OilRig
Also reported as IRN2, Helix Kitten, Evasive Serpens, Hazel Sandstorm, EUROPIUM and 22 other names. Linked to Iran by three sources.
Reports per quarter
Techniques seen in the last two years
- T1041 6 reports reports only
- T1105 6 reports in ATT&CK
- T1059.003 4 reports in ATT&CK
- T1070.004 4 reports in ATT&CK
- T1071.001 4 reports in ATT&CK
- T1074.001 4 reports reports only
- T1082 4 reports in ATT&CK
- T1112 4 reports in ATT&CK
- T1140 4 reports in ATT&CK
- T1190 4 reports reports only
Show all 277 techniques Show fewer
- T1547.001 4 reports reports only
- T1573.001 4 reports reports only
- T1003.001 3 reports in ATT&CK
- T1008 3 reports in ATT&CK
- T1020 3 reports reports only
- T1021.001 3 reports in ATT&CK
- T1027 3 reports reports only
- T1033 3 reports in ATT&CK
- T1046 3 reports in ATT&CK
- T1047 3 reports in ATT&CK
- T1053 3 reports reports only
- T1059 3 reports in ATT&CK
- T1059.001 3 reports in ATT&CK
- T1102.002 3 reports reports only
- T1132.001 3 reports reports only
- T1490 3 reports reports only
- T1543.003 3 reports in ATT&CK
- T1546 3 reports reports only
- T1566.002 3 reports in ATT&CK
- T1567 3 reports reports only
- T1567.002 3 reports reports only
- T1583 3 reports reports only
- T1608 3 reports reports only
- T1010 2 reports reports only
- T1016 2 reports in ATT&CK
- T1021 2 reports reports only
- T1036.004 2 reports reports only
- T1053.005 2 reports in ATT&CK
- T1055 2 reports reports only
- T1057 2 reports in ATT&CK
- T1059.006 2 reports reports only
- T1059.007 2 reports reports only
- T1069 2 reports reports only
- T1071 2 reports reports only
- T1078 2 reports in ATT&CK
- T1083 2 reports reports only
- T1087 2 reports reports only
- T1090 2 reports reports only
- T1091 2 reports reports only
- T1098 2 reports reports only
- T1102 2 reports reports only
- T1106 2 reports reports only
- T1119 2 reports in ATT&CK
- T1120 2 reports in ATT&CK
- T1134 2 reports reports only
- T1134.001 2 reports reports only
- T1135 2 reports reports only
- T1137 2 reports reports only
- T1189 2 reports reports only
- T1195 2 reports in ATT&CK
- T1204 2 reports reports only
- T1204.001 2 reports in ATT&CK
- T1204.002 2 reports in ATT&CK
- T1213 2 reports reports only
- T1219 2 reports in ATT&CK
- T1480 2 reports reports only
- T1485 2 reports reports only
- T1486 2 reports reports only
- T1489 2 reports reports only
- T1505.003 2 reports in ATT&CK
- T1518.001 2 reports reports only
- T1547.009 2 reports reports only
- T1559 2 reports reports only
- T1560.001 2 reports reports only
- T1566 2 reports reports only
- T1566.001 2 reports in ATT&CK
- T1566.003 2 reports in ATT&CK
- T1569.002 2 reports reports only
- T1571 2 reports reports only
- T1573 2 reports reports only
- T1573.002 2 reports in ATT&CK
- T1574.001 2 reports reports only
- T1583.001 2 reports in ATT&CK
- T1583.003 2 reports reports only
- T1585.002 2 reports reports only
- T1587.001 2 reports in ATT&CK
- T1595.002 2 reports reports only
- T1622 2 reports reports only
- T1001 1 report reports only
- T1003.002 1 report reports only
- T1005 1 report in ATT&CK
- T1007 1 report in ATT&CK
- T1012 1 report in ATT&CK
- T1016.001 1 report reports only
- T1018 1 report reports only
- T1021.002 1 report reports only
- T1021.004 1 report in ATT&CK
- T1021.005 1 report reports only
- T1021.006 1 report reports only
- T1025 1 report in ATT&CK
- T1027.007 1 report reports only
- T1027.009 1 report reports only
- T1027.013 1 report in ATT&CK
- T1030 1 report reports only
- T1036 1 report in ATT&CK
- T1036.005 1 report in ATT&CK
- T1037 1 report reports only
- T1037.001 1 report reports only
- T1039 1 report reports only
- T1040 1 report reports only
- T1048 1 report reports only
- T1048.001 1 report reports only
- T1048.003 1 report in ATT&CK
- T1049 1 report in ATT&CK
- T1053.003 1 report reports only
- T1055.001 1 report reports only
- T1055.002 1 report reports only
- T1055.003 1 report reports only
- T1055.004 1 report reports only
- T1055.009 1 report reports only
- T1055.012 1 report reports only
- T1056 1 report reports only
- T1056.001 1 report in ATT&CK
- T1056.002 1 report reports only
- T1059.002 1 report reports only
- T1059.004 1 report reports only
- T1059.005 1 report in ATT&CK
- T1059.009 1 report reports only
- T1059.010 1 report reports only
- T1059.011 1 report reports only
- T1068 1 report in ATT&CK
- T1069.001 1 report in ATT&CK
- T1069.002 1 report in ATT&CK
- T1069.003 1 report reports only
- T1070 1 report reports only
- T1070.006 1 report reports only
- T1070.009 1 report reports only
- T1071.004 1 report in ATT&CK
- T1072 1 report reports only
- T1074 1 report reports only
- T1074.002 1 report reports only
- T1078.003 1 report reports only
- T1078.004 1 report reports only
- T1087.001 1 report in ATT&CK
- T1087.002 1 report in ATT&CK
- T1087.004 1 report reports only
- T1090.001 1 report reports only
- T1090.003 1 report reports only
- T1095 1 report reports only
- T1098.001 1 report reports only
- T1098.003 1 report reports only
- T1098.004 1 report reports only
- T1098.005 1 report reports only
- T1098.006 1 report reports only
- T1098.007 1 report reports only
- T1104 1 report reports only
- T1113 1 report in ATT&CK
- T1114 1 report reports only
- T1114.001 1 report reports only
- T1114.002 1 report reports only
- T1114.003 1 report reports only
- T1115 1 report in ATT&CK
- T1123 1 report reports only
- T1124 1 report reports only
- T1125 1 report reports only
- T1129 1 report reports only
- T1132 1 report reports only
- T1133 1 report in ATT&CK
- T1134.002 1 report reports only
- T1136 1 report reports only
- T1136.001 1 report reports only
- T1136.002 1 report reports only
- T1137.006 1 report reports only
- T1195.002 1 report reports only
- T1199 1 report reports only
- T1200 1 report reports only
- T1201 1 report in ATT&CK
- T1202 1 report reports only
- T1203 1 report in ATT&CK
- T1210 1 report reports only
- T1213.001 1 report reports only
- T1213.002 1 report reports only
- T1213.003 1 report reports only
- T1217 1 report reports only
- T1218.011 1 report reports only
- T1482 1 report reports only
- T1484 1 report reports only
- T1484.001 1 report reports only
- T1491.002 1 report reports only
- T1496 1 report reports only
- T1497 1 report reports only
- T1497.001 1 report in ATT&CK
- T1497.003 1 report reports only
- T1505 1 report reports only
- T1505.004 1 report reports only
- T1518 1 report reports only
- T1529 1 report reports only
- T1530 1 report reports only
- T1534 1 report reports only
- T1537 1 report reports only
- T1538 1 report reports only
- T1543 1 report reports only
- T1543.002 1 report reports only
- T1543.004 1 report reports only
- T1546.003 1 report reports only
- T1546.004 1 report reports only
- T1546.008 1 report reports only
- T1546.012 1 report reports only
- T1546.015 1 report reports only
- T1547 1 report reports only
- T1547.002 1 report reports only
- T1547.005 1 report reports only
- T1548 1 report reports only
- T1548.002 1 report reports only
- T1550 1 report reports only
- T1550.001 1 report reports only
- T1550.002 1 report reports only
- T1554 1 report reports only
- T1555.003 1 report in ATT&CK
- T1556 1 report reports only
- T1556.006 1 report reports only
- T1556.009 1 report reports only
- T1557 1 report reports only
- T1559.001 1 report reports only
- T1560 1 report reports only
- T1560.002 1 report reports only
- T1560.003 1 report reports only
- T1564.003 1 report reports only
- T1565 1 report reports only
- T1565.001 1 report reports only
- T1566.004 1 report reports only
- T1567.001 1 report reports only
- T1569 1 report reports only
- T1570 1 report reports only
- T1572 1 report in ATT&CK
- T1574 1 report reports only
- T1574.011 1 report reports only
- T1578 1 report reports only
- T1580 1 report reports only
- T1583.004 1 report reports only
- T1583.006 1 report reports only
- T1584 1 report reports only
- T1585 1 report reports only
- T1585.003 1 report reports only
- T1586.002 1 report in ATT&CK
- T1587 1 report reports only
- T1587.003 1 report reports only
- T1588 1 report reports only
- T1588.002 1 report in ATT&CK
- T1588.003 1 report in ATT&CK
- T1588.004 1 report reports only
- T1588.007 1 report reports only
- T1590.005 1 report reports only
- T1591 1 report reports only
- T1592.002 1 report reports only
- T1595 1 report reports only
- T1598 1 report reports only
- T1598.003 1 report reports only
- T1602 1 report reports only
- T1602.001 1 report reports only
- T1602.002 1 report reports only
- T1608.001 1 report in ATT&CK
- T1608.002 1 report reports only
- T1608.003 1 report reports only
- T1608.004 1 report reports only
- T1608.005 1 report reports only
- T1608.006 1 report reports only
- T1613 1 report reports only
- T1614 1 report reports only
- T1614.001 1 report reports only
- T1615 1 report reports only
- T1619 1 report reports only
- T1620 1 report reports only
- T1652 1 report reports only
- T1654 1 report reports only
- T1657 1 report reports only
- T1659 1 report reports only
Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.
Also listed by ATT&CK
CVEs named in reports
- CVE-2007-5633
- CVE-2008-3431 KEV
- CVE-2009-0824
- CVE-2009-0927 KEV
- CVE-2009-3129 KEV
- CVE-2010-0188 KEV ransomware
- CVE-2010-0232 KEV
- CVE-2010-0249 KEV
- CVE-2010-1592
- CVE-2010-3333 KEV
- CVE-2010-4398 KEV
- CVE-2011-0609 KEV
Show all 303 CVEs Show fewer
- CVE-2011-0611 KEV
- CVE-2011-1255
- CVE-2011-2005 KEV
- CVE-2011-2110
- CVE-2011-3544 KEV
- CVE-2011-4369
- CVE-2012-0158 KEV ransomware
- CVE-2012-0422
- CVE-2012-0779
- CVE-2012-1535 KEV
- CVE-2012-1723 KEV ransomware
- CVE-2012-1856 KEV
- CVE-2012-1875
- CVE-2012-1889 KEV
- CVE-2012-4681 KEV ransomware
- CVE-2012-4792 KEV
- CVE-2012-5687
- CVE-2013-0422 KEV ransomware
- CVE-2013-0640 KEV
- CVE-2013-0808
- CVE-2013-1331 KEV
- CVE-2013-1347 KEV
- CVE-2013-1493
- CVE-2013-2618
- CVE-2013-2729 KEV
- CVE-2013-3346 KEV
- CVE-2013-3660 KEV
- CVE-2013-3893 KEV
- CVE-2013-3897 KEV
- CVE-2013-3906 KEV
- CVE-2013-4786
- CVE-2013-4979
- CVE-2013-5065 KEV
- CVE-2013-7331 KEV
- CVE-2014-0322 KEV
- CVE-2014-0497 KEV
- CVE-2014-0515
- CVE-2014-0640
- CVE-2014-1761 KEV
- CVE-2014-1776 KEV
- CVE-2014-4076
- CVE-2014-4113 KEV
- CVE-2014-4114 KEV
- CVE-2014-4404 KEV
- CVE-2014-6332 KEV
- CVE-2014-6352 KEV
- CVE-2014-8361 KEV
- CVE-2014-8439 KEV
- CVE-2014-9583
- CVE-2015-1130 KEV
- CVE-2015-1635 KEV
- CVE-2015-1641 KEV
- CVE-2015-1642 KEV
- CVE-2015-1701 KEV ransomware
- CVE-2015-1805
- CVE-2015-2051 KEV
- CVE-2015-2387 KEV
- CVE-2015-2419 KEV
- CVE-2015-2424 KEV
- CVE-2015-2545 KEV
- CVE-2015-2546 KEV ransomware
- CVE-2015-2590 KEV
- CVE-2015-3043 KEV
- CVE-2015-3105
- CVE-2015-4902 KEV
- CVE-2015-5119 KEV
- CVE-2015-5122 KEV
- CVE-2015-7547
- CVE-2015-7645 KEV ransomware
- CVE-2015-7755 KEV
- CVE-2015-8651 KEV
- CVE-2016-0034 KEV ransomware
- CVE-2016-0147
- CVE-2016-0167 KEV ransomware
- CVE-2016-0189 KEV ransomware
- CVE-2016-0984 KEV
- CVE-2016-1010 KEV
- CVE-2016-1019 KEV ransomware
- CVE-2016-10401
- CVE-2016-3353
- CVE-2016-4117 KEV ransomware
- CVE-2016-4119
- CVE-2016-4171 KEV
- CVE-2016-5195 KEV
- CVE-2016-7255 KEV ransomware
- CVE-2016-7855 KEV
- CVE-2017-0143 KEV ransomware
- CVE-2017-0144 KEV ransomware
- CVE-2017-0146 KEV ransomware
- CVE-2017-0147 KEV ransomware
- CVE-2017-0176
- CVE-2017-0199 KEV ransomware
- CVE-2017-01995
- CVE-2017-0213 KEV ransomware
- CVE-2017-0261 KEV
- CVE-2017-0262 KEV
- CVE-2017-0263 KEV
- CVE-2017-1000353 KEV
- CVE-2017-10271 KEV ransomware
- CVE-2017-1099
- CVE-2017-11292 KEV
- CVE-2017-11317 KEV
- CVE-2017-11357 KEV ransomware
- CVE-2017-11467
- CVE-2017-11774 KEV
- CVE-2017-11882 KEV ransomware
- CVE-2017-12149 KEV ransomware
- CVE-2017-12629
- CVE-2017-12824
- CVE-2017-17215
- CVE-2017-18368 KEV
- CVE-2017-5638 KEV ransomware
- CVE-2017-7269 KEV
- CVE-2017-8570 KEV
- CVE-2017-8759 KEV
- CVE-2017-9248 KEV
- CVE-2017-9822 KEV ransomware
- CVE-2018-0101
- CVE-2018-0171 KEV
- CVE-2018-0296 KEV
- CVE-2018-0798 KEV
- CVE-2018-0802 KEV ransomware
- CVE-2018-10088
- CVE-2018-10561 KEV
- CVE-2018-10562 KEV ransomware
- CVE-2018-11776 KEV
- CVE-2018-13379 KEV ransomware
- CVE-2018-15454
- CVE-2018-1579
- CVE-2018-15961 KEV
- CVE-2018-15982 KEV ransomware
- CVE-2018-20250 KEV ransomware
- CVE-2018-2025036
- CVE-2018-2628 KEV
- CVE-2018-2893
- CVE-2018-4878 KEV ransomware
- CVE-2018-4990 KEV
- CVE-2018-5002 KEV
- CVE-2018-6055
- CVE-2018-7600 KEV ransomware
- CVE-2018-7602 KEV ransomware
- CVE-2018-8120 KEV ransomware
- CVE-2018-8174 KEV ransomware
- CVE-2018-8373 KEV
- CVE-2018-8405 KEV ransomware
- CVE-2018-8406 KEV ransomware
- CVE-2018-8440 KEV ransomware
- CVE-2018-8453 KEV ransomware
- CVE-2018-8589 KEV
- CVE-2018-8611 KEV
- CVE-2018-9866
- CVE-2019-0604 KEV ransomware
- CVE-2019-0708 KEV ransomware
- CVE-2019-0797 KEV
- CVE-2019-0803 KEV ransomware
- CVE-2019-0808 KEV
- CVE-2019-0859 KEV ransomware
- CVE-2019-10149 KEV
- CVE-2019-1132 KEV
- CVE-2019-11510 KEV ransomware
- CVE-2019-11707 KEV
- CVE-2019-11708 KEV
- CVE-2019-1367 KEV ransomware
- CVE-2019-13720 KEV
- CVE-2019-1458 KEV ransomware
- CVE-2019-1579 KEV ransomware
- CVE-2019-1652 KEV
- CVE-2019-1653 KEV
- CVE-2019-17026 KEV
- CVE-2019-17100
- CVE-2019-18935 KEV ransomware
- CVE-2019-19781 KEV ransomware
- CVE-2019-2215 KEV
- CVE-2019-2725 KEV ransomware
- CVE-2019-3568 KEV
- CVE-2019-5786 KEV
- CVE-2019-6225
- CVE-2019-7286 KEV
- CVE-2019-7287 KEV
- CVE-2019-7609 KEV
- CVE-2019-8518
- CVE-2019-9670 KEV
- CVE-2020-0674 KEV
- CVE-2020-0688 KEV ransomware
- CVE-2020-0796 KEV ransomware
- CVE-2020-10148 KEV
- CVE-2020-10189 KEV
- CVE-2020-1472 KEV ransomware
- CVE-2020-14882 KEV
- CVE-2020-1664
- CVE-2020-17144 KEV
- CVE-2020-2021 KEV ransomware
- CVE-2020-3529
- CVE-2020-35730 KEV
- CVE-2020-4006 KEV
- CVE-2020-5135 KEV ransomware
- CVE-2020-5902 KEV ransomware
- CVE-2020-6418 KEV
- CVE-2020-6819 KEV
- CVE-2020-6820 KEV
- CVE-2020-8467 KEV
- CVE-2020-8468 KEV
- CVE-2021-1732 KEV ransomware
- CVE-2021-21148 KEV
- CVE-2021-2114810
- CVE-2021-21972 KEV ransomware
- CVE-2021-22941 KEV ransomware
- CVE-2021-26084 KEV ransomware
- CVE-2021-26334
- CVE-2021-26411 KEV ransomware
- CVE-2021-2641111
- CVE-2021-26855 KEV ransomware
- CVE-2021-26857 KEV ransomware
- CVE-2021-26858 KEV ransomware
- CVE-2021-27065 KEV ransomware
- CVE-2021-27101 KEV ransomware
- CVE-2021-27102 KEV ransomware
- CVE-2021-27103 KEV ransomware
- CVE-2021-30665 KEV
- CVE-2021-30666 KEV
- CVE-2021-31207 KEV ransomware
- CVE-2021-33766 KEV
- CVE-2021-34448 KEV
- CVE-2021-344486
- CVE-2021-34473 KEV ransomware
- CVE-2021-34523 KEV ransomware
- CVE-2021-35211 KEV ransomware
- CVE-2021-36934 KEV
- CVE-2021-38647 KEV ransomware
- CVE-2021-3970
- CVE-2021-3971
- CVE-2021-3972
- CVE-2021-4034 KEV ransomware
- CVE-2021-40539 KEV ransomware
- CVE-2021-44228 KEV ransomware
- CVE-2022-0847 KEV
- CVE-2022-1040 KEV
- CVE-2022-1388 KEV ransomware
- CVE-2022-22954 KEV ransomware
- CVE-2022-22960 KEV
- CVE-2022-22963 KEV
- CVE-2022-22965 KEV
- CVE-2022-26134 KEV ransomware
- CVE-2022-27926 KEV
- CVE-2022-30190 KEV ransomware
- CVE-2022-42475 KEV ransomware
- CVE-2022-47966 KEV ransomware
- CVE-2022-47986 KEV ransomware
- CVE-2023-0669 KEV ransomware
- CVE-2023-20198 KEV
- CVE-2023-20269 KEV ransomware
- CVE-2023-20273 KEV
- CVE-2023-22515 KEV ransomware
- CVE-2023-22518 KEV ransomware
- CVE-2023-23397 KEV
- CVE-2023-27350 KEV ransomware
- CVE-2023-27351 KEV ransomware
- CVE-2023-27532 KEV ransomware
- CVE-2023-2868 KEV
- CVE-2023-28771 KEV
- CVE-2023-34048 KEV
- CVE-2023-34362 KEV ransomware
- CVE-2023-3466
- CVE-2023-3467
- CVE-2023-3519 KEV ransomware
- CVE-2023-36033 KEV
- CVE-2023-36884 KEV ransomware
- CVE-2023-38831 KEV ransomware
- CVE-2023-40044 KEV ransomware
- CVE-2023-42793 KEV ransomware
- CVE-2023-46604 KEV ransomware
- CVE-2023-46805 KEV ransomware
- CVE-2023-47246 KEV ransomware
- CVE-2023-48788 KEV ransomware
- CVE-2023-4911 KEV
- CVE-2023-4966 KEV ransomware
- CVE-2023-50164
- CVE-2023-5631 KEV
- CVE-2024-0012 KEV ransomware
- CVE-2024-11182 KEV
- CVE-2024-1709 KEV ransomware
- CVE-2024-21413 KEV
- CVE-2024-21887 KEV ransomware
- CVE-2024-21893 KEV ransomware
- CVE-2024-21983
- CVE-2024-30088 KEV ransomware
- CVE-2024-3400 KEV ransomware
- CVE-2024-47575 KEV
- CVE-2024-49039 KEV ransomware
- CVE-2024-9474 KEV ransomware
- CVE-2024-9680 KEV ransomware
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor UNIT 42 PLAYBOOK VIEWER
-
New Destructive Wiper ZeroCleare Targets Energy Sector in the Middle East
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor New Destructive Wiper ZeroCleare Targets Energy Sector in the Middle East
Show all 403 reports Show fewer
-
Subgroup: [Unnamed group USA] - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Subgroup: [Unnamed group USA] - Threat Group Cards: A Threat Actor Encyclopedia
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor DistTrack (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Helix Kitten
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
Subgroup: Greenbug, Volatile Kitten - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Subgroup: Greenbug, Volatile Kitten - Threat Group Cards: A Threat Actor Encyclopedia
-
APT 33, Elfin, Magnallium - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor APT 33, Elfin, Magnallium - Threat Group Cards: A Threat Actor Encyclopedia
-
The original link failed its last check. Original publisher Detailsfor Council on Foreign Relations
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Charming Kitten
-
Targeted Attacks against Banks in the Middle East
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor Targeted Attacks against Banks in the Middle East
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor TwoFace (Malware Family)
-
Chafer, APT 39 - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Chafer, APT 39 - Threat Group Cards: A Threat Actor Encyclopedia
-
OilRig, APT 34, Helix Kitten, Chrysene
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor OilRig, APT 34, Helix Kitten, Chrysene
-
Researchers Discover New variants of APT34 Malware
The original link failed its last check. Original publisher Detailsfor Researchers Discover New variants of APT34 Malware
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor BONDUPDATER (Malware Family)
-
The original link failed its last check. Original publisher Detailsfor Talks - BrightTALK
-
The Israel-Hamas War | Cyber Domain State-Sponsored Activity of Interest
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor The Israel-Hamas War | Cyber Domain State-Sponsored Activity of Interest
-
The original link failed its last check. Original publisher Detailsfor Untitled
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor watchtower-2023-eoy-report-en
-
OilRig's persistent attacks using cloud service-powered downloaders
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor OilRig's persistent attacks using cloud service-powered downloaders
-
From Albania To The Middle East: The Scarred Manticore Is Listening
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor From Albania To The Middle East: The Scarred Manticore Is Listening
-
From Albania to the Middle East_ The Scarred Manticore is Listening - Check Point Research
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor From Albania to the Middle East_ The Scarred Manticore is Listening - Check Point Research
-
New APT34 Malware Targets The Middle East
The original link failed its last check. Original publisher Detailsfor New APT34 Malware Targets The Middle East
-
New APT34 Malware Targets The Middle East
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor New APT34 Malware Targets The Middle East
-
New APT34 Malware Targets The Middle East
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New APT34 Malware Targets The Middle East
-
More Than Meets the Eye- Exposing a Polyglot File That Delivers IcedID
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor More Than Meets the Eye- Exposing a Polyglot File That Delivers IcedID
-
Microsoft investigates Iranian attacks against the Albanian government
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Microsoft investigates Iranian attacks against the Albanian government
-
Advanced Persistent Threats (APTs)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Advanced Persistent Threats (APTs)
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT trends report Q2 2020
-
Burned and Blinded - Escalation Risks of Intelligence Loss from Countercyber Operations in Crisis
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Burned and Blinded - Escalation Risks of Intelligence Loss from Countercyber Operations in Crisis
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT34 - Saitama Agent
-
Translating Saitama's DNS tunneling messages
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Translating Saitama's DNS tunneling messages
-
THALES%20THREAT%20HANDBOOK%202022%20Light%20Version_1.pdf
The original link failed its last check. Original publisher Detailsfor THALES%20THREAT%20HANDBOOK%202022%20Light%20Version_1.pdf
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor eset_threat_report_t12022
-
Please Confirm You Received Our APT
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Please Confirm You Received Our APT
-
APT34 targets Jordan Government using new Saitama backdoor
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT34 targets Jordan Government using new Saitama backdoor
-
Social Engineering Remains Key Tradecraft for Iranian APTs
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Social Engineering Remains Key Tradecraft for Iranian APTs
-
Iranian Hackers Using New Marlin Backdoor in 'Out to Sea' Espionage Campaign
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Iranian Hackers Using New Marlin Backdoor in 'Out to Sea' Espionage Campaign
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor eset_threat_report_t32021
-
Evolving trends in Iranian threat actor activity – MSTIC presentation at CyberWarCon 2021
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Evolving trends in Iranian threat actor activity – MSTIC presentation at CyberWarCon 2021
-
Global_APT_Research_Report_for_the_first_half_of_2021-360
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Global_APT_Research_Report_for_the_first_half_of_2021-360
-
Masters of Mimicry: new APT group ChamelGang and its arsenal
The original link failed its last check. Original publisher Detailsfor Masters of Mimicry: new APT group ChamelGang and its arsenal
-
Advanced Persistent Threats (APTs)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Advanced Persistent Threats (APTs)
-
An Overview of FinTech Threat Landscape
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor An Overview of FinTech Threat Landscape
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Pay2Kitten report
-
Ongoing Campaign Leveraging Exchange Vulnerability Potentially Linked to Iran
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Ongoing Campaign Leveraging Exchange Vulnerability Potentially Linked to Iran
-
Geopolitical nation-state threat actor overview June 2021
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Geopolitical nation-state threat actor overview June 2021
-
The blurry boundaries between nation-state actors and the cybercrime underground
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The blurry boundaries between nation-state actors and the cybercrime underground
-
The original link failed its last check. Original publisher Detailsfor mtrends-2018.pdf
-
Prometei Botnet Exploiting Microsoft Exchange Vulnerabilities
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Prometei Botnet Exploiting Microsoft Exchange Vulnerabilities
-
Iran’s APT34 Returns with an Updated Arsenal
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Iran’s APT34 Returns with an Updated Arsenal
-
Iran’s APT34 Returns with an Updated Arsenal - Check Point Research
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Iran’s APT34 Returns with an Updated Arsenal - Check Point Research
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor LazyScripter
-
The_CrowdStrike_2021_Global_Threat_Report
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The_CrowdStrike_2021_Global_Threat_Report
-
https---www.ptsecurity.com-ww-en-analytics-antisandbox-techniques-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor https---www.ptsecurity.com-ww-en-analytics-antisandbox-techniques-
-
The original link failed its last check. Original publisher Detailsfor Analytics
-
SolarWinds- How a Rare DGA Helped Attacker Communications Fly Under the Radar
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor SolarWinds- How a Rare DGA Helped Attacker Communications Fly Under the Radar
-
Identifying Critical Infrastructure Targeting through Network Creation
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Identifying Critical Infrastructure Targeting through Network Creation
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ATR_82599
-
Group-IB_Hi-Tech_Crime_Trends_2020-2021_en
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Group-IB_Hi-Tech_Crime_Trends_2020-2021_en
-
Iranian hackers are selling access to compromised companies on an underground forum
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Iranian hackers are selling access to compromised companies on an underground forum
-
FBI says an Iranian hacking group is attacking F5 networking devices
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor FBI says an Iranian hacking group is attacking F5 networking devices
-
APT_trends_report_Q2_2020_Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT_trends_report_Q2_2020_Securelist
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT trends report Q2 2020
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor OilRig Targets Middle Eastern Telecommunications Organization and Adds Novel C2 Channel with Steganography to Its Inventory
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor OilRig Targets Middle Eastern Telecommunications Organization and Adds Novel C2 Channel with Steganography to Its Inventory
-
OilRig APT Drills into Malware Innovation with Unique Backdoor
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor OilRig APT Drills into Malware Innovation with Unique Backdoor
-
SCANdalous! (External Detection Using Network Scan Data and Automation)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor SCANdalous! (External Detection Using Network Scan Data and Automation)
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 0628-2020APT上半年报告-画册
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Suspected Naikon DGA Domains
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ESET_Turla_ComRAT
-
Sophisticated Espionage Group Turns Attention to Telecom Providers in South Asia _ Symantec Blogs
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Sophisticated Espionage Group Turns Attention to Telecom Providers in South Asia _ Symantec Blogs
-
Sophisticated Espionage Group Turns Attention to Telecom Providers in South Asia
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Sophisticated Espionage Group Turns Attention to Telecom Providers in South Asia
-
Report2020CrowdStrikeGlobalThreatReport
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Report2020CrowdStrikeGlobalThreatReport
-
The North Korean Kimsuky APT keeps threatening South Korea evolving its TTPs
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The North Korean Kimsuky APT keeps threatening South Korea evolving its TTPs
-
apt34-aka-oilrig-attacks-lebanon-government-entities-with-maildropper-implant
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor apt34-aka-oilrig-attacks-lebanon-government-entities-with-maildropper-implant
-
Karkoff 2020- a new APT34 espionage operation involves Lebanon Government
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Karkoff 2020- a new APT34 espionage operation involves Lebanon Government
-
Karkoff 2020 a new APT34 espionage operation involves Lebanon Government
The original link failed its last check. Detailsfor Karkoff 2020 a new APT34 espionage operation involves Lebanon Government
-
The ICS Threat Landscape and Activity Groups
The original link failed its last check. Original publisher Detailsfor The ICS Threat Landscape and Activity Groups
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Fox Kittens report 16.2.2020
-
2020.02.22_APT_threat_report_2019_CN_version
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 2020.02.22_APT_threat_report_2019_CN_version
-
New Iranian Campaign Tailored to US Companies Utilizes an Updated Toolset
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New Iranian Campaign Tailored to US Companies Utilizes an Updated Toolset
-
xHunt Campaign- New Watering Hole Identified for Credential Harvesting
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor xHunt Campaign- New Watering Hole Identified for Credential Harvesting
-
Current Iran-Associated Cyber Threats
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Current Iran-Associated Cyber Threats
-
IBM X-Force IRIS ZeroCleare - Tehcnical Paper
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor IBM X-Force IRIS ZeroCleare - Tehcnical Paper
-
Iranian Threat Actors- Preliminary Analysis
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Iranian Threat Actors- Preliminary Analysis
-
Iranian Cyber Response to Death of IRGC Head Would Likely Use Reported TTPs and Previous Access
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Iranian Cyber Response to Death of IRGC Head Would Likely Use Reported TTPs and Previous Access
-
North American Electric Cyber Threat Perspective
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor North American Electric Cyber Threat Perspective
-
Drilling Deep: A Look at Cyberattacks on the Oil and Gas Industry
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Drilling Deep: A Look at Cyberattacks on the Oil and Gas Industry
-
Group-IB_Hi-Tech_Crime_Trends_2019-2020_en
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Group-IB_Hi-Tech_Crime_Trends_2019-2020_en
-
Microsoft Word - New Destructive Wiper ZeroCleare v1 MLM comments.docx
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Microsoft Word - New Destructive Wiper ZeroCleare v1 MLM comments.docx
-
Group-IB_Hi-Tech_Crime_Trends_2019-2020
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Group-IB_Hi-Tech_Crime_Trends_2019-2020
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT34 Event Analysis Report
-
ReverseEngineering_SecurityReport_EN_2019.10.16-2.pdf
The original link failed its last check. Original publisher Detailsfor ReverseEngineering_SecurityReport_EN_2019.10.16-2.pdf
-
xHunt Campaign- Attacks on Kuwait Shipping and Transportation Organizations
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor xHunt Campaign- Attacks on Kuwait Shipping and Transportation Organizations
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Chirp of the PoisonFrog
-
Tortoiseshell Group Targets IT Providers in Saudi Arabia in Probable Supply Chain Attacks
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Tortoiseshell Group Targets IT Providers in Saudi Arabia in Probable Supply Chain Attacks
-
Tortoiseshell Group Targets IT Providers in Saudi Arabia in Probable Supply Chain Attacks
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Tortoiseshell Group Targets IT Providers in Saudi Arabia in Probable Supply Chain Attacks
-
Tortoiseshell Group Targets IT Providers in Saudi Arabia in Probable Supply Chain Attacks
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Tortoiseshell Group Targets IT Providers in Saudi Arabia in Probable Supply Chain Attacks
-
LYCEUM Takes Center Stage in Middle East Campaign
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor LYCEUM Takes Center Stage in Middle East Campaign
-
Cyber Threat Group LYCEUM Takes Center Stage in Middle East Campaign
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Cyber Threat Group LYCEUM Takes Center Stage in Middle East Campaign
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT34- The Helix Kitten Cybercriminal Group Loves to Meow Middle Eastern and International Organizations
-
APT_trends_report_Q2_2019_Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT_trends_report_Q2_2019_Securelist
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT trends report Q2 2019
-
Dragos - Global Oil and Gas Cyber Threat Perspctive
The original link failed its last check. Original publisher Detailsfor Dragos - Global Oil and Gas Cyber Threat Perspctive
-
Hard Pass_ Declining APT34’s Invite to Join Their Professional Network
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Hard Pass_ Declining APT34’s Invite to Join Their Professional Network
-
Hard Pass- Declining APT34’s Invite to Join Their Professional Network
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Hard Pass- Declining APT34’s Invite to Join Their Professional Network
-
Hard Pass: Declining APT34's Invite to Join Their Professional Network
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Hard Pass: Declining APT34's Invite to Join Their Professional Network
-
Threat Group Cards: A Threat Actor Encyclopedia
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
Waterbug_ Espionage Group Rolls Out Brand-New Toolset in Attacks Against Governments
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Waterbug_ Espionage Group Rolls Out Brand-New Toolset in Attacks Against Governments
-
Waterbug- Espionage Group Rolls Out Brand-New Toolset in Attacks Against Governments
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Waterbug- Espionage Group Rolls Out Brand-New Toolset in Attacks Against Governments
-
Waterbug: Espionage Group Rolls Out Brand-New Toolset in Attacks Against Governments
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Waterbug: Espionage Group Rolls Out Brand-New Toolset in Attacks Against Governments
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT34 Tools Leak
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT34- Jason project
-
The original link failed its last check. Detailsfor APT34 Jason project
-
New leaks of Iranian cyber-espionage operations hit Telegram and the Dark Web
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New leaks of Iranian cyber-espionage operations hit Telegram and the Dark Web
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT34- Glimpse project
-
Raw Threat Intelligence 2019-04-30- Oilrig data dump link analysis
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Raw Threat Intelligence 2019-04-30- Oilrig data dump link analysis
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Behind the Scenes with OilRig
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT34- webmask project
-
DNSpionage brings out the Karkoff
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor DNSpionage brings out the Karkoff
-
The original link failed its last check. Detailsfor APT34 webmask project
-
Hacking (Back) and Influence Operations
The original link failed its last check. Original publisher Detailsfor Hacking (Back) and Influence Operations
-
DNS Tunneling in the Wild- Overview of OilRig’s DNS Tunneling
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor DNS Tunneling in the Wild- Overview of OilRig’s DNS Tunneling
-
The original link failed its last check. Original publisher Detailsfor rpt-mtrends-2019.pdf
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Report2019GlobalThreatReport
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT Trends report Q2 2017
-
New Python-Based Payload MechaFlounder Used by Chafer
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New Python-Based Payload MechaFlounder Used by Chafer
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor rpt-mtrends-2019
-
The original link failed its last check. Original publisher Detailsfor CrowdStrike_GTR_2019.pdf
-
yir-ics-activity-groups-threat-landscape-2018.pdf
The original link failed its last check. Original publisher Detailsfor yir-ics-activity-groups-threat-landscape-2018.pdf
-
2019.01.03.Tencent_APT_Summary_report_2018_CN_Version
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 2019.01.03.Tencent_APT_Summary_report_2018_CN_Version
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 2018 Master Table
-
APT39- An Iranian Cyber Espionage Group Focused on Personal Information
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT39- An Iranian Cyber Espionage Group Focused on Personal Information
-
The APT Chronicles_December 2018 edition
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The APT Chronicles_December 2018 edition
-
Meet CrowdStrike’s Adversary of the Month for November- HELIX KITTEN
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Meet CrowdStrike’s Adversary of the Month for November- HELIX KITTEN
-
Analyzing OilRig’s Ops Tempo from Testing to Weaponization to Delivery
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Analyzing OilRig’s Ops Tempo from Testing to Weaponization to Delivery
-
CDS2018-Technical-S3-You've Got Mail_clean
The original link failed its last check. Original publisher Detailsfor CDS2018-Technical-S3-You've Got Mail_clean
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Tunneling Under the Sands
-
OilRig Uses Updated BONDUPDATER to Target Middle Eastern Government
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor OilRig Uses Updated BONDUPDATER to Target Middle Eastern Government
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor OilRig Targets a Middle Eastern Government and Adds Evasion Techniques to OopsIE - Palo Alto Networks Blog
-
HITB-SG-2018-E - In the trails of WINDSHIFT [Autosaved]
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor HITB-SG-2018-E - In the trails of WINDSHIFT [Autosaved]
-
Accenture-Cyber-Threatscape-Report-2018.pdf
The original link failed its last check. Original publisher Detailsfor Accenture-Cyber-Threatscape-Report-2018.pdf
-
OilRig Targets Technology Service Provider and Government Agency with QUADAGENT
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor OilRig Targets Technology Service Provider and Government Agency with QUADAGENT
-
Researchers Discover New variants of APT34 Malware
The original link failed its last check. Original publisher Detailsfor Researchers Discover New variants of APT34 Malware
-
Researchers Discover New variants of APT34 Malware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Researchers Discover New variants of APT34 Malware
-
Industrial Control System Threats
The original link failed its last check. Original publisher Detailsfor Industrial Control System Threats
-
Chafer_ Latest Attacks Reveal Heightened Ambitions _ Symantec Blogs
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Chafer_ Latest Attacks Reveal Heightened Ambitions _ Symantec Blogs
-
Chafer- Latest Attacks Reveal Heightened Ambitions
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Chafer- Latest Attacks Reveal Heightened Ambitions
-
OopsIE! OilRig Uses ThreeDollars to Deliver New Trojan
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor OopsIE! OilRig Uses ThreeDollars to Deliver New Trojan
-
unit42-oilrig-uses-rgdoor-iis-backdoor-targets-middle-east
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor unit42-oilrig-uses-rgdoor-iis-backdoor-targets-middle-east
-
OilRig uses RGDoor IIS Backdoor on Targets in the Middle East
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor OilRig uses RGDoor IIS Backdoor on Targets in the Middle East
-
Iran’s Cyber Ecosystem- Who Are the Threat Actors-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Iran’s Cyber Ecosystem- Who Are the Threat Actors-
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Iran_Cyber_Final_Full_v2
-
Introducing the Adversary Playbook- First up, OilRig
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Introducing the Adversary Playbook- First up, OilRig
-
OilRig Performs Tests on the TwoFace Webshell
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor OilRig Performs Tests on the TwoFace Webshell
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New Targeted Attack in the Middle East by APT34, a Suspected Iranian Threat Group, Using CVE-2017-11882 Exploit
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor New Targeted Attack in the Middle East by APT34, a Suspected Iranian Threat Group, Using CVE-2017-11882 Exploit « New Targeted Attack in the Middle East by APT34, a Suspected Iranian Threat Group, Using CVE-2017-11882 Exploit | FireEye Inc
-
Advanced Persistent Threat Groups
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Advanced Persistent Threat Groups
-
A dive into MuddyWater APT targeting Middle-East
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor A dive into MuddyWater APT targeting Middle-East
-
OilRig Deploys "ALMA Communicator" - DNS Tunneling Trojan
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor OilRig Deploys "ALMA Communicator" - DNS Tunneling Trojan
-
OilRig Deploys “ALMA Communicator” – DNS Tunneling Trojan
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor OilRig Deploys “ALMA Communicator” – DNS Tunneling Trojan
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Greenbug
-
Iranian Threat Agent Greenbug Impersonates Israeli High-Tech and Cyber Security Companies
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Iranian Threat Agent Greenbug Impersonates Israeli High-Tech and Cyber Security Companies
-
OilRig Group Steps Up Attacks with New Delivery Documents and New Injector Trojan
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor OilRig Group Steps Up Attacks with New Delivery Documents and New Injector Trojan
-
Striking Oil- A Closer Look at Adversary Infrastructure
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Striking Oil- A Closer Look at Adversary Infrastructure
-
With Fake News And Femmes Fatales, Iran's Spies Learn To Love Facebook
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor With Fake News And Femmes Fatales, Iran's Spies Learn To Love Facebook
-
The Curious Case of Mia Ash- Fake Persona Lures Middle Eastern Targets
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Curious Case of Mia Ash- Fake Persona Lures Middle Eastern Targets
-
OilRig Uses ISMDoor Variant; Possibly Linked to Greenbug Threat Group
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor OilRig Uses ISMDoor Variant; Possibly Linked to Greenbug Threat Group
-
OilRig uses ISMDoor variant; Possibly Linked to Greenbug Threat Group
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor OilRig uses ISMDoor variant; Possibly Linked to Greenbug Threat Group
-
Iranian Hackers Have Been Infiltrating Critical Infrastructure Companies
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Iranian Hackers Have Been Infiltrating Critical Infrastructure Companies
-
Shamoon Collaborator Greenbug Adopts New Communication Tool
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Shamoon Collaborator Greenbug Adopts New Communication Tool
-
Iranian Fileless Attack Infiltrates Israeli Organizations
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Iranian Fileless Attack Infiltrates Israeli Organizations
-
Iranian Fileless Attack Infiltrates Israeli Organizations
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Iranian Fileless Attack Infiltrates Israeli Organizations
-
OilRig Actors Provide a Glimpse into Development and Testing Efforts
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor OilRig Actors Provide a Glimpse into Development and Testing Efforts
-
Iranian PupyRAT Bites Middle Eastern Organizations | SecureWorks
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Iranian PupyRAT Bites Middle Eastern Organizations | SecureWorks
-
Shamoon- Multi-staged destructive attacks limited to specific targets
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Shamoon- Multi-staged destructive attacks limited to specific targets
-
Iranian PupyRAT Bites Middle Eastern Organizations
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Iranian PupyRAT Bites Middle Eastern Organizations
-
Inside OilRig -- Tracking Iran's Busiest Hacker Crew On Its Global Rampage
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Inside OilRig -- Tracking Iran's Busiest Hacker Crew On Its Global Rampage
-
Iranian PupyRAT Bites Middle Eastern Organizations
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Iranian PupyRAT Bites Middle Eastern Organizations
-
Greenbug cyberespionage group targeting Middle East, possible links to Shamoon
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor Greenbug cyberespionage group targeting Middle East, possible links to Shamoon
-
Greenbug cyberespionage group targeting Middle East, possible links to Shamoon
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Greenbug cyberespionage group targeting Middle East, possible links to Shamoon
-
Iranian Fileless Attack Infiltrates Israeli Organizations
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Iranian Fileless Attack Infiltrates Israeli Organizations
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Iranian Threat Agent OilRig Delivers Digitally Signed Malware, Impersonates University of Oxford _ ClearSky Cybersecurity
-
OilRig Malware Campaign Updates Toolset and Expands Targets
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor OilRig Malware Campaign Updates Toolset and Expands Targets
-
The OilRig Campaign- Attacks on Saudi Arabian Organizations Deliver Helminth Backdoor
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The OilRig Campaign- Attacks on Saudi Arabian Organizations Deliver Helminth Backdoor
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The OilRig Campaign: Attacks on Saudi Arabian Organizations Deliver Helminth Backdoor - Palo Alto Networks BlogPalo Alto Networks Blog
-
APT34 Deploys Phishing Attack With New Malware
The original link failed its last check. Original publisher Detailsfor APT34 Deploys Phishing Attack With New Malware
Newest first. Details opens the report in Explore.