FORENSIA

THREAT_ACTOR · G0049

OilRig

Also known as: OilRig, COBALT GYPSY, IRN2, APT34, Helix Kitten, Evasive Serpens, Hazel Sandstorm, EUROPIUM, ITG13, Earth Simnavaz, Crambus, TA452

Profile

OilRig is a suspected Iranian threat group that has targeted Middle Eastern and international victims since at least 2014. The group has targeted a variety of sectors, including financial, government, energy, chemical, and telecommunications. It appears the group carries out supply chain attacks, leveraging the trust relationship between organizations to attack their primary targets. The group works on behalf of the Iranian government based on infrastructure details that contain references to Iran, use of Iranian infrastructure, and targeting that aligns with nation-state interests.

MITRE ATT&CK ↗

Techniques

76 ATT&CK techniques attributed to this actor.

T1003.001 LSASS MemoryT1003.004 LSA SecretsT1003.005 Cached Domain CredentialsT1005 Data from Local SystemT1007 System Service DiscoveryT1008 Fallback ChannelsT1012 Query RegistryT1016 System Network Configuration DiscoveryT1021.001 Remote Desktop ProtocolT1021.004 SSHT1025 Data from Removable MediaT1027.005 Indicator Removal from ToolsT1027.013 Encrypted/Encoded FileT1033 System Owner/User DiscoveryT1036 MasqueradingT1036.005 Match Legitimate Resource Name or LocationT1046 Network Service DiscoveryT1047 Windows Management InstrumentationT1048.003 Exfiltration Over Unencrypted Non-C2 ProtocolT1049 System Network Connections DiscoveryT1053.005 Scheduled TaskT1056.001 KeyloggingT1057 Process DiscoveryT1059 Command and Scripting InterpreterT1059.001 PowerShellT1059.003 Windows Command ShellT1059.005 Visual BasicT1068 Exploitation for Privilege EscalationT1069.001 Local GroupsT1069.002 Domain GroupsT1070.004 File DeletionT1071.001 Web ProtocolsT1071.004 DNST1078 Valid AccountsT1078.002 Domain AccountsT1082 System Information DiscoveryT1087.001 Local AccountT1087.002 Domain AccountT1105 Ingress Tool TransferT1110 Brute ForceT1112 Modify RegistryT1113 Screen CaptureT1115 Clipboard DataT1119 Automated CollectionT1120 Peripheral Device DiscoveryT1133 External Remote ServicesT1137.004 Outlook Home PageT1140 Deobfuscate/Decode Files or InformationT1195 Supply Chain CompromiseT1201 Password Policy DiscoveryT1203 Exploitation for Client ExecutionT1204.001 Malicious LinkT1204.002 Malicious FileT1218.001 Compiled HTML FileT1219 Remote Access ToolsT1497.001 System ChecksT1505.003 Web ShellT1543.003 Windows ServiceT1552.001 Credentials In FilesT1553.002 Code SigningT1555 Credentials from Password StoresT1555.003 Credentials from Web BrowsersT1555.004 Windows Credential ManagerT1556.002 Password Filter DLLT1566.001 Spearphishing AttachmentT1566.002 Spearphishing LinkT1566.003 Spearphishing via ServiceT1572 Protocol TunnelingT1573.002 Asymmetric CryptographyT1583.001 DomainsT1586.002 Email AccountsT1587.001 MalwareT1588.002 ToolT1588.003 Code Signing CertificatesT1608.001 Upload MalwareT1686.003 Windows Host Firewall

Software

30 malware/tools attributed to this actor.

MimikatzPsExecNetTasklistRegftpSysteminfoipconfignetstatcertutilHelminthPOWRUNERSEASHARPEEISMInjectorRGDoorOopsIEQUADAGENTLaZagneBONDUPDATERRDATngrokSideTwistZeroCleareSolarSampleCheck5000MangoODAgentOilCheckOilBoosterPowerExchange

Related corpus activity

10,451 indicators EXHIBIT techniques this actor uses. This is a shared-technique signal, not a first-party attribution to OilRig.

IndicatorTypeFamilySevSrc
cve-2023-44976cveransomware852
cve-2026-1969cve851
cve-2025-68670cve852
cve-2026-3102cve853
cve-2025-2492cve852
cve-2021-29441cve851
cve-2026-22584cve852
cve-2025-11837cve852
cve-2025-34054cve854
cve-2014-2321cve851
cve-2020-17456cve851
cve-2020-22658cve852
cve-2017-18377cve851
cve-2021-25646cve851
cve-2025-66478cve852
cve-2025-0921cve852
cve-2021-27076cve851
cve-2013-3307cve852
cve-2016-5681cve852
cve-2016-15047cve854
cve-2024-1781cve851
cve-2018-8007cve851
cve-2025-23304cve852
cve-2021-4045cve851
cve-2020-22653cve852
cve-2022-47945cve851
cve-2025-34117cve851
cve-2026-4368cveransomware851
cve-2013-7471cve851
cve-2026-0740cve851

Showing the top 30 by severity of 10,451.