Threats Feed|APT34|Last Updated 01/05/2026|AuthorCertfa Radar|Publish Date29/09/2023

APT34's Menorah Malware: A Look at the New Cyber Threat Targeting Saudi Arabia

  • Actor Motivations: Espionage,Exfiltration
  • Attack Vectors: Backdoor,Malicious Macro,Spear Phishing
  • Attack Complexity: Medium
  • Threat Risk: High Impact/Low Probability

Threat Overview

Trend Micro researchers identified APT34 using a new custom backdoor named Menorah — a .NET-based malware delivered via a malicious Word document ("MyCv.doc") disguised as a Seychelles government license registration form. The document contained hidden macros that dropped Menorah into the system's %ALLUSERSPROFILE%\Office365 directory and established persistence through a scheduled task named "OneDriveStandaloneUpdater." Once installed, Menorah fingerprinted the victim machine using a hashed combination of machine name and username, communicated with a remote C2 server over HTTP using Base64-encoded, XOR-obfuscated traffic, and supported commands for file listing, selective file upload, shell command execution, and file download. The pricing in the lure document was denominated in Saudi Riyal, strongly suggesting the targeted victim was an organization in Saudi Arabia. Trend Micro noted functional similarities to APT34's earlier SideTwist backdoor, particularly in C2 communication and machine fingerprinting logic, though Menorah is a .NET reimplementation with enhanced sandbox evasion and traffic obfuscation.

Detected Targets

TypeDescriptionConfidence
SectorGovernment Agencies and Services
The lure document mimicked a license registration form from the Seychelles Licensing Authority. Pricing in Saudi Riyal suggests the intended victim was a government-affiliated or regulated organization in Saudi Arabia.
Medium
RegionSaudi Arabia
High

Extracted IOCs

  • tecforsc-001-site1.gtempurl[.]com
  • 64156f9ca51951a9bf91b5b74073d31c16873ca60492c25895c1f0f074787345
  • 8a8a7a506fd57bde314ce6154f2484f280049f2bda504d43704b9ad412d5d618
  • hxxp://tecforsc-001-site1.gtempurl[.]com/ads.asp
download

Tip: 4 related IOCs (0 IP, 1 domain, 1 URL, 0 email, 2 file hash) to this threat have been found.

Overlaps

APT34Menorah Malware: APT34’s Espionage Tool in Middle East Campaigns

Source: SecurityScorecard - December 2023

Detection (three cases): hxxp://tecforsc-001-site1.gtempurl[.]com/ads.asp, 64156f9ca51951a9bf91b5b74073d31c16873ca60492c25895c1f0f074787345, tecforsc-001-site1.gtempurl[.]com

OilRigOilRig's Dual Campaigns Against Israeli Organizations: A Deep Dive

Source: ESET - September 2023

Detection (one case): tecforsc-001-site1.gtempurl[.]com

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

APT34 Menorah Malware Campaign — Frequently Asked Questions

In August 2023, Trend Micro's threat hunters identified a targeted spearphishing campaign by the Iranian state-linked group APT34 that deployed a new custom backdoor called Menorah. The malware was hidden inside a malicious Word document disguised as a government license registration form. Once a victim opened the document and enabled macros, Menorah was silently installed on their machine, giving the attackers persistent remote access to the system.

In August 2023, Trend Micro's threat hunters identified a targeted spearphishing campaign by the Iranian state-linked group APT34 that deployed a new custom backdoor called Menorah. The malware was hidden inside a malicious Word document disguised as a government license registration form. Once a victim opened the document and enabled macros, Menorah was silently installed on their machine, giving the attackers persistent remote access to the system.

The attack was carried out by APT34, also known as OilRig — an Iranian state-sponsored hacking group that has been active since at least 2014. APT34 is widely believed to operate in support of Iran's intelligence objectives and has a long track record of targeting governments, critical infrastructure, and private organizations across the Middle East and beyond. Trend Micro attributed this campaign to APT34 based on infrastructure overlap, code similarities to prior APT34 tools, and consistent attack patterns.

The campaign was a cyberespionage operation. The Menorah backdoor was designed to silently collect information from infected systems — including file listings, specific documents, system identity details, and shell command outputs — and send that data back to a remote server controlled by the attackers. The goal was covert, long-term access to the victim's network for intelligence collection rather than immediate disruption or financial theft.

Based on available evidence, this appears to have been a narrowly targeted campaign directed at a specific organization in Saudi Arabia. The lure document — a fake government license form from the Seychelles Licensing Authority — contained pricing in Saudi Riyal, which strongly suggests the intended victim was a Saudi-based entity. No broader list of victims was identified by researchers. APT34's broader pattern, however, shows consistent targeting of Middle Eastern governments, energy companies, and critical infrastructure across the region.

The attack appears to have targeted an organization within Saudi Arabia, likely in or connected to government-regulated sectors given the use of a government licensing document as the lure. APT34 typically focuses on government agencies, energy and critical infrastructure, telecommunications, and financial institutions across the Middle East. While this specific campaign targeted a single organization, the group's historical operations have impacted a broad range of sectors in the region.

The attack started with a spearphishing email carrying a malicious Word document ("MyCv.doc"). When the victim opened the document and enabled macros, hidden code silently dropped the Menorah malware onto the system in a folder mimicking a Microsoft Office directory. The malware then created a scheduled task with a legitimate-sounding name to run itself automatically. Once active, Menorah connected to the attackers' remote server every 32 seconds, sent a fingerprint of the victim's machine, and awaited instructions — including commands to list files, upload documents, run system commands, or download additional tools.

Saudi Arabia is a high-value target for APT34 due to its geopolitical significance, its role as a major energy producer, and its position in regional politics that puts it in direct tension with Iran's strategic interests. Organizations in Saudi Arabia — particularly those connected to government, energy, or regulated industries — hold sensitive information that would be valuable to Iranian intelligence services. APT34 has repeatedly focused on Saudi Arabian targets over many years, making the kingdom one of the group's primary areas of operation.

Organizations should disable macros in Microsoft Office documents received from external sources and train employees to recognize phishing lures using government document themes. Security teams should monitor for new scheduled tasks with names mimicking legitimate Windows or Microsoft services. Block or alert on outbound HTTP connections to gtempurl[.]com domains, and add the disclosed file hashes and C2 URL to endpoint and network detection tools. Finally, keep email filtering and endpoint protection updated to detect Trojan.W97M.SIDETWIST.AB and Trojan.MSIL.SIDETWIST.AA variants.

About Affiliation
APT34
APT34 is Mandiant's designation for the Iranian MOIS-linked threat cluster known as OilRig. Active since at least 2014, Mandiant identified APT34 as an advanced persistent threat focused on long-term espionage against government, energy, and financial organizations in the Middle East. Mandiant has documented the group's evolution over more than a decade, including its use of DNS-based command and control, LinkedIn-based social engineering lures, and a continuously expanding custom malware arsenal. APT34 remains one of the most thoroughly documented Iranian state-sponsored actors in public threat intelligence.
View APT34's Insights