The term 'apt34_malware' refers to malware attributed to the Iranian APT34 (Oilrig) group, a state-sponsored cyber-espionage actor. While the provided content does not include actual malware source code, it references previous leaks (notably by the pseudonym Lab Dookhtegam) that exposed APT34 malware source code and operational data. APT34 is known for targeting a wide range of industries, including airlines, travel booking sites, insurance, IT, telecom firms, and government agencies worldwide. Their campaigns have focused on data theft, such as retrieving passenger manifests, reservations, and payment card numbers. The group has also attempted, though unsuccessfully, to develop malware targeting SCADA industrial control systems. The leaks have included images of source code, C2 server backends, and victim lists, but not the binaries or full source code for the malware itself. The exposure of these operational details has forced APT34 and related Iranian groups to re-tool and delay future operations. Indicators of compromise are not directly mentioned in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.