (Win32_BaseBoard), Sandboxie DLL (SbieDll.dll), VBox DLL (vboxmrxnp.dll), VMware DLLs (vmGuestLib.dll / vmbusres.dll), and a time zone check (DaylightName compared against Iran, Arab, Arabia, Middle East — covering UTC+2/+3/+3.5/+4 across 10 countries). A tenth check requires the user to click OK on a fake user32.dll error dialog, ensuring human interaction. Strings are obfuscated using a hyphen-delimited integer encoding (each value minus 1, converted to character). The GUID written to GDI.bin is used as the scheduled task name (replacing the hardcoded name in earlier variants), and the Trojan copies itself to %APPDATA%\Windows\WindowsImplantment.exe with hidden and system flags. C2 communication uses Internet Explorer application object HTTP requests; URL parameter strings are reversed from the previous variant (chk→khc, what→tahw, resp→pser, oops→spoo). A 2-second delay using cmd.exe choice is inserted post-dialog. Four commands are supported: run command (1), download file (2), read/upload file (3), and boom! (uninstall). C2 domain: windowspatch[.]com.

    read more about Time-Zone Specific OopsIE Variant Reinforces OilRig’s Targeted Approach
  3. Public

    Adapting and Evolving: A Look at the OilRig's QUADAGENT-Driven Attacks

    The OilRig group continued its espionage activities, primarily within the Middle East. Between May and June 2018, they orchestrated multiple attacks using compromised accounts from a Middle Eastern government agency, targeting a technology services provider and another government entity. The group leveraged a PowerShell backdoor called QUADAGENT and employed spear-phishing tactics, obfuscation using the Invoke-Obfuscation toolkit, and PE files to achieve their objectives. They also used stolen credentials and decoy dialog boxes to reduce suspicion and evade detection.

    read more about Adapting and Evolving: A Look at the OilRig's QUADAGENT-Driven Attacks
  4. Public

    Decoding OilRig's New Cyberthreat: How OopsIE Trojan Targeted Middle East Organizations

    The OilRig threat group initiated an attack targeting organizations in the Middle East through spear-phishing emails with a malicious Microsoft Word document called ThreeDollars. The document contained a new payload, OopsIE Trojan, which was delivered either directly or through the document. OilRig implemented different delivery tactics due to prior encounters with their targeted organization. They also adopted password-protected documents as an evasion tactic. The OopsIE Trojan communicated with a C2 server and executed commands provided by it.

    read more about Decoding OilRig's New Cyberthreat: How OopsIE Trojan Targeted Middle East Organizations
  5. Public

    APT34's Enhanced Cyber Espionage: BONDUPDATER and POWRUNER Malware Variants Unveiled

    Booz Allen DarkLabs' Threat Hunt team pivoted from FireEye's December 2017 APT34 report to discover three previously unreported BONDUPDATER/POWRUNER variants, then extended that work using a ClearSky tip to find two more, yielding seven total malware samples linked to APT34 operations. All variants follow the same execution chain: a dropper (.exe) creates and runs rUpdateChecker.ps1 in a staging directory (C:\ProgramData\Windows\Microsoft\java\ or C:\Users\Public\Java), which creates a VBScript and a scheduled task to run the script every minute. The VBScript deploys POWRUNER — a PowerShell backdoor for arbitrary command execution and TCP-based data exfiltration — and in most variants also BONDUPDATER, a downloader that uses a domain generation algorithm (DGA) for DNS-based C2. The DGA for poison-frog[.]club variants generates subdomains from a unique victim ID (derived from MAC address or whoami), randomly inserted parameters, random hex characters, and hardcoded string elements — producing distinct send and receive subdomain formats. A second cluster, identified from a ClearSky tip, uses window5[.]win as the C2 domain with a URI of /update.aspx. Infrastructure pivoting confirmed that poison-frog[.]club, proxycheker[.]pro, and associated IPs (82.102.14.219, 94.23.172.164, 185.15.247.147) overlap with domains mentioned in the original FireEye report (dns-update[.]club, hpserver[.]online, anyportals[.]com), corroborating the APT34 attribution. Booz Allen also provides a YARA rule for static detection of the dropper binaries based on PDB path strings.

    read more about APT34's Enhanced Cyber Espionage: BONDUPDATER and POWRUNER Malware Variants Unveiled
  6. Public

    TwoFace Webshell to RGDoor: A Resilient Cyber Attack on Middle Eastern Organizations

    OilRig was identified by Unit 42 as deploying a secondary backdoor, RGDoor, via the TwoFace webshell to regain access to compromised webservers once TwoFace was detected and removed. Targeting eight Middle Eastern government organizations, a financial institution, and an educational institution, RGDoor allows OilRig to execute commands and upload and download files from the server. The backdoor was created using C++, resulting in a DLL that relies on HTTP POST requests to communicate with the backdoor.

    read more about TwoFace Webshell to RGDoor: A Resilient Cyber Attack on Middle Eastern Organizations
  7. Public

    OilRig Perfects Evasion Techniques with TwoFace Webshell

    Unit 42 monitored OilRig's testing of the TwoFace webshell, specifically its TwoFace++ variant, to evade detection by security tools. Analysis revealed that OilRig's developers systematically modified the webshell's loader script to reduce detection rates, ultimately achieving zero detection by altering code related to the embedded payload's update functionality. The testing involved decoding and encrypting webshell data and frequent code alterations to pinpoint and circumvent security measures. Additionally, another webshell, named DarkSeaGreenShell, was discovered during these tests.

    read more about OilRig Perfects Evasion Techniques with TwoFace Webshell
  8. Public

    APT34's Utilization of Microsoft Office Vulnerabilities to Compromise Middle Eastern Organizations

    The Iranian cyber espionage group APT34 exploited two vulnerabilities (CVE-2017-0199 and CVE-2017-11882) in Microsoft Office to deliver malicious payloads against Middle Eastern governmental organizations. The group utilized spear-phishing emails with malicious .rtf files attached, which upon opening, exploited the vulnerabilities and executed malicious scripts. The scripts, POWRUNER and BONDUPDATER, performed actions such as persistence and command-and-control (C2) communication, including use of a domain generation algorithm (DGA) to evade detection.

    read more about APT34's Utilization of Microsoft Office Vulnerabilities to Compromise Middle Eastern Organizations
  9. Public

    OilRig Threat Group Introduces ALMA Communicator in Spear-Phishing Attacks

    The OilRig threat group has been utilizing a refined version of the Clayslide delivery document for spear-phishing attacks since May 2016. Recently, they have developed a new custom Trojan named "ALMA Communicator", and incorporated the use of Mimikatz for credential harvesting in the delivery phase of the attack. The targets included an individual at a public utilities company in the Middle East. ALMA Communicator uses DNS tunneling for C2 communication and has some data transfer limitations, which may have prompted the early deployment of Mimikatz.

    read more about OilRig Threat Group Introduces ALMA Communicator in Spear-Phishing Attacks
  10. Public

    Inside OilRig's Attack on UAE Government: ISMInjector and CVE-2017-0199 Exploit in Play

    The OilRig group launched a spear-phishing attack on an organization within the United Arab Emirates government on August 23, 2017. The phishing email contained two malicious attachments, and also used an image hosted on an adversary-owned server to potentially track email opens. OilRig likely gained access to a user's Outlook Web Access (OWA) account within the targeted organization to send phishing emails internally. The attachments included a document with a malicious macro and a file that attempted to exploit the CVE-2017-0199 vulnerability. The ultimate payloads were the new ISMInjector tool and the ISMAgent Trojan, with infrastructure linked to previous OilRig campaigns.

    read more about Inside OilRig's Attack on UAE Government: ISMInjector and CVE-2017-0199 Exploit in Play
  11. Public

    Unraveling OilRig's Cyber Operations: Israel and Middle East in the Crosshairs

    Palo Alto Networks Unit 42's September 2017 report documents OilRig's adversary infrastructure by tracing activity from a previously discovered TwoFace web shell. Researchers identified a network of 14 C2 IP addresses and 7 credential-harvesting domains — all designed to spoof the webmail portals of specific Israeli targets, including Tel Aviv University, Hebrew University of Jerusalem, Bezeq International, Macro Advisory Partners, Tidhar Group, and the Institute for National Security Studies. The harvesters were exact replicas of the legitimate login pages, indicating a targeted credential theft mission against Israel-connected organizations. Analysis of tools uploaded to compromised web servers revealed OilRig's post-exploitation toolkit: Mimikatz (credential dumping), PsExec (remote execution), PuTTY Link/Plink (SSH tunneling for lateral movement), and RGDoor (a custom IIS backdoor for persistent fallback access). Two additional web shells — RunningBee (password-protected) and LittleFace (command execution via HTTP POST) — were also identified. A shared Mimikatz sample linked TwoFace and OilRig infrastructure, establishing tactical overlap between the two campaigns. Targeted sectors included think tanks, universities, strategic consulting firms, real estate companies, and telecommunications providers across the Middle East, with a heavy focus on Israeli interests.

    read more about Unraveling OilRig's Cyber Operations: Israel and Middle East in the Crosshairs
  12. Public

    Mia Ash: Anatomy of a cyber espionage persona, COBALT GYPSY lures middle eastern targets

    The article "The Curious Case of Mia Ash" by SecureWorks details a sophisticated cyber espionage campaign. This campaign involved a fake online persona named Mia Ash, created by the threat group COBALT GYPSY, which is associated with Iranian cyber operations. Mia Ash was used to establish relationships with employees in targeted organizations, primarily in the Middle East and North Africa. The persona, active across various social media platforms, was instrumental in delivering malware through seemingly innocent interactions. The case underlines the increasing complexity of cyber threats where social engineering and fake identities are employed to breach security systems.

    read more about Mia Ash: Anatomy of a cyber espionage persona, COBALT GYPSY lures middle eastern targets
  13. Public

    OilRig's Developmental Tactics: Evading Antivirus Through Rigorous Testing

    Palo Alto Unit42 documents the earliest known example of OilRig's systematic AV evasion testing process, conducted in June and November 2016 against their ClaySlide delivery documents — the same organized methodology Unit42 would later observe again in the 2018 BONDUPDATER campaign. In June 2016, OilRig created a base test file on June 13 and then ran 17 iterative modifications over a 2-hour window on June 15, starting at 4 AV detections and ending at 0. In November 2016, a second testing session generated 7 iterations in approximately 30 minutes on November 15 (following a base file on November 14), reducing detections from 5 to 2. Both sessions used the same pattern: upload to a public AV scanning service, measure the detection count, make one targeted change, re-upload, repeat. The June testing covered: payload removal (to isolate macro detection), removal and re-addition of the scheduled task creation block, command encoding experiments (base64, hexadecimal), intentional misspellings of key strings ("poawearshell", "scshtassks"), use of a FireEye blog URL as a base64 filler to test string-based detection, keyboard mashing, variable/function renaming, folder path changes, and reverting to the base document to restart the process. The November testing focused on decoy worksheet modifications (changing worksheet name, content, and sheet hash), function name obfuscation (Doom_Init → Doon_Init → Ini), variable name changes (BackupVbs → Backup_Vbs), string concatenation of the scheduled task creation command, and moving payload storage locations within the spreadsheet cells. The June campaign used C2 domain update-kernal[.]net; the November campaign used updateorg[.]com with the same Helminth payload. Unit42 assesses this testing behavior reflects a professionally organized operations model in which delivery documents are extended for as long as possible through iterative evasion refinement.

    read more about OilRig's Developmental Tactics: Evading Antivirus Through Rigorous Testing
  14. Public

    OilRig Campaign Resurfaces: Iranian Hackers Target Israel with Helminth Trojan

    Between April 19-24, 2017, several Israeli organizations, including high-tech development companies, medical entities, and educational institutions were targeted by a politically motivated campaign attributed to the Iranian hacker group responsible for the OilRig malware campaigns. The fileless attack was delivered through compromised email accounts at Ben-Gurion University using Microsoft Word documents exploiting the CVE-2017-0199 vulnerability. The Helminth Trojan was installed as a result, bearing a striking similarity to the OilRig campaign conducted against Middle Eastern financial institutions the previous year. The threat actors exploited the gap between patch release and rollout, with active C&C servers still operational at the time of report publication.

    read more about OilRig Campaign Resurfaces: Iranian Hackers Target Israel with Helminth Trojan
  15. Public

    COBALT GYPSY's Yet Another PupyRAT-driven Phishing Campaign

    SecureWorks researchers identified a phishing campaign targeting a Middle Eastern organization in January 2017, linked to COBALT GYPSY (Aka OilRig). The attackers employed spear-phishing emails containing shortened URLs redirecting to spoofed domains. Victims were presented with a malicious Microsoft Office document, which executed PowerShell commands when opened, installing PupyRAT, a multi-platform remote access trojan (RAT).

    read more about COBALT GYPSY's Yet Another PupyRAT-driven Phishing Campaign
  16. Public

    Stolen Code Signatures Fuel OilRig's Multi-Nation Cyber Attacks

    The Iranian threat agent OilRig, active since the end of 2015, has been implicated in a wave of cyber attacks targeting several countries, namely Israel, Turkey, Qatar, Kuwait, UAE, Saudi Arabia, and Lebanon. In their most recent campaigns, they have leveraged advanced strategies, setting up fake VPN portals, counterfeit websites, and using stolen code signing certificates to give their malware an appearance of authenticity. This not only illustrates their high technical capability, but also underscores the complexity and effectiveness of their operations. These attacks have largely targeted IT and financial institutions, causing significant concerns in these sectors.

    read more about Stolen Code Signatures Fuel OilRig's Multi-Nation Cyber Attacks
  17. Public

    OilRig Campaign: Malware Updates and Expanded Global Targets

    The OilRig cyberattack campaign, first analyzed in May 2016, continues to evolve, targeting government organizations and companies in Saudi Arabia, Qatar, Turkey, Israel, and the United States. Using spear-phishing emails with malicious Microsoft Excel documents, the attackers have updated their toolset, including Clayslide delivery documents and the Helminth backdoor. The malware communicates with remote servers via HTTP and DNS for command and control. Despite its lack of sophistication, the malware successfully operates under the radar in many establishments due to techniques like DNS command and control.

    read more about OilRig Campaign: Malware Updates and Expanded Global Targets
  18. Public

    OilRig Group Unleashes Coordinated Cyber Campaigns on Saudi Arabian Industries

    Palo Alto Unit42 introduces the OilRig campaign — naming both the threat group and the Helminth backdoor based on the Persian word "Nafti" (نفتی, meaning "oily") found hardcoded alongside philosopher names (Plato, Arasto, ALAfghani) in malware samples. The report documents two waves of targeted attacks on Saudi Arabian organizations across the financial, technology, defense, and telecommunications sectors: an August 2015 wave using fake job offers to deliver the Helminth executable variant, and a May 2016 wave using a service-provider social engineering theme to deliver the Helminth script variant via Clayslide Excel macro documents. The Clayslide delivery documents display a fake "Incompatible" worksheet instructing the user to enable macros, after which they show legitimate-looking decoy content (internal IP status tables) while installing Helminth's two-component script variant: update.vbs (HTTP C2 for batch script download and output upload) and dns.ps1 (DNS-based C2 using IP address octets as data transport, with 33.33.x.x as a start marker and 35.35.x.x as a stop marker). Both scripts create a fully functional remote shell. The executable variant, delivered via the HerHer dropper Trojan, adds a keylogger module (wintrust.hlm DLL) that monitors keystrokes and clipboard contents. Both variants beacon hardcoded per-sample "Group" (targeted organization name) and "Name" (philosopher/Persian word) values in C2 traffic, confirming deliberate pre-operational targeting. WHOIS registrant data for C2 domains included Iranian email addresses (chmail.ir provider, Tehran geolocation), consistent with Iranian-based operators. The scheduled task "GoogleUpdateTaskMachineUI" ran update.vbs every three minutes.

    read more about OilRig Group Unleashes Coordinated Cyber Campaigns on Saudi Arabian Industries
  19. Public

    APT34 Targets Middle Eastern Banks with Macro Malware

    APT34 launched targeted attacks against banks in the Middle East in May 2016. The threat actors sent malicious macro-enabled XLS files in emails to banking sector employees, which then created multiple directories and dropped PowerShell scripts to perform various malicious activities. The macros also unhidden content post-execution, creating a false sense of legitimacy. These files executed various scripts to download additional payloads, gather information, and exfiltrate data over DNS queries, demonstrating the continued effectiveness of macro malware.

    read more about APT34 Targets Middle Eastern Banks with Macro Malware