OilRig: Cyber-Espionage Targeting Global Critical Sectors
- Actor Motivations: Espionage,Exfiltration,Undetected
- Attack Vectors: Credential stuffing,Backdoor,Spear Phishing
- Attack Complexity: High
- Threat Risk: High Impact/Low Probability
Threat Overview
SOCRadar's January 2025 dark web profile on OilRig (APT34) documents the group as one of Iran's most persistent and sophisticated state-sponsored threat actors, active since at least 2016. OilRig targets government agencies, energy and oil & gas companies, telecommunications providers, financial institutions, universities, and research institutions — primarily across the Middle East, with confirmed extensions to Europe, North America, and Asia. The group follows a full kill chain methodology: reconnaissance using Netstat and Systeminfo; weaponization with custom tools including BondUpdater and Helminth; spearphishing delivery via email attachments, links, and LinkedIn (T1566.001/002/003); exploitation via Mimikatz for credential dumping and CVE-2017-11774 to abuse Outlook Home Page for persistence; C2 via DNS tunneling, encrypted channels, and fallback HTTP; and exfiltration over FTP (T1048.003). Post-compromise tools include LaZagne, ISMInjector, BONDUPDATER, PAExec, KEYPUNCH, LONGWATCH, VALUEVAULT, PICKPOCKET, and GOLDIRONY. OilRig also abuses Plink for tunnel creation and uses web shells for persistence. In destructive operations, the group has deployed ZeroCleare — a disk-wiping malware — demonstrating capability beyond espionage. The group regularly updates its toolset and evades detection through base64 obfuscation, AV testing, file deletion, and domain generation algorithms. OilRig's targeting aligns consistently with Iranian geopolitical and economic interests.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Case | Turkish Airlines Turkish Airlines or officially Türk Hava Yolları Anonim Ortaklığı is the flag carrier of Turkey. As of 2022, it operates scheduled services to 340 destinations in Europe, Asia, Africa, and the Americas, making it the largest mainline carrier in the world by number of passenger destinations. Turkish Airlines has been targeted by OilRig as the main target. | Verified |
| Sector | Defense | Verified |
| Sector | Financial | Verified |
| Sector | Government Agencies and Services | Verified |
| Sector | Energy | Verified |
| Sector | Oil and Gas | Verified |
| Sector | Telecommunication | Verified |
| Sector | University | Verified |
| Sector | University | Verified |
| Region | Middle East Countries | Verified |
| Region | Saudi Arabia | Verified |
| Region | United States | High |
| Region | European Countries | Verified |
Exploited Vulnerabilities
FAQs
Frequently Asked Questions about OilRig (APT34)
OilRig, also known as APT34, is an Iranian state-sponsored threat group active since at least 2016. They run long-term cyber-espionage campaigns against government agencies, energy and oil companies, telecoms, financial institutions, and universities — primarily in the Middle East, with operations extending to Europe, North America, and Asia. Their methods range from spearphishing emails to custom malware and DNS tunneling for covert communications. In some cases they have also deployed destructive disk-wiping malware. SOCRadar published a comprehensive profile of the group in January 2025, summarizing their full decade of documented activity.
OilRig is widely attributed to Iranian state interests. The group's targeting — focused on Iran's regional rivals in the Middle East, organizations connected to energy and oil markets, and entities that could provide geopolitical intelligence — is consistent with Iranian government collection priorities. Multiple security vendors including Palo Alto, FireEye, and CrowdStrike have attributed the group to Iran. OilRig is also known by several aliases: APT34, Helix Kitten, and Earth Simnavaz.
OilRig's primary goal is espionage — collecting intelligence that serves Iranian state interests. This includes stealing government communications, energy sector data, financial intelligence, and information about military and defense programs. The group also collects credentials at scale, which they reuse to maintain persistent access and pivot through networks. In some operations, they have gone beyond espionage and deployed destructive malware (ZeroCleare) capable of wiping entire disk systems — showing they can shift from intelligence collection to sabotage when directed to do so.
OilRig operates at significant scale — active since 2016 across the Middle East, Europe, North America, and Asia. Confirmed targets include organizations in Saudi Arabia, the UAE, Qatar, Kuwait, Turkey, and beyond. Sectors affected include government, energy and oil and gas, telecommunications, finance, defense, universities, and research institutions. Their consistent activity over nearly a decade across multiple continents makes them one of the broadest-operating Iranian APT groups in terms of geographic and sectoral reach.
OilRig primarily targets government agencies, energy and oil and gas companies, telecommunications providers, financial institutions, defense organizations, universities, and research institutions. Their focus on energy and oil aligns with Iran's interest in monitoring global energy markets and gaining competitive intelligence. Government and defense targets yield strategic and political intelligence. Telecoms provide access to communications infrastructure and subscriber data. Universities and think tanks are targeted for research on technology, cybersecurity, and political topics relevant to Iran's interests.
OilRig follows a structured kill chain. They begin with spearphishing — sending targeted emails with malicious attachments or links, and in some cases reaching out via LinkedIn. Once a victim opens the malicious file or clicks the link, custom malware like Helminth or BondUpdater is installed, establishing a backdoor. The group then uses PowerShell, Windows Command Shell, and VBScript to execute commands, dumps credentials with Mimikatz and LaZagne, and moves laterally through the network using stolen credentials and tools like PAExec. For persistence, they deploy web shells on servers and abuse the Outlook Home Page feature (CVE-2017-11774). Command and control runs primarily over DNS tunneling, with HTTP fallback and Plink-based encrypted tunnels. Data is exfiltrated over FTP, separate from the C2 channel. In some operations, they have deployed ZeroCleare to wipe disk data on target systems.
OilRig's targets hold information that directly serves Iranian strategic interests. Middle Eastern governments hold intelligence about regional security, diplomatic negotiations, and military capabilities — all critical for Iran's foreign policy. Energy and oil companies provide competitive intelligence about global energy markets and pricing, which matters enormously to an economy built on oil exports. Telecoms give access to communications infrastructure that can be monitored or disrupted. Defense organizations hold data about weapons programs and military capabilities that Iran needs to assess threats and plan responses. Universities and think tanks produce research that shapes policy toward Iran. Together, these targets give OilRig a comprehensive intelligence picture spanning political, economic, and military domains.
Deploy advanced email filtering with attachment sandboxing and block malicious file types. Train staff to spot spearphishing — including LinkedIn-delivered approaches. Apply the patch for CVE-2017-11774 and audit Outlook Home Page registry keys for unauthorized URL entries. Monitor DNS traffic for tunneling indicators: high query volume, unusually long hostnames, and TXT records carrying encoded data. Deploy credential theft detection for Mimikatz, LSASS memory access, and LaZagne execution. Enforce MFA on all external-facing services — VPN, OWA, Citrix — since OilRig aggressively reuses stolen credentials. Implement network segmentation to limit lateral movement. Maintain offline encrypted backups of critical systems as a safeguard against ZeroCleare-style disk-wiping operations. Organizations in energy, government, defense, and telecom sectors in the Middle East should treat OilRig as an active ongoing threat and invest in proactive threat hunting against known OilRig IOCs and TTPs.