Saitama is a .NET backdoor associated with the Iranian espionage group APT34, also known as OilRig. It is notable for using DNS tunneling as its command-and-control channel, encapsulating victim-to-operator communications in DNS traffic rather than relying on more conventional web protocols. A distinctive implementation detail is its use of IPv4 address responses to encode operator commands, with octets representing ASCII values, instead of using larger DNS record types commonly seen in other DNS tunneling malware.
Saitama has been used in targeted intrusion activity against Middle Eastern entities, including government organizations, and has been observed in operations against Jordanian foreign ministry targets in 2022. Reporting links its deployment to phishing campaigns in which malicious Microsoft Excel documents containing VBA macros acted as the first-stage dropper for the backdoor. In these operations, the macro-based lure delivered the .NET payload onto Windows systems.
The malware supports covert command-and-control over DNS and can transmit host information to its operators through multiple DNS requests, demonstrating an exfiltration capability in addition to remote access functionality. Its tradecraft aligns with APT34’s long-running cyber-espionage activity against government, financial, energy, chemical, and telecommunications sectors, particularly in the Middle East. Saitama forms part of a broader post-2019 evolution in APT34 tooling alongside families such as RDAT and SideTwist, reflecting the group’s effort to refresh its arsenal and reduce detection while maintaining access to regional government and enterprise targets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Saitama is a backdoor that uses the DNS protocol to encapsulate its command and control (C2) messages - a technique known as DNS Tunneling.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
Saitama is a backdoor that uses the DNS protocol to encapsulate its command and control (C2) messages.
Saitama is a backdoor that uses the DNS protocol to encapsulate its command and control (C2) messages - a technique known as DNS Tunneling (MITRE ATT&CK T1071).
the new attack implemented in the group’s latest deployment is a .Net dropper that drops the actual malware.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as one of the newer attack tools developed by APT34 after 2019; no further functionality is described in this content.
Backdoor malware used by Oilrig for espionage operations, providing persistent access to targeted systems.
A .NET backdoor used by APT34, delivered via VBA macro in Excel files as part of phishing-based initial access, with final stages leveraging Microsoft Exchange Web Services Managed API.
A backdoor that uses DNS tunneling for command-and-control, hiding C2 traffic in DNS queries and encoding commands in returned IPv4 addresses rather than TXT records. It can exfiltrate host data such as Windows version information in segmented DNS requests.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.