LONGWATCH is a Windows malware family associated with the Iranian state-aligned threat actor APT34, also known as OilRig. It has been documented in espionage operations targeting organizations in sectors including government, energy, utilities, and oil and gas, particularly in the Middle East. LONGWATCH has been described both as a keylogging tool used by OilRig and as a Pickpocket-related credential theft utility, indicating overlap between keystroke capture and browser-focused credential collection in the tooling attributed to this cluster.
Its primary confirmed behavior is keylogging: LONGWATCH records user keystrokes and stores them locally for later collection. Reporting also links it to browser credential theft activity and describes it as a Pickpocket variant in some campaigns, suggesting use for harvesting credentials from victim systems as part of broader intelligence collection. LONGWATCH appeared alongside other APT34 malware families in a 2019 phishing operation that used social engineering personas and malicious documents to compromise targets.
The malware is part of OilRig’s broader post-compromise collection toolkit, supporting credential access and surveillance on infected hosts. Its use is consistent with APT34 tradecraft centered on spearphishing-led initial access, followed by deployment of custom Windows malware for persistence, credential theft, and espionage.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
OilRig has used keylogging tools called KEYPUNCH and LONGWATCH.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
Most recently in June 2019, a phishing campaign was observed asking victims to join their social network. This time the group masqueraded as a Cambridge University lecturer, also setting up a LinkedIn page in order to gain victims’ trust.
They use phishing emails to deliver weaponized Microsoft Excel documents... Between 2014 to 2016, the group's attack campaigns targeted banks and technology organizations in Saudi Arabia with phishing emails that included weaponized Microsoft Excel attachments.
14 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Keylogging tool used to capture keystrokes.
A Pickpocket variant used for browser credential theft.
Keylogger used by APT34 that records keystrokes (and related key state strings) to c:\windows\temp\log.txt.
Keylogging tool used in operations attributed to OilRig.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.