Veaty is a backdoor associated with Iranian cyber-espionage activity, particularly operations attributed to APT34, also known as OilRig, with reporting placing its use in campaigns against Iraqi government entities and other government targets in the Gulf region. It has been referenced as part of the broader Project CAV3RN malware ecosystem alongside other backdoors and communication components used in modular post-compromise operations. Detection reporting indicates Veaty is implemented as an MSIL executable and includes email-based command-and-control functionality. Its documented role is consistent with covert remote access and operator tasking in targeted intrusions conducted for espionage purposes. Available reporting does not provide enough high-confidence technical detail to support a more granular characterization of its internal capabilities beyond its use as a backdoor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Use of compromised infrastructure belonging to entities in regions it targets, as observed in Solar and Veaty malware
7 distinct techniques documented for this family, organized by ATT&CK tactic.
Finally, for command and control and exfiltration, Iranian-linked groups most commonly rely on application layer protocols (T1071), such as HTTP
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as comparative malware associated with use of compromised regional infrastructure.
Named backdoor listed among malware/tools, without substantive discussion in this reference.
APT34 backdoor used in multi-stage intrusion campaigns against Iraqi government entities.
MSIL-based backdoor for Windows, using email as a command and control channel.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.