G0049 · 56 ATT&CK techniques · 19 correlated reports

OilRig

Aliases: COBALT GYPSY, IRN2, APT34, Helix Kitten, Evasive Serpens, Hazel Sandstorm, EUROPIUM, ITG13

OilRig is a suspected Iranian threat group that has targeted Middle Eastern and international victims since at least 2014. The group has targeted a variety of sectors, including financial, government, energy, chemical, and telecommunications. It appears the group carries out supply chain attacks, leveraging the trust relationship between organizations to attack their primary targets. The group works on behalf of the Iranian government based on infrastructure details that contain references to Iran, use of Iranian infrastructure, and targeting that aligns with nation-state interests.

Open interactive actor investigation

ATT&CK techniques

T1555.004
Windows Credential Manager
T1082
System Information Discovery
T1003.001
LSASS Memory
T1008
Fallback Channels
T1071.001
Web Protocols
T1059.003
Windows Command Shell
T1021.001
Remote Desktop Protocol
T1505.003
Web Shell
T1036
Masquerading
T1218.001
Compiled HTML File
T1046
Network Service Discovery
T1087.001
Local Account
T1137.004
Outlook Home Page
T1069.002
Domain Groups
T1113
Screen Capture
T1007
System Service Discovery
T1059.001
PowerShell
T1070.004
File Deletion
T1204.002
Malicious File
T1133
External Remote Services
T1201
Password Policy Discovery
T1087.002
Domain Account
T1003.004
LSA Secrets
T1140
Deobfuscate/Decode Files or Information
T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
T1110
Brute Force
T1059.005
Visual Basic
T1566.002
Spearphishing Link
T1120
Peripheral Device Discovery
T1071.004
DNS
T1105
Ingress Tool Transfer
T1049
System Network Connections Discovery
T1204.001
Malicious Link
T1078
Valid Accounts
T1573.002
Asymmetric Cryptography
T1566.001
Spearphishing Attachment
T1053.005
Scheduled Task
T1119
Automated Collection
T1056.001
Keylogging
T1033
System Owner/User Discovery
T1566.003
Spearphishing via Service
T1572
Protocol Tunneling
T1047
Windows Management Instrumentation
T1021.004
SSH
T1555
Credentials from Password Stores
T1003.005
Cached Domain Credentials
T1027.013
Encrypted/Encoded File
T1069.001
Local Groups
T1552.001
Credentials In Files
T1057
Process Discovery
T1555.003
Credentials from Web Browsers
T1016
System Network Configuration Discovery
T1012
Query Registry
T1059
Command and Scripting Interpreter
T1497.001
System Checks
T1027.005
Indicator Removal from Tools

Correlated CTI and IR reports

OilRig G0049
MITRE ATT&CK · direct source mapping
DNS Tunneling in the Wild: Overview of OilRig's DNS Tunneling
Unit 42 · actor reference
Iran-linked OilRig attacks Israeli organizations with cloud service-powered downloaders
ESET Research · actor reference
1. Executive Summary
Israel Threat Actors CTI · explicit report mention
Actor Deep Research Prompts
Israel Threat Actors CTI · explicit report mention
CTI Research: MuddyWater / Seedworm (Mango Sandstorm)
1200km CTI repository · explicit report mention
CTI Research: MuddyWater / Seedworm (Mango Sandstorm)
1200km CTI repository · explicit report mention
Cyber Threat Intelligence Dossier: Iranian and Hamas-Aligned Operations Targeting Israeli and Allied Ecosystems (2023-2026)
Israel Threat Actors CTI · explicit report mention
Defensive CTI Research on Threats to Israeli Government and Public-Sector Environments
Israel Threat Actors CTI · explicit report mention
Defensive Cyber Threat Intelligence Report: Israeli Critical Infrastructure and Geopolitical Escalation (2024-2026)
Israel Threat Actors CTI · explicit report mention
Executive Summary
Israel Threat Actors CTI · explicit report mention
Israel Government Threat Actors CTI: Evidentiary Foundation Intake
Israel Threat Actors CTI · explicit report mention
Malicious Activity as a Statistical Signal: A Detection Engineering Analysis of Anomaly-Based Detection
1200km CTI repository · explicit report mention
OilRig (APT34 / Helix Kitten / Earth Simnavaz etc)
Israel Threat Actors CTI · explicit report mention
Release Notes
Israel Threat Actors CTI · explicit report mention
Report Index
Israel Threat Actors CTI · explicit report mention
Research Intake Upgrade Summary
Israel Threat Actors CTI · explicit report mention
APT and financial attacks on industrial organizations in H2 2023
Kaspersky ICS CERT · actor context
OilRig APT 2025
Brandefense · actor context

Continue the investigation