All actors

OilRig

Also reported as IRN2, Helix Kitten, Evasive Serpens, Hazel Sandstorm, EUROPIUM and 22 other names. Linked to Iran by three sources.

Reports
403
Last reported
Known CVEs
303
Techniques in ATT&CK
81
Origin
Iran
ID
G0049
Merge evidence
30 alias matches

Reports per quarter

  1. 2013 Q1: 1 report
  2. 2013 Q2: 1 report
  3. 2013 Q3: no reports
  4. 2013 Q4: no reports
  5. 2014 Q1: no reports
  6. 2014 Q2: no reports
  7. 2014 Q3: no reports
  8. 2014 Q4: no reports
  9. 2015 Q1: no reports
  10. 2015 Q2: no reports
  11. 2015 Q3: no reports
  12. 2015 Q4: no reports
  13. 2016 Q1: no reports
  14. 2016 Q2: 4 reports
  15. 2016 Q3: no reports
  16. 2016 Q4: 3 reports
  17. 2017 Q1: 16 reports
  18. 2017 Q2: 8 reports
  19. 2017 Q3: 13 reports
  20. 2017 Q4: 18 reports
  21. 2018 Q1: 15 reports
  22. 2018 Q2: 5 reports
  23. 2018 Q3: 11 reports
  24. 2018 Q4: 6 reports
  25. 2019 Q1: 16 reports
  26. 2019 Q2: 26 reports
  27. 2019 Q3: 21 reports
  28. 2019 Q4: 11 reports
  29. 2020 Q1: 20 reports
  30. 2020 Q2: 6 reports
  31. 2020 Q3: 16 reports
  32. 2020 Q4: 7 reports
  33. 2021 Q1: 9 reports
  34. 2021 Q2: 9 reports
  35. 2021 Q3: 8 reports
  36. 2021 Q4: 6 reports
  37. 2022 Q1: 7 reports
  38. 2022 Q2: 14 reports
  39. 2022 Q3: 10 reports
  40. 2022 Q4: no reports
  41. 2023 Q1: 7 reports
  42. 2023 Q2: 3 reports
  43. 2023 Q3: 3 reports
  44. 2023 Q4: 8 reports
  45. 2024 Q1: 3 reports
  46. 2024 Q2: 7 reports
  47. 2024 Q3: 4 reports
  48. 2024 Q4: 7 reports
  49. 2025 Q1: 1 report
  50. 2025 Q2: 5 reports
  51. 2025 Q3: no reports
  52. 2025 Q4: no reports
  53. 2026 Q1: 3 reports
  54. 2026 Q2: 61 reports
  55. 2026 Q3: 4 reports
Dated reports, 2013 Q1 to 2026 Q3.

Techniques seen in the last two years

Show all 277 techniques Show fewer

Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.

Also listed by ATT&CK

Show all 18 techniques Show fewer

CVEs named in reports

Show all 303 CVEs Show fewer

KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.

Reports

  1. UNIT 42 PLAYBOOK VIEWER

    date ORKL added it fromORKL

Show all 403 reports Show fewer
  1. DistTrack (Malware Family)

    date ORKL added it fromORKL

  2. Helix Kitten

    date ORKL added it fromORKL

  3. Threat Group Cards: A Threat Actor Encyclopedia

    date ORKL added it fromORKL

  4. Council on Foreign Relations

    date ORKL added it fromORKL

  5. Charming Kitten

    date ORKL added it fromORKL

  6. Targeted Attacks against Banks in the Middle East

    date ORKL added it fromORKL

  7. Threat Group Cards: A Threat Actor Encyclopedia

    date ORKL added it fromORKL

  8. TwoFace (Malware Family)

    date ORKL added it fromORKL

  9. OilRig, APT 34, Helix Kitten, Chrysene

    date ORKL added it fromORKL

  10. BONDUPDATER (Malware Family)

    date ORKL added it fromORKL

  11. Talks - BrightTALK

    date ORKL added it fromORKL

  12. Untitled

    Malpedia library date fromORKL

  13. watchtower-2023-eoy-report-en

    file creation date fromORKL

  14. New APT34 Malware Targets The Middle East

    Malpedia library date fromORKL

  15. New APT34 Malware Targets The Middle East

    date in the CCS '25 data Trendmicro fromORKLCCS '25 data

  16. New APT34 Malware Targets The Middle East

    date in the title fromORKL

  17. Advanced Persistent Threats (APTs)

    date in the title fromORKL

  18. APT trends report Q2 2020

    date in the title fromORKL

  19. APT34 - Saitama Agent

    date in the title fromORKL

  20. APT34 - Saitama Agent

    Malpedia library date XJunior fromORKLCCS '25 data

  21. Translating Saitama's DNS tunneling messages

    date in the title fromORKL

  22. eset_threat_report_t12022

    file creation date fromORKL

  23. Please Confirm You Received Our APT

    date in the title fromORKL

  24. APT34 targets Jordan Government using new Saitama backdoor

    date in the title fromORKL

  25. Social Engineering Remains Key Tradecraft for Iranian APTs

    date in the title fromORKL

  26. eset_threat_report_t32021

    file creation date fromORKL

  27. Global_APT_Research_Report_for_the_first_half_of_2021-360

    file creation date fromORKL

  28. Advanced Persistent Threats (APTs)

    date in the title fromORKL

  29. An Overview of FinTech Threat Landscape

    date in the title fromORKL

  30. Pay2Kitten report

    Malpedia library date fromORKL

  31. Geopolitical nation-state threat actor overview June 2021

    date in the title fromORKL

  32. mtrends-2018.pdf

    file creation date fromORKL

  33. Iran’s APT34 Returns with an Updated Arsenal

    date in the title fromORKL

  34. Iran’s APT34 Returns with an Updated Arsenal - Check Point Research

    date in the CCS '25 data Check Point fromORKLCCS '25 data

  35. LazyScripter

    Malpedia library date Malwarebytes fromORKLCCS '25 data

  36. The_CrowdStrike_2021_Global_Threat_Report

    file creation date fromORKL

  37. Analytics

    Malpedia library date fromORKL

  38. ATR_82599

    date in the CCS '25 data Telsy fromORKLCCS '25 data

  39. Group-IB_Hi-Tech_Crime_Trends_2020-2021_en

    file creation date fromORKL

  40. APT_trends_report_Q2_2020_Securelist

    file creation date fromORKL

  41. APT trends report Q2 2020

    date in the title fromORKL

  42. 0628-2020APT上半年报告-画册

    file creation date fromORKL

  43. Suspected Naikon DGA Domains

    date in the title fromORKL

  44. ESET_Turla_ComRAT

    Malpedia library date ESET fromORKLCCS '25 data

  45. Report2020CrowdStrikeGlobalThreatReport

    Malpedia library date fromORKL

  46. The North Korean Kimsuky APT keeps threatening South Korea evolving its TTPs

    date in the CCS '25 data Yoroi fromORKLCCS '25 data

  47. apt34-aka-oilrig-attacks-lebanon-government-entities-with-maildropper-implant

    date in the CCS '25 data Telsy fromORKLCCS '25 data

  48. Fox Kittens report 16.2.2020

    date in the CCS '25 data ClearSky Cyber Security ltd fromORKLCCS '25 data

  49. 2020.02.22_APT_threat_report_2019_CN_version

    Malpedia library date fromORKL

  50. Current Iran-Associated Cyber Threats

    file creation date Symantec fromORKL

  51. IBM X-Force IRIS ZeroCleare - Tehcnical Paper

    file creation date fromORKL

  52. Iranian Threat Actors- Preliminary Analysis

    date in the title fromORKL

  53. North American Electric Cyber Threat Perspective

    Malpedia library date fromORKL

  54. Drilling Deep: A Look at Cyberattacks on the Oil and Gas Industry

    date in the CCS '25 data Trend Micro fromORKLCCS '25 data

  55. Group-IB_Hi-Tech_Crime_Trends_2019-2020_en

    file creation date fromORKL

  56. Microsoft Word - New Destructive Wiper ZeroCleare v1 MLM comments.docx

    date in the CCS '25 data IBM Security fromORKLCCS '25 data

  57. Group-IB_Hi-Tech_Crime_Trends_2019-2020

    date in the CCS '25 data Group-IB fromORKLCCS '25 data

  58. APT34 Event Analysis Report

    date in the title fromORKL

  59. Chirp of the PoisonFrog

    date in the title fromORKL

  60. LYCEUM Takes Center Stage in Middle East Campaign

    date in the title fromORKL

  61. Cyber Threat Group LYCEUM Takes Center Stage in Middle East Campaign

    date in the CCS '25 data SecureWorks fromORKLCCS '25 data

  62. APT_trends_report_Q2_2019_Securelist

    file creation date fromORKL

  63. APT trends report Q2 2019

    date in the title fromORKL

  64. Threat Group Cards: A Threat Actor Encyclopedia

    file creation date ThaiCERT fromORKL

  65. APT34 Tools Leak

    date in the title fromORKL

  66. Threat Group Cards: A Threat Actor Encyclopedia

    file creation date Martijn van der Heide fromORKL

  67. APT34- Jason project

    date in the title fromORKL

  68. APT34 Jason project

    date in the CCS '25 data Marco Ramilli's Blog fromCCS '25 data

  69. APT34- Glimpse project

    date in the title fromORKL

  70. APT34 Glimpse project

    date in the CCS '25 data Marco Ramilli's Blog fromCCS '25 data

  71. Behind the Scenes with OilRig

    date in the title fromORKL

  72. APT34- webmask project

    date in the title fromORKL

  73. DNSpionage brings out the Karkoff

    date in the title fromORKL

  74. APT34 webmask project

    date in the CCS '25 data Marco Ramilli's Blog fromCCS '25 data

  75. Hacking (Back) and Influence Operations

    Malpedia library date fromORKL

  76. rpt-mtrends-2019.pdf

    file creation date fromORKL

  77. Report2019GlobalThreatReport

    file creation date fromORKL

  78. APT Trends report Q2 2017

    file creation date fromORKL

  79. New Python-Based Payload MechaFlounder Used by Chafer

    date in the title fromORKL

  80. rpt-mtrends-2019

    file creation date fromORKL

  81. CrowdStrike_GTR_2019.pdf

    file creation date fromORKL

  82. 2019.01.03.Tencent_APT_Summary_report_2018_CN_Version

    file creation date fromORKL

  83. 2018 Master Table

    file creation date fromORKL

  84. The APT Chronicles_December 2018 edition

    date in the CCS '25 data FireEye fromORKLCCS '25 data

  85. Tunneling Under the Sands

    date in the title fromORKL

  86. HITB-SG-2018-E - In the trails of WINDSHIFT [Autosaved]

    date in the CCS '25 data Bellingcat fromORKLCCS '25 data

  87. M-Trends Overview

    Malpedia library date Marco Rottigni fromORKL

  88. M-TRENDS2018

    file creation date FireEye fromORKL

  89. Researchers Discover New variants of APT34 Malware

    Malpedia library date Booz Allen Hamilton fromORKLCCS '25 data

  90. Researchers Discover New variants of APT34 Malware

    date in the title fromORKL

  91. Industrial Control System Threats

    Malpedia library date Dragos fromORKL

  92. Chafer_ Latest Attacks Reveal Heightened Ambitions _ Symantec Blogs

    date in the CCS '25 data Symantec fromORKLCCS '25 data

  93. Chafer- Latest Attacks Reveal Heightened Ambitions

    date in the title fromORKL

  94. OopsIE! OilRig Uses ThreeDollars to Deliver New Trojan

    date in the title fromORKL

  95. unit42-oilrig-uses-rgdoor-iis-backdoor-targets-middle-east

    file creation date fromORKL

  96. Iran’s Cyber Ecosystem- Who Are the Threat Actors-

    date in the title fromORKL

  97. Iran_Cyber_Final_Full_v2

    file creation date fromORKL

  98. Introducing the Adversary Playbook- First up, OilRig

    date in the title fromORKL

  99. OilRig Performs Tests on the TwoFace Webshell

    date in the title fromORKL

  100. Advanced Persistent Threat Groups

    date in the title fromORKL

  101. A dive into MuddyWater APT targeting Middle-East

    date in the title fromORKL

  102. OilRig Deploys "ALMA Communicator" - DNS Tunneling Trojan

    date in the CCS '25 data Palo Alto Networks fromORKLCCS '25 data

  103. Greenbug

    file creation date fromORKL

  104. Striking Oil- A Closer Look at Adversary Infrastructure

    date in the title fromORKL

  105. OilRig uses ISMDoor variant; Possibly Linked to Greenbug Threat Group

    date in the CCS '25 data Palo Alto fromORKLCCS '25 data

  106. Iranian Fileless Attack Infiltrates Israeli Organizations

    file creation date fromORKL

  107. Iranian Fileless Attack Infiltrates Israeli Organizations

    date in the title fromORKL

  108. Iranian PupyRAT Bites Middle Eastern Organizations

    date in the title fromORKL

  109. Iranian PupyRAT Bites Middle Eastern Organizations

    date in the CCS '25 data Secureworks fromORKLCCS '25 data

  110. Iranian Fileless Attack Infiltrates Israeli Organizations

    date in the CCS '25 data Morphisec fromORKLCCS '25 data

Newest first. Details opens the report in Explore.