Unraveling OilRig's Cyber Operations: Israel and Middle East in the Crosshairs
- Actor Motivations: Espionage,Exfiltration
- Attack Vectors: Backdoor,RAT,Spear Phishing
- Attack Complexity: High
- Threat Risk: High Impact/Low Probability
Threat Overview
Palo Alto Networks Unit 42's September 2017 report documents OilRig's adversary infrastructure by tracing activity from a previously discovered TwoFace web shell. Researchers identified a network of 14 C2 IP addresses and 7 credential-harvesting domains — all designed to spoof the webmail portals of specific Israeli targets, including Tel Aviv University, Hebrew University of Jerusalem, Bezeq International, Macro Advisory Partners, Tidhar Group, and the Institute for National Security Studies. The harvesters were exact replicas of the legitimate login pages, indicating a targeted credential theft mission against Israel-connected organizations. Analysis of tools uploaded to compromised web servers revealed OilRig's post-exploitation toolkit: Mimikatz (credential dumping), PsExec (remote execution), PuTTY Link/Plink (SSH tunneling for lateral movement), and RGDoor (a custom IIS backdoor for persistent fallback access). Two additional web shells — RunningBee (password-protected) and LittleFace (command execution via HTTP POST) — were also identified. A shared Mimikatz sample linked TwoFace and OilRig infrastructure, establishing tactical overlap between the two campaigns. Targeted sectors included think tanks, universities, strategic consulting firms, real estate companies, and telecommunications providers across the Middle East, with a heavy focus on Israeli interests.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Case | Bezeq International Bezeq International Ltd. provides communication services. The Company offers Internet, international domestic and organizational telephony, IT, hosting, data communication, and information security solutions. Bezeq serves customers worldwide. Bezeq International has been targeted by OilRig with abusive purposes. | Verified |
| Case | Hebrew University of Jerusalem The Hebrew University of Jerusalem is a public research university based in Jerusalem, Israel. Co-founded by Albert Einstein and Chaim Weizmann in July 1918, the public university officially opened in April 1925. Hebrew University of Jerusalem has been targeted by OilRig with abusive purposes. | Verified |
| Case | Institute of National Security Studies (INSSS) The Institute for National Security Studies (INSS) is an independent Israeli research institute and think tank affiliated with Tel Aviv University dealing in areas of national security matters such as military and strategic affairs, terrorism and low intensity conflict, military balance in the Middle East, and cyber warfare. Institute of National Security Studies (INSSS) has been targeted by OilRig with abusive purposes. | Verified |
| Case | Macro Advisory Partners Macro Advisory Partners is a global advisory firm that provides strategic insights to leading investors, corporations, and governments. The firm specializes in macroeconomic and geopolitical analysis, and offers counsel on issues such as the global economy, disruptive geopolitics, US-China relations, and the energy transition. The firm was founded in 2013 by Nader Mousavizadeh and Richard Gnodde. Macro Advisory Partners has been targeted by OilRig with abusive purposes. | Verified |
| Case | Tel Aviv University Tel Aviv University is a public research university in Tel Aviv, Israel. With over 30,000 students, it is the largest university in the country. Tel Aviv University has been targeted by OilRig with abusive purposes. | Verified |
| Case | Tidhar Group Tidhar is a dynamic international real estate group that initiates, builds and markets residential, commercial and industrial projects in Israel. Tidhar Group has been targeted by OilRig with abusive purposes. | Verified |
| Sector | Consulting | Verified |
| Sector | Government Agencies and Services | Verified |
| Sector | Real Estate | Verified |
| Sector | Scientific Research | Verified |
| Sector | Telecommunication | Verified |
| Sector | University | Verified |
| Sector | Utilities | Verified |
| Region | Israel | Verified |
| Region | Saudi Arabia | Verified |
| Region | Middle East Countries | Verified |
Extracted IOCs
- logn-micrsftonine-con[.]ml
- mail-macroadvisorypartners[.]ml
- my-mailcoil[.]ml
- owa-insss-org-ill-owa-authen[.]ml
- so-cc-hujii-ac-il[.]ml
- webmaiil-tau-ac-il[.]ml
- webmail-tidhar-co-il[.]ml
- 28a0db561ff5a525bc2696cf98d96f443f528afe63c5097c5e0ccad071fcb8c2
- 3b08535b4add194f5661e1131c8e81af373ca322cf669674cf1272095e5cab95
- 450ebd66ba67bb46bf18d122823ff07ef4a7b11afe63b6f269aec9236a1790cd
- 497e6965120a7ca6644da9b8291c65901e78d302139d221fcf0a3ec6c5cf9de3
- 5b7eb534a852c187eee7eb729056082eec7a028819191fc2bc3ba4d1127fbd12
- 5ead94f12c307438e6475e49f02bedaee0cd09ce6cebb7939f9a2830f913212c
- 6ae32cd3b5a8a1dbb5464372ded370f31802fd1f5031795b43d662c64fc5b301
- 6e623311768f1c419b3f755248a3b3d4bf80d26606a74ed4cfd25547a67734c7
- 744e0ce108598aaa8994f211e00769ac8a3f05324d3f07f7705277b9af7a7497
- bb9b4e088eb99100156f56bbd35a21ff7e96981ffe78ca9132781e9b3f064f44
- caf5f9791ab3049811e16971b4673ec6d4baf35ffaadd7486ea4c5e318d10696
- d3b03c0da854102802c21c0fa8736910ea039bbe93a140c09689fc802435ea31
- 137[.]74.131.208
- 138[.]201.209.162
- 138[.]201.209.182
- 176[.]9.164.252
- 212[.]16.80.102
- 37[.]59.229.231
- 51[.]254.50.153
- 5[.]39.59.97
- 89[.]163.206.0
- 91[.]121.237.224
- 91[.]121.237.227
- 92[.]222.209.48
- 92[.]222.209.51
- 94[.]23.172.49
Tip: 33 related IOCs (14 IP, 7 domain, 0 URL, 0 email, 12 file hash) to this threat have been found.
Overlaps
Source: Symantec - May 2020
Detection (one case): 450ebd66ba67bb46bf18d122823ff07ef4a7b11afe63b6f269aec9236a1790cd
Source: Palo Alto Networks - January 2018
Detection (one case): 497e6965120a7ca6644da9b8291c65901e78d302139d221fcf0a3ec6c5cf9de3
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
Frequently Asked Questions About OilRig's Infrastructure Campaign Against Israeli and Middle East Targets
OilRig, an Iranian state-sponsored threat group, built a targeted attack infrastructure aimed at stealing credentials from specific Israeli organizations and maintaining persistent access to compromised web servers across the Middle East. The group deployed credential-harvesting websites that were exact copies of target login portals, alongside multiple web shells and post-exploitation tools on servers they had compromised. Palo Alto Networks Unit 42 uncovered the operation in September 2017 while investigating the TwoFace web shell they had previously documented.
The campaign is attributed to OilRig, an Iranian state-sponsored cyber-espionage group also linked to APT34 and Helix Kitten. Unit 42 established the connection through a shared Mimikatz sample found on both TwoFace-infected infrastructure and OilRig tooling, as well as significant targeting overlap between the two campaigns in the Middle East. OilRig is assessed to operate in support of Iranian government interests.
The primary objectives were credential theft and persistent network access. The credential harvesters were designed to collect login credentials from employees at specific Israeli institutions. Once access was gained via stolen credentials or web shell deployment, OilRig established multiple redundant backdoors for long-term presence, then used post-exploitation tools to move laterally and dump additional credentials — consistent with a strategic intelligence collection mission focused on Israel and the broader Middle East region.
The campaign targeted specific organizations in Israel and the broader Middle East. The credential harvesters directly named six Israeli targets: Tel Aviv University, Hebrew University of Jerusalem, Bezeq International (telecom), Macro Advisory Partners (strategic consulting), Tidhar Group (real estate), and the Institute for National Security Studies (think tank). Additional compromised web servers were located at educational and government institutions across Saudi Arabia and other Middle Eastern countries, which were used as infrastructure hop points.
The campaign focused on think tanks, academic institutions, strategic consulting firms, telecommunications providers, real estate companies, and the oil and gas sector — all organizations with strong connections to Israeli national security, regional economic intelligence, or Iran's geopolitical interests. The specificity of the credential harvesters (each one tailored to a named organization) confirms this was a deliberate, targeted operation rather than opportunistic credential theft.
The attack unfolded in two parallel tracks. In the first, OilRig registered .ml domains that mimicked the webmail portals of target organizations and stood up pixel-perfect replicas of their login pages — likely sending phishing emails to direct victims to these fake portals and capture their credentials. In the second track, OilRig deployed TwoFace, RunningBee, and LittleFace web shells on compromised web servers across the Middle East, using those servers as both C2 hop points and staging platforms. Post-exploitation tools including Mimikatz (credential dumping), PsExec (remote execution), Plink (SSH tunneling), and RGDoor (IIS backdoor) were then uploaded to maintain deep access and move laterally within victim networks.
Israel is a primary geopolitical rival of Iran, and Israeli universities, think tanks, and national security institutions produce and hold sensitive strategic intelligence. The Institute for National Security Studies directly informs Israeli defense policy. Macro Advisory Partners advises on Israel-region geopolitics. Bezeq International's telecom infrastructure provides potential access to communications data. OilRig's Middle Eastern focus also reflects Iran's broader interest in monitoring regional governments, oil sector activity, and organizations with connections to Iran's adversaries.
Enable multi-factor authentication on all webmail and OWA portals to reduce the impact of credential harvesting — even if users enter credentials on a fake site, MFA prevents immediate account compromise. Audit internet-facing IIS web servers for unauthorized ISAPI modules and .aspx web shells, particularly in authentication directories. Monitor DNS and passive DNS for newly registered domains using typosquatting or subdomain patterns that mimic your organization's mail hostnames. Alert on Mimikatz behavioral indicators (LSASS access, comsvcs.dll MiniDump) and on unusual use of PsExec, Plink, or other remote tools initiated from web server processes. Block the 14 C2 IPs and 7 credential harvesting domains documented in this report.