← threatfilter.dev / all groups / OilRig
OilRig
Also known as: COBALT GYPSY · IRN2 · APT34 · Helix Kitten · Evasive Serpens · Hazel Sandstorm · EUROPIUM · ITG13 · Earth Simnavaz · Crambus · TA452
Overview
OilRig is a suspected Iranian threat group that has targeted Middle Eastern and international victims since at least 2014. The group has targeted a variety of sectors, including financial, government, energy, chemical, and telecommunications. It appears the group carries out supply chain attacks, leveraging the trust relationship between organizations to attack their primary targets. The group works on behalf of the Iranian government based on infrastructure details that contain references to Iran, use of Iranian infrastructure, and targeting that aligns with nation-state interests.
Targets
Chemical · Civil society · Defense · Education · Energy · Engineering · Finance · Government · Other · Private sector · Technology · Telecommunications
Regions
Canada · China · France · Germany · India · Iraq · Israel · Kuwait · Lebanon · Mexico · Middle East · Pakistan · Qatar · Saudi Arabia · South Korea · Turkey · United Kingdom · United States
Capabilities
- Supply-chain compromise — ATT&CK T1195
- Destructive / data-wiping operations — software: ZeroCleare
- Exploitation of public-facing / client applications — ATT&CK T1203
- Custom malware/implant development — ATT&CK: 18 attributed custom malware families
- Documented tooling: Watering holes, 64-bit malware, covert C2 via IPv6 DNS, ISMDOOR — MISP galaxy (meta.capabilities)
TTPs — 76 techniques across 13 tactics
Resource Development
-
T1583.001Domains -
T1586.002Email Accounts -
T1587.001Malware -
T1588.002Tool -
T1588.003Code Signing Certificates -
T1608.001Upload Malware
Initial Access
-
T1195Supply Chain Compromise -
T1566.001Spearphishing Attachment -
T1566.002Spearphishing Link -
T1566.003Spearphishing via Service
Execution
-
T1047Windows Management Instrumentation -
T1053.005Scheduled Task -
T1059Command and Scripting Interpreter -
T1059.001PowerShell -
T1059.003Windows Command Shell -
T1059.005Visual Basic -
T1203Exploitation for Client Execution -
T1204.001Malicious Link -
T1204.002Malicious File
Persistence
-
T1133External Remote Services -
T1137.004Outlook Home Page -
T1505.003Web Shell -
T1543.003Windows Service
Privilege Escalation
Stealth
-
T1027.005Indicator Removal from Tools -
T1027.013Encrypted/Encoded File -
T1036Masquerading -
T1036.005Match Legitimate Resource Name or Location -
T1070.004File Deletion -
T1078Valid Accounts -
T1078.002Domain Accounts -
T1140Deobfuscate/Decode Files or Information -
T1218.001Compiled HTML File -
T1497.001System Checks
Defense Impairment
-
T1112Modify Registry -
T1553.002Code Signing -
T1556.002Password Filter DLL -
T1686.003Windows Host Firewall
Credential Access
-
T1003.001LSASS Memory -
T1003.004LSA Secrets -
T1003.005Cached Domain Credentials -
T1110Brute Force -
T1552.001Credentials In Files -
T1555Credentials from Password Stores -
T1555.003Credentials from Web Browsers -
T1555.004Windows Credential Manager
Discovery
-
T1007System Service Discovery -
T1012Query Registry -
T1016System Network Configuration Discovery -
T1033System Owner/User Discovery -
T1046Network Service Discovery -
T1049System Network Connections Discovery -
T1057Process Discovery -
T1069.001Local Groups -
T1069.002Domain Groups -
T1082System Information Discovery -
T1087.001Local Account -
T1087.002Domain Account -
T1120Peripheral Device Discovery -
T1201Password Policy Discovery
Lateral Movement
-
T1021.001Remote Desktop Protocol -
T1021.004SSH
Collection
-
T1005Data from Local System -
T1025Data from Removable Media -
T1056.001Keylogging -
T1113Screen Capture -
T1115Clipboard Data -
T1119Automated Collection
Command and Control
-
T1008Fallback Channels -
T1071.001Web Protocols -
T1071.004DNS -
T1105Ingress Tool Transfer -
T1219Remote Access Tools -
T1572Protocol Tunneling -
T1573.002Asymmetric Cryptography
Exfiltration
Tools & malware (30)
ISMInjector · ODAgent · RDAT · Systeminfo · QUADAGENT · OopsIE · ngrok · Tasklist · Net · certutil · ZeroCleare · Reg · POWRUNER · netstat · Solar · ipconfig · LaZagne · BONDUPDATER · SideTwist · Helminth · Mango · OilBooster · SampleCheck5000 · PsExec · SEASHARPEE · Mimikatz · PowerExchange · OilCheck · RGDoor · ftp
Reporting (3)
- Earth Simnavaz (aka APT34) Levies Advanced Cyberattacks Against Middle East — Fahmy, M. et al
- Crambus: New Campaign Targets Middle Eastern Government — Symantec Threat Hunter Team
- How Microsoft names threat actors — Microsoft