news.mlab.sh
Threat intelligence
Threat actor

OilRig

Profile from actors.mlab.sh, coverage from our own index.

Suspected origin
Iran
First seen
2014-01-01 00:00:00
Motivation
Information theft and espionage
Targeted sectors
Aviation, Chemical, Defense, Education, Energy, Financial, Government, High-Tech, IT, Hospitality, Oil and gas, Telecommunications
TLP
WHITE

OilRig is a threat group with suspected Iranian origins that has targeted Middle Eastern and international victims since at least 2014. The group has targeted a variety of industries, including financial, government, energy, chemical, and telecommunications, and has largely focused its operations within the Middle East. It appears the group carries out supply chain attacks, leveraging the trust relationship between organizations to attack their primary targets. FireEye assesses that the group works on behalf of the Iranian government based on infrastructure details that contain references to Iran, use of Iranian infrastructure, and targeting that aligns with nation-state interests. This group was previously tracked under two distinct groups, APT 34 and OilRig, but was combined due to additional reporting giving higher confidence about the overlap of the activity. OilRig has 1 subgroup: 1. Subgroup: Greenbug, Volatile Kitten OilRig seems to be closely related to APT 33, Elfin, Magnallium since at least 2017 and perhaps DNSpionage. They also seem to overlap with Hexane. Also see HomeLand Justice and Orangeworm.

Also known as

APT 34APT34ATK 40ChryseneCobalt GypsyCrambusDEV-0861Earth SimnavazEUROPIUMEvasive SerpensG0049Hazel SandstormHelix KittenIRN2ITG13OilRigScarred ManticoreStorm-0861TA452Twisted KittenUNC1860Yellow Maero

Vulnerabilities exploited

Tooling and malware

BONDUPDATERHelminthISMInjectorMangoODAgentOilBoosterOilCheckOopsIEPowerExchangePOWRUNERQUADAGENTRDATRGDoorSampleCheck5000SEASHARPEESideTwistSolarZeroClearecertutilftpipconfigLaZagneMimikatzNetnetstatngrokPsExecRegSysteminfoTasklist

MITRE ATT&CK techniques

T1005 Data from Local SystemT1025 Data from Removable MediaT1113 Screen CaptureT1115 Clipboard DataT1119 Automated CollectionT1008 Fallback ChannelsT1105 Ingress Tool TransferT1219 Remote Access ToolsT1572 Protocol TunnelingT1110 Brute ForceT1555 Credentials from Password StoresT1112 Modify RegistryT1007 System Service DiscoveryT1012 Query RegistryT1016 System Network Configuration DiscoveryT1033 System Owner/User DiscoveryT1046 Network Service DiscoveryT1049 System Network Connections DiscoveryT1057 Process DiscoveryT1082 System Information DiscoveryT1120 Peripheral Device DiscoveryT1201 Password Policy DiscoveryT1047 Windows Management InstrumentationT1059 Command and Scripting InterpreterT1203 Exploitation for Client ExecutionT1195 Supply Chain CompromiseT1133 External Remote ServicesT1068 Exploitation for Privilege EscalationT1036 MasqueradingT1078 Valid AccountsT1140 Deobfuscate/Decode Files or Information

Coverage 2