Threat intelligence
- Suspected origin
- Iran
- First seen
- 2014-01-01 00:00:00
- Motivation
- Information theft and espionage
- Targeted sectors
- Aviation, Chemical, Defense, Education, Energy, Financial, Government, High-Tech, IT, Hospitality, Oil and gas, Telecommunications
- TLP
- WHITE
OilRig is a threat group with suspected Iranian origins that has targeted Middle Eastern and international victims since at least 2014. The group has targeted a variety of industries, including financial, government, energy, chemical, and telecommunications, and has largely focused its operations within the Middle East. It appears the group carries out supply chain attacks, leveraging the trust relationship between organizations to attack their primary targets. FireEye assesses that the group works on behalf of the Iranian government based on infrastructure details that contain references to Iran, use of Iranian infrastructure, and targeting that aligns with nation-state interests. This group was previously tracked under two distinct groups, APT 34 and OilRig, but was combined due to additional reporting giving higher confidence about the overlap of the activity.
OilRig has 1 subgroup:
1. Subgroup: Greenbug, Volatile Kitten
OilRig seems to be closely related to APT 33, Elfin, Magnallium since at least 2017 and perhaps DNSpionage. They also seem to overlap with Hexane.
Also see HomeLand Justice and Orangeworm.
Also known as
APT 34APT34ATK 40ChryseneCobalt GypsyCrambusDEV-0861Earth SimnavazEUROPIUMEvasive SerpensG0049Hazel SandstormHelix KittenIRN2ITG13OilRigScarred ManticoreStorm-0861TA452Twisted KittenUNC1860Yellow Maero
Vulnerabilities exploited
Tooling and malware
BONDUPDATERHelminthISMInjectorMangoODAgentOilBoosterOilCheckOopsIEPowerExchangePOWRUNERQUADAGENTRDATRGDoorSampleCheck5000SEASHARPEESideTwistSolarZeroClearecertutilftpipconfigLaZagneMimikatzNetnetstatngrokPsExecRegSysteminfoTasklist
MITRE ATT&CK techniques
T1005 Data from Local SystemT1025 Data from Removable MediaT1113 Screen CaptureT1115 Clipboard DataT1119 Automated CollectionT1008 Fallback ChannelsT1105 Ingress Tool TransferT1219 Remote Access ToolsT1572 Protocol TunnelingT1110 Brute ForceT1555 Credentials from Password StoresT1112 Modify RegistryT1007 System Service DiscoveryT1012 Query RegistryT1016 System Network Configuration DiscoveryT1033 System Owner/User DiscoveryT1046 Network Service DiscoveryT1049 System Network Connections DiscoveryT1057 Process DiscoveryT1082 System Information DiscoveryT1120 Peripheral Device DiscoveryT1201 Password Policy DiscoveryT1047 Windows Management InstrumentationT1059 Command and Scripting InterpreterT1203 Exploitation for Client ExecutionT1195 Supply Chain CompromiseT1133 External Remote ServicesT1068 Exploitation for Privilege EscalationT1036 MasqueradingT1078 Valid AccountsT1140 Deobfuscate/Decode Files or Information
Coverage 2
threat-intel
The Cavern C2 framework, used by Iranian nation-state hackers linked to the Ministry of Intelligence and Security (MOIS) and associated with groups like MuddyWater and OilRig (Lyceum), is undergoing continuous evolution.…

threat-intel
HollowGraph, a new malware dubbed by Group-IB, leverages Microsoft 365 calendars to establish command-and-control communication, specifically targeting Israeli entities. The malware uses a sophisticated technique to hide…