Cyber-Espionage in the Middle East: A Deep Dive into APT34's Operations
- Actor Motivations: Espionage,Exfiltration
- Attack Vectors: Vulnerability Exploitation,Backdoor,RAT,Spear Phishing
- Attack Complexity: High
- Threat Risk: High Impact/Low Probability
Threat Overview
Cyware's August 2019 overview profiles APT34 (also known as Helix Kitten, OilRig, and Greenbug), an Iranian state-sponsored threat group active since 2014. The group targets organizations across the Middle East and beyond, focusing on finance, government, energy, telecommunications, IT, military, healthcare, and education sectors. APT34 is assessed to collect intelligence that serves Iran's economic and geopolitical interests. Over a five-year period, its campaigns evolved from spearphishing Middle Eastern banks with weaponized Excel attachments to broader global operations. Notable campaigns include exploitation of CVE-2017-0199 (OLE remote code execution) against Israeli institutions in April 2017, and CVE-2017-11882 (Office memory corruption) in October 2017 UAE government targeting. The group deployed a large custom malware arsenal including Helminth, OopsIE, POWRUNER, BONDUPDATER, Karkoff, ISMAgent, Poison Frog, Neptun, and web shells (TwoFace, RGDoor, HyperShell, HighShell, RunningBee, PhpSpy). In April 2019, the threat actor "Lab Dookhtegan" publicly leaked APT34 tools and victim lists. In June 2019, Russian group Turla was discovered hijacking APT34 infrastructure to deliver its own Neptun backdoor. A total of 101 C2 IPs, 63 domains, 117 shell URLs, and 9 file hashes are documented as indicators of compromise from this report.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Case | Juniper Networks Juniper Networks, Inc. is an American multinational corporation headquartered in Sunnyvale, California. The company develops and markets networking products, including routers, switches, network management software, network security products, and software-defined networking technology. Juniper Networks has been targeted by APT34 with abusive purposes. | Verified |
| Case | Lebanon General Directorate of General Security The General Security Directorate is a Lebanese intelligence agency founded on July 21, 1921 and originally known as the "first bureau". Lebanon General Directorate of General Security has been targeted by APT34 as the main target. | Verified |
| Case | University of Oxford The University of Oxford is a collegiate research university in Oxford, England. There is evidence of teaching as early as 1096, making it the oldest university in the English-speaking world and the world's second-oldest university in continuous operation. University of Oxford has been targeted by APT34 with abusive purposes. | Verified |
| Sector | Defense | Verified |
| Sector | Financial | Verified |
| Sector | Government Agencies and Services | Verified |
| Sector | Information Technology | Verified |
| Sector | Medical | Verified |
| Sector | Military | Verified |
| Sector | Telecommunication | Verified |
| Sector | Transportation | Verified |
| Sector | University | Verified |
| Sector | Utilities | Verified |
| Region | Albania | Verified |
| Region | Israel | Verified |
| Region | Lebanon | Verified |
| Region | Saudi Arabia | Verified |
| Region | South Korea | Verified |
| Region | United Arab Emirates | Verified |
| Region | United States | Verified |
| Region | Zimbabwe | Verified |
| Region | Middle East Countries | Verified |
| Region | European Countries | Verified |
Exploited Vulnerabilities
Extracted IOCs
- dnrd[.]ae
- e-albania[.]al
- government[.]ae
- jaf.mil[.]jo
- oxford-careers[.]com
- oxford-employee[.]com
- oxford[.]in
- webmail.gov[.]jo
- bulksms.umniah[.]com
- email.omnix-group[.]com
- email.ssc.gov[.]jo
- email.umniah[.]com
- evserver.umniah[.]com
- formerst.gulfair[.]com
- fwx1.petra.gov[.]jo
- fwx1.petranews.gov[.]jo
- gis.moei.gov[.]ae
- gis.moenr.gov[.]ae
- ictinfo.moict.gov[.]jo
- ksa.olayan[.]net
- mail.alfuttaim[.]ae
- mail.alraidah.com[.]sa
- mailarchive.emiratesid[.]ae
- mail.cma.org[.]sa
- mail.dallah-hospital[.]com
- mailkw.agility[.]com
- mail.mindware[.]ae
- mail.mis.com[.]sa
- mail.mofa.gov[.]iq
- mail.mygov[.]ae
- mail.omantourism.gov[.]om
- mail.orange-jtg[.]jo
- mail.primus.com[.]jo
- mail.soc.mil[.]ae
- mail.sts.com[.]jo
- mail.tameen[.]ae
- mail.zayed.org[.]ae
- meet.saudiairlines[.]com
- m.murasalaty.moenr.gov[.]ae
- owa.e-albania[.]al
- staging.forus[.]jo
- webmail.alsalam[.]aero
- webmail.bix[.]bh
- webmail.citc.gov[.]sa
- webmail.dha.gov[.]ae
- webmail.dnrd[.]ae
- webmail.dsc.gov[.]ae
- webmail.eminsco[.]com
- webmail.emiratesid[.]ae
- webmail.ictfund.gov[.]ae
- webmail.moe.gov[.]sa
- webmail.presflt[.]ae
- webmail.qchem[.]com
- webmail.tra.gov[.]ae
- www.abudhabiairport[.]ae
- www.ajfd.gov[.]ae
- www.alraidah.com[.]sa
- www.dns[.]jo
- www.marubi.gov[.]al
- www.mpwh.gov[.]jo
- www.sts.com[.]jo
- www.tra.gov[.]ae
- 07e791d18ea8f2f7ede2962522626b43f28cb242873a7bd55fff4feb91299741
- 27e03b98ae0f6f2650f378e9292384f1350f95ee4f3ac009e0113a8d9e2e14ed
- 2943e69e6c34232dee3236ced38d41d378784a317eeaf6b90482014210fcd459
- 3ca3a957c526eaeabcf17b0b2cd345c0fffab549adfdf04470b6983b87f7ec62
- a6a0fbfee08367046d3d26fb4b4cf7779f7fb6eaf7e60e1d9b6bf31c5be5b63e
- b1d621091740e62c84fc8c62bcdad07873c8b61b83faba36097ef150fd6ec768
- c9d5dc956841e000bfd8762e2f0b48b66c79b79500e894b4efa7fb9ba17e4e9e
- dd6d7af00ef4ca89a319a230cdd094275c3a1d365807fe5b34133324bdaa0229
- fe1b011fe089969d960d2dce2a61020725a02e15dbc812ee6b6ecc6a98875392
- 103[.]102.44.181
- 103[.]102.45.14
- 109[.]236.85.129
- 110[.]74.202.90
- 114[.]198.235.22
- 114[.]198.237.3
- 114[.]255.190.1
- 1[.]202.179.13
- 1[.]202.179.14
- 122[.]146.71.136
- 132[.]68.32.165
- 142[.]234.200.99
- 146[.]112.61.108
- 158[.]69.57.62
- 168[.]187.92.92
- 168[.]63.221.220
- 172[.]241.140.238
- 172[.]81.134.226
- 173[.]234.153.194
- 173[.]234.153.201
- 176[.]9.164.215
- 178[.]32.127.230
- 180[.]166.27.217
- 180[.]169.13.230
- 185[.]10.115.199
- 185[.]140.249.157
- 185[.]140.249.63
- 185[.]15.247.140
- 185[.]161.209.157
- 185[.]161.211.86
- 185[.]174.100.56
- 185[.]174.102.14
- 185[.]181.8.158
- 185[.]181.8.252
- 185[.]191.228.103
- 185[.]20.187.8
- 185[.]227.108.35
- 185[.]236.76.35
- 185[.]236.76.59
- 185[.]236.76.80
- 185[.]236.77.17
- 185[.]236.77.75
- 185[.]236.78.217
- 185[.]236.78.63
- 185[.]56.91.61
- 187[.]174.201.179
- 190[.]2.142.59
- 194[.]9.177.15
- 194[.]9.178.10
- 194[.]9.179.23
- 195[.]12.113.50
- 195[.]88.204.17
- 197[.]253.14.10
- 198[.]143.182.22
- 200[.]33.162.13
- 202[.]104.127.218
- 202[.]134.62.169
- 202[.]164.27.206
- 202[.]175.114.11
- 202[.]175.31.141
- 202[.]183.235.31
- 202[.]183.235.4
- 202[.]70.34.68
- 205[.]177.180.161
- 209[.]88.89.35
- 210[.]22.172.26
- 211[.]238.138.68
- 213[.]131.83.73
- 213[.]14.218.51
- 213[.]189.82.221
- 213[.]202.217.9
- 213[.]227.140.32
- 217[.]182.217.122
- 221[.]5.148.230
- 222[.]178.70.8
- 222[.]66.8.76
- 23[.]106.215.76
- 23[.]19.226.69
- 23[.]227.201.6
- 38[.]132.124.153
- 41[.]203.90.221
- 46[.]105.251.42
- 46[.]165.246.196
- 46[.]235.95.125
- 46[.]4.69.52
- 51[.]211.184.170
- 58[.]210.216.113
- 59[.]124.43.229
- 60[.]247.31.237
- 70[.]36.107.34
- 77[.]42.251.125
- 78[.]100.87.199
- 81[.]17.56.249
- 82[.]178.124.59
- 83[.]244.91.132
- 88[.]255.182.69
- 88[.]99.246.174
- 91[.]195.89.155
- 95[.]0.139.4
- 95[.]168.176.172
- 95[.]168.176.173
- 213[.]189.82.221/owa/auth/errorff[.]aspx
- hxxp://bulksms.umniah[.]com/gmgweb/msgtypesvalid.aspx
- hxxp://dnrd[.]ae:8080/_layouts/wrkstatlog.aspx
- hxxp://fwx1.petra.gov[.]jo/sedcowebserver/global.aspx
- hxxp://fwx1.petranews.gov[.]jo/sedcowebserver/content/rtl/qualitycontrol.aspx
- hxxp://ictinfo.moict.gov[.]jo/di7web/libraries/aspx/regstructures.aspx
- hxxps://110[.]74.202.90/owa/auth/errorff[.]aspx
- hxxps://114[.]198.235.22/owa/auth/login[.]aspx
- hxxps://114[.]198.237.3/owa/auth/login[.]aspx
- hxxps://114[.]255.190.1/owa/auth/error1[.]aspx
- hxxps://1[.]202.179.13/owa/auth/error1[.]aspx
- hxxps://1[.]202.179.14/owa/auth/error1[.]aspx
- hxxps://122[.]146.71.136/owa/auth/error3[.]aspx
- hxxps://132[.]68.32.165/owa/auth/logout[.]aspx
- hxxps://132[.]68.32.165/owa/auth/signout[.]aspx
- hxxps://168[.]63.221.220/owa/auth/error3[.]aspx
- hxxps://180[.]166.27.217/owa/auth/error3[.]aspx
- hxxps://180[.]169.13.230/owa/auth/error1[.]aspx
- hxxps://185[.]10.115.199/owa/auth/logout[.]aspx
- hxxps://187[.]174.201.179/owa/auth/error1[.]aspx
- hxxps://195[.]12.113.50/owa/auth/error3[.]aspx
- hxxps://195[.]88.204.17/owa/auth/logout[.]aspx
- hxxps://197[.]253.14.10/owa/auth/logout[.]aspx
- hxxps://200[.]33.162.13/owa/auth/error3[.]aspx
- hxxps://202[.]104.127.218/owa/auth/error1[.]aspx
- hxxps://202[.]104.127.218/owa/auth/exppw[.]aspx
- hxxps://202[.]134.62.169/owa/auth/signin[.]aspx
- hxxps://202[.]164.27.206/owa/auth/signout[.]aspx
- hxxps://202[.]175.114.11/owa/auth/error1[.]aspx
- hxxps://202[.]175.31.141/owa/auth/error3[.]aspx
- hxxps://202[.]183.235.31/owa/auth/signout[.]aspx
- hxxps://202[.]183.235.4/owa/auth/signout[.]aspx
- hxxps://202[.]70.34.68/owa/auth/error0[.]aspx
- hxxps://202[.]70.34.68/owa/auth/error1[.]aspx
- hxxps://205[.]177.180.161/owa/auth/erroref[.]aspx
- hxxps://209[.]88.89.35/owa/auth/logout[.]aspx
- hxxps://210[.]22.172.26/owa/auth/error1[.]aspx
- hxxps://211[.]238.138.68/owa/auth/error1[.]aspx
- hxxps://213[.]131.83.73/owa/auth/error4[.]aspx
- hxxps://213[.]14.218.51/owa/auth/logon[.]aspx
- hxxps://221[.]5.148.230/owa/auth/outlook[.]aspx
- hxxps://222[.]178.70.8/owa/auth/outlook[.]aspx
- hxxps://222[.]66.8.76/owa/auth/error1[.]aspx
- hxxps://41[.]203.90.221/owa/auth/logout[.]aspx
- hxxps://46[.]235.95.125/owa/auth/signin[.]aspx
- hxxps://51[.]211.184.170/owa/auth/owaauth[.]aspx
- hxxps://58[.]210.216.113/owa/auth/error1[.]aspx
- hxxps://59[.]124.43.229/owa/auth/error0[.]aspx
- hxxps://60[.]247.31.237/owa/auth/error3[.]aspx
- hxxps://60[.]247.31.237/owa/auth/logoff[.]aspx
- hxxps://77[.]42.251.125/owa/auth/logout[.]aspx
- hxxps://78[.]100.87.199/owa/auth/logon[.]aspx
- hxxps://82[.]178.124.59/owa/auth/gettokenid[.]aspx
- hxxps://83[.]244.91.132/owa/auth/logon[.]aspx
- hxxps://88[.]255.182.69/owa/auth/getidtoken[.]aspx
- hxxps://91[.]195.89.155/owa/auth/signin[.]aspx
- hxxps://95[.]0.139.4/owa/auth/logon[.]aspx
- hxxps://e-albania[.]al/dptaktkonstatim.aspx
- hxxps://email.omnix-group[.]com/owa/auth/signon.aspx
- hxxps://email.ssc.gov[.]jo/owa/auth/signin.aspx
- hxxps://email.umniah[.]com/owa/auth/redirsuite.aspx
- hxxps://evserver.umniah[.]com/index.aspx
- hxxps://formerst.gulfair[.]com/gfstmssspr/webform.aspx
- hxxps://gis.moei.gov[.]ae/petrol.aspx
- hxxps://gis.moenr.gov[.]ae/petrol.aspx
- hxxps://government[.]ae/tax.aspx
- hxxps://jaf.mil[.]jo/showcontents.aspx
- hxxps://ksa.olayan[.]net/owa/auth/signin.aspx
- hxxps://mail.alfuttaim[.]ae/owa/auth/change_password.aspx
- hxxps://mail.alraidah.com[.]sa/owa/auth/getlogintoken.aspx
- hxxps://mailarchive.emiratesid[.]ae/enterprisevault/js/jquery.aspx
- hxxps://mail.cma.org[.]sa/owa/auth/signin.aspx
- hxxps://mail.dallah-hospital[.]com/owa/auth/getidtokens.aspx
- hxxps://mailkw.agility[.]com/owa/auth/redirsuiteservice.aspx
- hxxps://mail.mindware[.]ae/owa/auth/outlooktoken.aspx
- hxxps://mail.mis.com[.]sa/owa/auth/redirect.aspx
- hxxps://mail.mofa.gov[.]iq/owa/auth/redirsuiteservice.aspx
- hxxps://mail.mygov[.]ae/owa/auth/owalogin.aspx
- hxxps://mail.omantourism.gov[.]om/owa/auth/gettokenid.aspx
- hxxps://mail.orange-jtg[.]jo/owa/auth/signin.aspx
- hxxps://mail.primus.com[.]jo/owa/auth/getidtoken.aspx
- hxxps://mail.soc.mil[.]ae/owa/auth/expirepw.aspx
- hxxps://mail.sts.com[.]jo/owa/auth/signout.aspx
- hxxps://mail.tameen[.]ae/owa/auth/outlooklogon.aspx
- hxxps://mail.zayed.org[.]ae/owa/auth/espw.aspx
- hxxps://meet.saudiairlines[.]com/clientresourcehandler.aspx
- hxxps://m.murasalaty.moenr.gov[.]ae/signproces.aspx
- hxxps://owa.e-albania[.]al/owa/auth/outlookdn.aspx
- hxxp://staging.forus[.]jo/_layouts/explainedit.aspx
- hxxps://webmail.alsalam[.]aero/owa/auth/eventclass.aspx
- hxxps://webmail.bix[.]bh/ecp/auth/eventclass.aspx
- hxxps://webmail.bix[.]bh/owa/auth/eventclass.aspx
- hxxps://webmail.bix[.]bh/owa/auth/timeoutctl.aspx
- hxxps://webmail.citc.gov[.]sa/owa/auth/timeout.aspx
- hxxps://webmail.dha.gov[.]ae/owa/auth/outlookservice.aspx
- hxxps://webmail.dnrd[.]ae/owa/auth/getidtoken.aspx
- hxxps://webmail.dsc.gov[.]ae/owa/auth/outlooklogonservice.aspx
- hxxps://webmail.eminsco[.]com/owa/auth/outlookcname.aspx
- hxxps://webmail.eminsco[.]com/owa/auth/outlookfilles.aspx
- hxxps://webmail.emiratesid[.]ae/owa/auth/handlerservice.aspx
- hxxps://webmail.emiratesid[.]ae/owa/auth/redirsuiteservice.aspx
- hxxps://webmail.gov[.]jo/owa/auth/getidtokens.aspx
- hxxps://webmail.ictfund.gov[.]ae/owa/auth/owaauth.aspx
- hxxps://webmail.moe.gov[.]sa/owa/auth/redirectcache.aspx
- hxxps://webmail.moe.gov[.]sa/owa/auth/redireservice.aspx
- hxxps://webmail.presflt[.]ae/owa/auth/logontimeout.aspx
- hxxps://webmail.qchem[.]com/owa/auth/redirectcache.aspx
- hxxps://webmail.tra.gov[.]ae/owa/auth/outlookdn.aspx
- hxxps://www.dns[.]jo/statistic.aspx
- hxxps://www.tra.gov[.]ae/signin.aspx
- hxxp://www.abudhabiairport[.]ae/english/resources.aspx
- hxxp://www.ajfd.gov[.]ae/_layouts/workpage.aspx
- hxxp://www.alraidah.com[.]sa/_layouts/wrksetlan.aspx
- hxxp://www.marubi.gov[.]al/aspx/viewpercthesaurus.aspx
- hxxp://www.mpwh.gov[.]jo/_layouts/createadaccounts.aspx
- hxxp://www.sts.com[.]jo/_layouts/15/moveresults.aspx
Tip: 290 related IOCs (101 IP, 63 domain, 117 URL, 0 email, 9 file hash) to this threat have been found.
Overlaps
Source: Palo Alto Networks - January 2020
Detection (three cases): 185[.]15.247.140, 185[.]161.211.86, 213[.]202.217.9
Source: NSFOCUS - November 2019
Detection (nine cases): 07e791d18ea8f2f7ede2962522626b43f28cb242873a7bd55fff4feb91299741, 27e03b98ae0f6f2650f378e9292384f1350f95ee4f3ac009e0113a8d9e2e14ed, 2943e69e6c34232dee3236ced38d41d378784a317eeaf6b90482014210fcd459, 3ca3a957c526eaeabcf17b0b2cd345c0fffab549adfdf04470b6983b87f7ec62, a6a0fbfee08367046d3d26fb4b4cf7779f7fb6eaf7e60e1d9b6bf31c5be5b63e, b1d621091740e62c84fc8c62bcdad07873c8b61b83faba36097ef150fd6ec768, c9d5dc956841e000bfd8762e2f0b48b66c79b79500e894b4efa7fb9ba17e4e9e, dd6d7af00ef4ca89a319a230cdd094275c3a1d365807fe5b34133324bdaa0229, fe1b011fe089969d960d2dce2a61020725a02e15dbc812ee6b6ecc6a98875392
Source: Palo Alto Network - September 2019
Detection (two cases): 185[.]15.247.140, 213[.]202.217.9
Source: Palo Alto Network - April 2019
Detection (six cases): 27e03b98ae0f6f2650f378e9292384f1350f95ee4f3ac009e0113a8d9e2e14ed, 3ca3a957c526eaeabcf17b0b2cd345c0fffab549adfdf04470b6983b87f7ec62, a6a0fbfee08367046d3d26fb4b4cf7779f7fb6eaf7e60e1d9b6bf31c5be5b63e, c9d5dc956841e000bfd8762e2f0b48b66c79b79500e894b4efa7fb9ba17e4e9e, dd6d7af00ef4ca89a319a230cdd094275c3a1d365807fe5b34133324bdaa0229, fe1b011fe089969d960d2dce2a61020725a02e15dbc812ee6b6ecc6a98875392
Source: APT34 / OILRIG Leak, Quick Analysis - April 2019
Detection (nine cases): 07e791d18ea8f2f7ede2962522626b43f28cb242873a7bd55fff4feb91299741, 27e03b98ae0f6f2650f378e9292384f1350f95ee4f3ac009e0113a8d9e2e14ed, 2943e69e6c34232dee3236ced38d41d378784a317eeaf6b90482014210fcd459, 3ca3a957c526eaeabcf17b0b2cd345c0fffab549adfdf04470b6983b87f7ec62, a6a0fbfee08367046d3d26fb4b4cf7779f7fb6eaf7e60e1d9b6bf31c5be5b63e, b1d621091740e62c84fc8c62bcdad07873c8b61b83faba36097ef150fd6ec768, c9d5dc956841e000bfd8762e2f0b48b66c79b79500e894b4efa7fb9ba17e4e9e, dd6d7af00ef4ca89a319a230cdd094275c3a1d365807fe5b34133324bdaa0229, fe1b011fe089969d960d2dce2a61020725a02e15dbc812ee6b6ecc6a98875392
Source: CrowdStrike - January 2019
Detection (two cases): 185[.]15.247.140, 185[.]20.187.8
Source: Openminded - January 2019
Detection (one case): 185[.]236.78.63
Source: Cisco Talos - November 2018
Detection (one case): 185[.]20.187.8
Source: ClearSky - January 2017
Detection (three cases): oxford-careers[.]com, oxford-employee[.]com, oxford[.]in
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
Frequently Asked Questions About APT34's Middle East Cyber Espionage Operations
APT34, an Iranian state-sponsored hacking group also known as Helix Kitten and OilRig, conducted sustained cyber espionage operations since 2014 targeting governments, financial institutions, energy companies, and other strategic sectors across the Middle East and beyond. The group used spearphishing emails, Office exploit documents, fake credential portals, and custom backdoors to break into networks and steal intelligence aligned with Iran's national interests. A major turning point came in April 2019 when a group called Lab Dookhtegan publicly leaked APT34's tools, infrastructure, and victim lists.
The attacks are attributed to APT34, a threat group assessed to operate on behalf of the Iranian government. The group is also tracked as OilRig, Helix Kitten, and Greenbug. Evidence supporting Iranian government sponsorship includes the group's consistent focus on targets that align with Iran's strategic interests, campaign activity correlated with Iranian working hours and national holidays, use of Iranian hacker tools and infrastructure, and multiple independent researcher assessments reaching the same conclusion.
The primary goal was intelligence gathering to support Iran's economic and geopolitical interests — particularly against rivals like the United States, Israel, and Saudi Arabia. The group collected credentials, stole sensitive documents, and maintained long-term access to government and critical infrastructure networks. Their persistent focus on specific target sets — energy, finance, military, and government — reflects a strategic intelligence collection mandate rather than opportunistic criminal activity.
The campaign was broad in both scope and duration, spanning five years across multiple continents. Primary targets were concentrated in the Middle East — particularly Saudi Arabia, UAE, Israel, Lebanon, and Jordan — but also extended to the United States, Europe (including Albania), South Korea, Zimbabwe, and South Asia. Across this period, APT34 targeted banks, airlines, governments, telecom companies, energy firms, hospitals, universities, and military organizations, with hundreds of confirmed compromised infrastructure endpoints documented.
APT34 targeted a wide range of industries: financial services, government agencies, energy and utilities, telecommunications, information technology, military organizations, healthcare, and education. Named victims include Juniper Networks (fake VPN portal), the Lebanon General Directorate of General Security, and the University of Oxford (via lookalike domains). The Saudi Arabian Communications & Information Technology Commission and Dubai Statistics Association were among those named in the April 2019 data leak.
APT34 typically initiated attacks with spearphishing emails containing malicious Microsoft Excel or Word documents embedded with VBA macros or exploiting Office vulnerabilities (CVE-2017-0199, CVE-2017-11882). Once executed, the documents installed backdoors — commonly Helminth, OopsIE, or POWRUNER — giving the attackers remote access. The group then escalated privileges, harvested credentials using tools like Pickpocket and ValueVault, moved laterally through the network via stolen accounts, and established long-term persistence using web shells on IIS servers and DNS tunneling for covert C2 communication.
These organizations hold strategic intelligence value for the Iranian government. Middle Eastern governments and militaries provide insight into Iran's regional rivals. Energy and petrochemical companies carry data relevant to Iran's economic competition with Gulf states. Financial institutions offer access to transactions and economic intelligence. The group's campaigns against Israeli institutions and U.S. defense and technology companies align with Iran's broader goal of monitoring and countering its principal adversaries.
Patch CVE-2017-0199 and CVE-2017-11882 and disable VBA macros in Office documents from external sources. Block .xlsm and macro-enabled Office attachments at the email gateway. Monitor IIS servers for unauthorized .aspx files in authentication paths, which may be APT34 web shells. Alert on outbound DNS queries with abnormally long subdomains — a sign of BONDUPDATER-style DNS tunneling. Block the 101 C2 IPs and 63 domains documented in this report at the network perimeter, and deploy EDR tools with behavioral detection for credential dumping, lateral movement via remote services, and PowerShell-based backdoor activity.