OilRig is an Iranian state-linked cyber espionage threat actor widely tracked as APT34 and assessed to be associated with Iran’s Ministry of Intelligence and Security (MOIS). The group has also been reported under aliases including Helix Kitten, Hazel Sandstorm, Cobalt Gypsy, Crambus, Europium, Evasive Serpens, Earth Simnavaz, IRN2, ITG13, and TA452. Lyceum, also known as Hexane and SiameseKitten, is commonly assessed as a subgroup or closely related cluster within the broader OilRig ecosystem. OilRig primarily conducts espionage and access operations against organizations in the Middle East, with repeated reporting on activity affecting government, energy, telecommunications, financial, transportation, chemical, and aerospace sectors. The group has also been linked to operations targeting Israeli organizations and service-provider ecosystems, including campaigns in which compromised IT providers were used to reach downstream victims. The actor is known for extensive use of spearphishing, credential theft, and abuse of trusted administrative mechanisms for initial access and follow-on compromise. OilRig has a long-standing preference for PowerShell-heavy tradecraft and frequent use of living-off-the-land techniques. Reported behaviors include execution via PowerShell, abuse of signed Windows binaries such as Regsvr32 and Certutil, system and host discovery using commands such as hostname and systeminfo, registry discovery to identify remote access artifacts and environment details, and checks for attached peripherals as part of victim profiling or anti-analysis. OilRig has developed and operated multiple custom malware and command-and-control frameworks over time. Public reporting has associated the group with Poison Frog and its successor Glimpse, including DNS-based command-and-control, as well as later activity overlapping with the Cavern framework and related tooling. More recent reporting has noted low-confidence overlaps between OilRig-linked Lyceum activity and malware families such as HOLLOWGRAPH, a Windows implant that abuses Microsoft 365 and Microsoft Graph API workflows for covert tasking and exfiltration. Separate Iran-nexus activity tracked as Cavern Manticore has shown technical overlap with Lyceum and broader OilRig tradecraft, particularly in modular .NET-based post-exploitation tooling, supply-chain-style delivery through enterprise software deployment paths, and targeting of Israeli government and IT-sector entities. Operationally, OilRig emphasizes stealthy post-compromise persistence, modular tooling, credential access, reconnaissance, and data theft. The group has repeatedly leveraged native administration features, remote management tooling, and staged module loading to reduce forensic visibility and tailor capabilities to victim environments. Its activity fits the pattern of a mature Iranian intelligence collection actor focused on long-term access, regional strategic targeting, and adaptable intrusion tradecraft rather than disruptive or destructive operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
59 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
53 malware families attributed to this actor across reporting.
48 additional families tracked in Mallory.
12 CVEs this actor has used in observed campaigns. 12 of them exploited in the wild.
OilRig has exploited CVE-2024-30088 to run arbitrary code in the context of SYSTEM .
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
we did produce two reports revolving around the use of a zero-day exploit (CVE-2017-0199). The most notable involved an actor we refer to as BlackOasis and their usage of the exploit in-the-wild prior to its discovery.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
7 more CVEs tied to this actor tracked in Mallory.
202 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Iranian threat actor referenced as the parent cluster of Lyceum; included as contextual attribution background rather than the confirmed operator of this campaign.
Referenced only as the parent group of Lyceum in attribution context for Cavern Manticore.
Referenced as the larger Iran-linked threat actor organization to which Lyceum is described as a subgroup, in connection with possible ties to Cavern Manticore.
Threat actor referenced because Lyceum is assessed to be a subgroup within it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.