Threats Feed|APT34|Last Updated 28/04/2026|AuthorCertfa Radar|Publish Date11/05/2022

Unveiling APT34’s Advanced Attack Tactics: From Excel Macros to DNS Tunneling

  • Actor Motivations: Espionage,Exfiltration
  • Attack Vectors: Backdoor,Spear Phishing
  • Attack Complexity: High
  • Threat Risk: High Impact/Low Probability

Threat Overview

FortiGuard Labs provides the most detailed technical analysis of the Saitama campaign against a Jordanian diplomat, identifying unique techniques across both the Excel macro and the dropped backdoor. The spearphishing email posed as a colleague from the target's own IT department, using the real employee's first and last name — an insider-impersonation lure rather than a generic government spoofing attempt. The Excel macro uses a sheet visibility toggle as an anti-emulation technique (targeting tools like ViperMonkey that may not support all Excel features), and beacons nine distinct execution states to the C2 via WMI Win32_PingStatus queries with unique subdomain prefixes per step, allowing the attacker to monitor macro progress in real time through their DNS logs. Three payload files are decoded from base64 UserForm label captions: update.exe (malware), update.exe.config (configuration), and a signed Microsoft.Exchange.WebServices.dll (clean, for legitimacy). The scheduled task "MicrosoftUpdate" runs every 4 hours using deprecated IdleSettings (10-minute idle requirement) for up to 20 days. The Saitama backdoor uses a Mersenne Twister PRNG seeded with an agent ID to generate DGA subdomains across three lookalike C2 domains; it validates DNS A-record responses by requiring the first octet to be ≥ 128 before treating the response as valid C2 data. Exfiltration uses Base32 encoding (consistent with APT34's DNSpionage tool) compressed before encoding. A mutex (726a06ad-475b-4bc6-8466-f08960595f1e) prevents concurrent execution. The C2 IP 193.239.84.207 has historical associations with NSO Group Pegasus, APT34, and GoziIFSB infrastructure. Fortinet assesses the 6–8 hour sleep is deliberately timed for a diplomat's work schedule, and the hardcoded internal network commands suggest prior limited access to the target network before this spearphishing attempt was made.

Detected Targets

TypeDescriptionConfidence
SectorGovernment Agencies and Services
Verified
RegionJordan
Verified

Extracted IOCs

  • asiaworldremit[.]com
  • astrazencea[.]com
  • astrazeneeca[.]com
  • cisco0[.]com
  • coinbasedeutschland[.]com
  • hsbcbkcn[.]com
  • joexpediagroup[.]com
  • ntu-sg-edu[.]com
  • theworldbank[.]uk
  • uber-asia[.]com
  • valtronics-ae[.]com
  • 7ebbeb2a25da1b09a98e1a373c78486ed2c5a7f2a16eec63e576c99efe0c7a49
  • 82a0f2b93c5bccf3ef920bae425dd768371248cda9948d5a8e70f3c34e9f7cca
  • c744da99fe19917e09cd1ecc48b563f9525dad3916e1902f61b79bda35298d87
  • e0872958b8d3824089e5e1cfab03d9d98d22b9bcb294463818d721380075a52d
  • 192[.]5.4.3
  • 193[.]239.84.207
  • 45[.]11.19.47
download

Tip: 18 related IOCs (3 IP, 11 domain, 0 URL, 0 email, 4 file hash) to this threat have been found.

Overlaps

Earth SimnavazEarth Simnavaz Targets UAE and Persian Gulf Energy Sector with Advanced Cyber Espionage

Source: Trend Micro - October 2024

Detection (one case): 7ebbeb2a25da1b09a98e1a373c78486ed2c5a7f2a16eec63e576c99efe0c7a49

APT34APT34’s Saitama Agent: Phishing and DNS Tunneling in Jordan

Source: XJunior - June 2022

Detection (five cases): 7ebbeb2a25da1b09a98e1a373c78486ed2c5a7f2a16eec63e576c99efe0c7a49, e0872958b8d3824089e5e1cfab03d9d98d22b9bcb294463818d721380075a52d, asiaworldremit[.]com, joexpediagroup[.]com, uber-asia[.]com

APT34Understanding Saitama: The Latest Weapon in APT34's Cyber Arsenal

Source: SANS - June 2022

Detection (four cases): e0872958b8d3824089e5e1cfab03d9d98d22b9bcb294463818d721380075a52d, asiaworldremit[.]com, joexpediagroup[.]com, uber-asia[.]com

APT34APT34 Uses Saitama Backdoor to Attack Jordanian Government through DNS Tunnelling

Source: Malwarebytes - May 2022

Detection (four cases): e0872958b8d3824089e5e1cfab03d9d98d22b9bcb294463818d721380075a52d, asiaworldremit[.]com, joexpediagroup[.]com, uber-asia[.]com

APT34APT34 Targets Jordan's Government with Saitama Backdoor: A New Wave of Cyber Espionage

Source: Malwarebytes - May 2022

Detection (four cases): e0872958b8d3824089e5e1cfab03d9d98d22b9bcb294463818d721380075a52d, asiaworldremit[.]com, joexpediagroup[.]com, uber-asia[.]com

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

Frequently Asked Questions: APT34's Saitama Campaign — Fortinet Technical Analysis

FortiGuard Labs discovered a sophisticated spearphishing campaign targeting a Jordanian diplomat. The attacker impersonated a real IT department colleague from the same organization — using the employee's actual name — and attached a malicious Excel file containing a confirmation form. The file installed the Saitama backdoor, which communicated exclusively over DNS and used several techniques not seen in typical malware: anti-analysis tricks, real-time state monitoring of the attack via DNS, and a list of commands pre-loaded with internal Jordanian government network addresses. Fortinet attributes the campaign to APT34 based on TTPs, targeting history, and shared infrastructure.

The attack is attributed to APT34, also known as OilRig or Helix Kitten — an Iranian state-aligned cyberespionage group active since at least 2014. Fortinet's attribution rests on the DNS tunneling C2 approach consistent with prior APT34 tools, the Base32 exfiltration encoding matching APT34's DNSpionage malware, the hardcoded internal network knowledge consistent with prior APT34 Jordan operations, and the C2 infrastructure sharing historical connections with documented APT34 activity.

The goal was espionage — specifically collecting sensitive information from a compromised Jordanian government machine. The Saitama backdoor's 22 hardcoded commands, many of which target internal government IP ranges and domain names, show this was not casual reconnaissance but a targeted operation against a specific known network. Fortinet also notes that the 6–8 hour sleep period appears deliberately timed for a diplomat's workday — suggesting the attackers planned to operate overnight after the victim left the office.

The attack was precision-targeted at a single Jordanian diplomat. Fortinet's telemetry confirmed active connections from Jordan to the C2 IP 45.11.19.47 associated with joexpediagroup[.]com. The hardcoded internal network commands in the backdoor indicate the attacker had prior knowledge of the target's internal infrastructure — likely from a limited earlier access point — before launching this spearphishing attempt. The attacker also carefully managed their C2 servers, taking two of the three domains offline shortly after the initial compromise window, suggesting tight operational control.

The confirmed target was a diplomat in Jordan's government — based on Fortinet's characterization and the sender's impersonation of an IT department colleague in the same governmental organization. APT34 has a documented history of targeting Jordanian government entities. The attack is part of a broader pattern of APT34 espionage operations against Middle Eastern government, financial, energy, and telecommunications sectors.

The attack began with a carefully crafted spearphishing email using a real IT employee's name. Opening the Excel attachment and enabling the macro triggered a sequence the attacker could monitor in real time through DNS — the macro beaconed each of nine execution steps using unique subdomain prefixes over WMI queries. The macro verified a mouse was connected before proceeding, decoded three files from base64 captions embedded in hidden form objects, and set up a scheduled task running every 4 hours for 20 days. The installed Saitama backdoor then connected to attacker-controlled servers via DNS, sleeping up to 6–8 hours between contact attempts and cycling through a state machine to receive commands encoded in DNS response IP octets. Results were compressed, Base32-encoded, and exfiltrated back via DNS subdomain strings.

Jordanian government officials represent high-value intelligence targets for Iran. Jordan's diplomatic relationships with Israel, the US, Saudi Arabia, and other Western partners make its foreign policy communications strategically important to Iranian intelligence. The insider-impersonation lure (using a real IT colleague's identity) suggests the attacker had already gathered organizational information before launching the attack — raising the likelihood that this was part of a sustained, multi-stage campaign rather than an isolated opportunistic attempt.

Block the three C2 domains and flag IPs 45.11.19.47 and 193.239.84.207 — the latter has shared infrastructure history with APT34 and NSO Group Pegasus. Hunt for the mutex value 726a06ad-475b-4bc6-8466-f08960595f1e to identify active Saitama infections on endpoints. Alert on WMI Win32_PingStatus queries initiated from Office application processes — an unusual and specific indicator of the macro's C2 beaconing. Monitor for scheduled tasks named "MicrosoftUpdate" with 4-hour intervals and files written to %LocalAppData%\MicrosoftUpdate by Office processes. Because the mouse-check anti-sandbox technique may defeat automated analysis, live EDR behavioral monitoring is more reliable than static sandboxing for detecting this campaign.

About Affiliation
APT34
APT34 is Mandiant's designation for the Iranian MOIS-linked threat cluster known as OilRig. Active since at least 2014, Mandiant identified APT34 as an advanced persistent threat focused on long-term espionage against government, energy, and financial organizations in the Middle East. Mandiant has documented the group's evolution over more than a decade, including its use of DNS-based command and control, LinkedIn-based social engineering lures, and a continuously expanding custom malware arsenal. APT34 remains one of the most thoroughly documented Iranian state-sponsored actors in public threat intelligence.
View APT34's Insights