Home/Threat Actor/OilRig
Threat Actor

OilRig

apt34_oilrig · iran · active since 2014

OilRig (APT34 / Helix Kitten / Earth Simnavaz / Crambus / Hazel Sandstorm / Evasive Serpens / Cobalt Gypsy / Greenbug / EUROPIUM / ITG13 / TA452 / G0049) is an Iranian state-sponsored cyber-espionage actor attributed to the Ministry of Intelligence and Security (MOIS / VAJA) and active since at least 2014, conducting the longest continuous operational cadence among Iranian APTs against government, diplomatic, oil and gas, petrochemical, financial, telecommunications, and identity- infrastructure targets primarily in the GCC, Levant, Iraq, and broader Middle East / North Africa.

technically distinguished by sustained sophisticated DNS tunneling for C2 (BONDUPDATER / QUADAGENT / ALMA Communicator / DNSExfiltrator / Saitama lineage), Outlook Home Page abuse (CVE-2017-11774), supply-chain compromise via trust relationships, LinkedIn-based academic- persona social engineering (FireEye 2019 'Hard Pass'), and an extensive custom backdoor family (Helminth - POWRUNER - BONDUPDATER - Saitama - SideTwist - StealHook - Menorah - Outer Space / Juicy Mix - PowerExchange)

the March-April 2019 Lab Dookhtegan public dump of OilRig's operational toolkit and operator identities and the October 2019 NSA / NCSC UK disclosure of Russian FSB Turla hijacking OilRig infrastructure as a false-flag layer represent two of the most consequential open-source exposures of a state actor's operational data, yet OilRig has continued aggressive operations through 2026 including the StealHook UAE Exchange targeting (October 2024) and broader identity-infrastructure compromise activity.

iran confidence: high 36 aliases MITRE ATT&CK G0057 ↗

Profile

OilRig (APT34 / Helix Kitten / Earth Simnavaz / Crambus / Hazel Sandstorm / Evasive Serpens / Cobalt Gypsy / Greenbug / EUROPIUM / ITG13 / TA452 / G0049) is one of the most operationally active Iranian state-sponsored cyber-espionage actors, formally attributed by multiple vendors to Iran's Ministry of Intelligence and Security (MOIS, also known as VAJA or VEVAK). Active since at least 2014 (with some indicators pointing to 2012 activity), OilRig has sustained the longest continuous operational cadence among Iranian APTs in public reporting, described by Hunt & Hackett as the central component of Iran's cyber-espionage and intelligence-gathering operations. Targeting is sharply focused on the Middle East and North Africa, with particular emphasis on Gulf Cooperation Council states (Saudi Arabia, UAE, Kuwait, Bahrain, Qatar, Oman), Levant countries (Jordan, Lebanon, Israel, Iraq, Palestine), Turkey, Egypt, and increasingly Iraq. Secondary targeting extends to Eurasia (Azerbaijan, Armenia, Georgia, Kazakhstan) and Western states with Middle East policy interests. Sectoral focus consistently covers government and foreign ministries, diplomatic missions, oil and gas, petrochemical, financial services, telecommunications, and increasingly identity infrastructure (Microsoft Exchange, Microsoft 365). OilRig is technically distinguished by sustained, sophisticated DNS tunneling for C2, across BONDUPDATER, QUADAGENT, ALMA Communicator, DNSExfiltrator, Saitama, Mango, and successor implants, establishing the technique as a defining OilRig fingerprint that other Iranian clusters later adopted. Other tradecraft hallmarks include: (a) supply-chain compromise via trust-relationship abuse (per FireEye's earliest profiles); (b) heavy use of Outlook Home Page abuse (CVE-2017-11774) and Exchange-based persistence (transport agent, mailbox rules, ExchangeLeech)

(c) LinkedIn-based social engineering with academic-persona pretexts (the 2019 'Hard Pass' campaign); (d) increasingly cloud-integrated tooling (Outer Space, Juicy Mix using cloud-service downloaders.

StealHook abusing on- premises Exchange)

(e) extensive custom backdoor families including Helminth, POWRUNER, BONDUPDATER, QUADAGENT, ISMAgent / ISMDoor, Saitama, SideTwist, StealHook, Menorah, Outer Space, Juicy Mix, Karkoff, RDAT, TONEDEAF, VALUEVAULT, LONGWATCH, PowerExchange. The March-April 2019 'Lab Dookhtegan' / 'Read My Lips' leak, in which a Persian-named persona dumped portions of OilRig's operational toolkit, source code, credentials, and operator identities via Telegram and GitHub, represented one of the most damaging open-source exposures of an active state actor's operational data. Despite this exposure, OilRig rapidly rebuilt and has continued aggressive operations, demonstrating strong state backing and operational resilience. The October 2019 NSA / NCSC UK disclosure that Russian FSB Turla had hijacked OilRig infrastructure and reused OilRig tooling as a false- flag layer compounded the operational complications from the Lab Dookhtegan exposure, the first openly-documented case of one state actor hijacking another's compromised victim access. Recent operations (2023-2026) emphasize identity-infrastructure compromise (Exchange, Microsoft 365), cloud-service-powered C2 downloaders, sustained Iraqi government targeting (Check Point June 2024), the StealHook backdoor against UAE Exchange servers (Trend Micro October 2024), and 2025 LLM use (Google Gemini, per Google Threat Intelligence reporting). The March 2, 2026 'Operation Epic Fury' US-Israeli joint coordinated action against Iranian infrastructure has implications for OilRig operations under continued vendor tracking.

Aliases

36
oilrigoil rigapt34cobalt gypsyirn2helix kittenevasive serpenshazel sandstormeuropiumitg13earth simnavazcrambusta452greenbugtwisted kittenvolatile kittenatk40dev-0861storm-0861scarred manticoreyellow maerochryseneoperation cleavercleaverop cleavertarh andishanalibabatg-2889threat group 2889moisministry of intelligence iranvajavevakg0049apt 34apt-34

Notable Campaigns

15
2026Operation Epic Fury, US/Israeli Coordinated Action (March 2026)
2025Iranian Actor LLM Use Including OilRig (Google Threat Intelligence 2025)
2024StealHook Backdoor Against Gulf-State Exchange Servers (Trend Micro October 2024)
2024Iranian Cyber Attack Against Iraqi Government (Check Point June 2024)
2023Symantec Crambus Disclosure (October 2023)
2023Outer Space / Juicy Mix Backdoors (ESET September 2023)
2022Saitama Backdoor Against Jordanian Foreign Affairs (May 2022)
2020DNS Tunneling Sustained Use (Unit 42 February 2020)
2019-2020ZeroCleare / Dustman Wiper Overlap (2019-2020)
2019Turla Hijacks OilRig Infrastructure (NSA/NCSC October 2019)
2019Lab Dookhtegan / Read My Lips Leak (March-April 2019)
2019Hard Pass, LinkedIn Spear-Phishing (FireEye July 2019)
2018BONDUPDATER Targeting Middle Eastern Government (Unit 42 September 2018)
2017FireEye APT34, New Targeted Attack in the Middle East (December 2017)
2016Unit 42, The OilRig Campaign (May 2016)

Attribution & Reporting

Attributed by
FBICISANSAUS Cyber CommandUS Department of TreasuryUK NCSCSaudi National Cybersecurity AuthorityUAE Cyber Security CouncilIsrael National Cyber DirectorateFive EyesMicrosoftMandiantFireEyeGoogle Cloud Threat IntelligenceCrowdStrikeSymantec / BroadcomPalo Alto Networks Unit 42Trend MicroESETCisco TalosKasperskyCheck Point ResearchSentinelOneProofpointRecorded FutureInsikt GroupDragosClearSkySecureWorksHunt & HackettBooz Allen HamiltonLab DookhteganSOCRadar
Key reporting
reportPalo Alto Networks Unit 42: The OilRig Campaign, Attacks on Saudi Arabian Organizations Deliver Helminth Backdoor (May 2016)
reportPalo Alto Networks Unit 42: OilRig Uses Updated BONDUPDATER to Target Middle Eastern Government (September 2018)
reportPalo Alto Networks Unit 42: DNS Tunneling in the Wild, Overview of OilRig's DNS Tunneling (February 2020)
reportPalo Alto Networks Unit 42: Evasive Serpens Atom Page (ongoing)
reportFireEye / Mandiant: APT34, New Targeted Attack in the Middle East (December 2017)
reportFireEye: Hard Pass, Declining APT34's Invite to Join Their Professional Network (July 2019)
reportESET: OilRig's Outer Space and Juicy Mix, Same ol' rig, new drill pipes (September 2023)
reportESET: OilRig's Persistent Attacks Using Cloud Service-Powered Downloaders (December 2023 / March 2024)
reportSymantec Threat Hunter Team: Crambus, New Campaign Targets Middle Eastern Government (October 2023)
reportTrend Micro: Earth Simnavaz (aka APT34) Levies Advanced Cyberattacks Against Middle East (October 2024)
reportCheck Point Research: The Unraveling of an Iranian Cyber Attack Against the Iraqi Government (June 2024)
reportMalwarebytes: APT34 Targets Jordan Government Using New Saitama Backdoor (May 2022)
reportFortinet: Please Confirm You Received Our APT (Saitama analysis, 2022)
reportNSA / NCSC UK: Turla Group Exploits Iranian APT to Expand Coverage of Victims (October 2019)
reportProofpoint: Iranian State-Sponsored and Aligned Attacks (January 2020)
reportSOCRadar: Dark Web Profile, OilRig / APT34 (August 2024)
reportHunt & Hackett: Threat Actor Profile, OilRig
reportRecorded Future / Insikt Group: Iranian APT34 Profile
reportCouncil on Foreign Relations: OilRig Cyber Operations Tracker
reportBooz Allen Hamilton: APT34 / OilRig Hunt Report
reportLab Dookhtegan / 'Read My Lips' Leak Material (March-April 2019, via Telegram and GitHub)
reportEuRepoC: APT Profile, OilRig

Operational

State sponsor

Iran Ministry of Intelligence and Security (MOIS / VAJA). Attribution by FireEye, Microsoft, Mandiant, and others based on Iranian infrastructure references, Persian-language artifacts in tooling, operating-hours alignment, and targeting consistently aligned with Iranian state intelligence priorities. The leaked 2019 Lab Dookhtegan operator data provided one of the strongest open-source attribution pillars.

Motivations
espionage, intelligence_gathering, long_term_access_positioning, diplomatic_collection, regional_geopolitical_collection, sanctions_evasion_research, dual_use_technology_collection, supply_chain_compromise, credential_harvesting, identity_infrastructure_compromise, opportunistic_destruction
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)57/60 · 95%
Analytics (MITRE CAR)35/60 · 58%
Runtime / container (Falco)5/60 · 8%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)12/60 · 20%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

14 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
MAILOVERMAIL OVERMANGOSTEENMENORAHMETERPRETERSAITAMASHADOWLOCKSHADOW LOCKSOLARSYSTEMSOLAR SYSTEMSTEALHOOKSTEAL HOOK
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin