TONEDEAF is a Windows backdoor associated with the Iranian espionage actor APT34, also tracked as OilRig. It was observed in 2019 in operations targeting a broad range of organizations in the Middle East, including energy, utilities, government, and oil and gas entities. The malware has also been linked to intrusion activity using social-engineering lures delivered through spoofed professional networking invitations and spearphishing themes.
TONEDEAF communicates with command-and-control infrastructure over HTTP using GET and POST requests. Its core functionality includes collecting basic system information, uploading and downloading files, and executing arbitrary shell commands, making it suitable for interactive post-compromise control and follow-on espionage activity. Reporting also indicates the family included a secondary DNS tunneling communication method, although that capability was described as non-functional in at least one analyzed context.
In documented intrusion chains, TONEDEAF was delivered via a weaponized Excel document containing VBA that reconstructed the payload and established persistence through a scheduled task. The malware was disguised during staging and installation to resemble benign document or system-management content. Its operational use, command execution support, and file-transfer features are consistent with APT34’s long-running intelligence collection campaigns against Middle Eastern targets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
ToneDeaf, which supports collecting system information, uploading and downloading of files, and arbitrary shell command execution, is a malware family that was deployed by the APT34 actor targeting a broad range of industries operating in the Middle East in July 2019.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
The ToneDeaf backdoor primarily communicated with its C&C over HTTP/S but included a secondary method, DNS tunneling, which does not function properly," the researchers said. "Shark has similar symptoms, where its primary communication method uses DNS but has a non-functional HTTP/S secondary option. | Marlin makes use of Microsoft's OneDrive API for its C2 operations.
traditional OilRig TTPs, which have involved the use of DNS and HTTPS for command-and-control (C&C) communications
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor referenced as installed via malicious invitation-themed lures attributed to APT34.
A backdoor used by APT34/OilRig that can collect system information, upload and download files, and execute arbitrary shell commands. It primarily communicated over HTTP/S and included a secondary DNS tunneling method that did not function properly.
Backdoor used by APT34 that communicates with C2 over HTTP (and has code for DNS-based C2/exfiltration, though not enabled in the analyzed sample). Supports system info collection, file upload/download, and arbitrary shell command execution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.