Karkoff is a lightweight, modular .NET backdoor associated with the Iranian espionage group APT34, also known as OilRig, Helix Kitten, and Greenbug. It has been used in cyber-espionage operations targeting government and other strategic organizations in the Middle East, with reporting linking it to campaigns against Microsoft Exchange infrastructure and government entities. Karkoff is designed to provide persistent access on compromised Windows systems and to execute selected commands remotely after initial compromise.
Karkoff has been delivered in phishing operations using weaponized Microsoft Excel documents with macros as an initial stage. In multiple APT34 intrusions, those lures were used to establish access before deploying the backdoor. The malware has also been observed in campaigns tied to DNSpionage-era activity.
Operationally, Karkoff supports remote administration and command execution and has been described as using both HTTP- and DNS-based communications in some reporting. A notable characteristic is its use of Microsoft Exchange as a command-and-control channel, including sending and receiving tasking through Exchange services with hardcoded account credentials. This tradecraft aligns with APT34’s broader preference for blending malicious traffic with legitimate enterprise communications and mail infrastructure to reduce detection. Karkoff has also been characterized as enabling persistent access and selective command execution rather than noisy, broad post-compromise activity.
Recent reporting indicates continued Karkoff activity into 2025 and 2026, including samples signed with an abused extended-validation code-signing certificate and variants modified for anti-analysis, such as oversized padding and spoofed compilation metadata. Those developments suggest ongoing maintenance and adaptation of the malware for defense evasion while preserving its core role as an espionage backdoor in APT34 operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
used a hardcoded account to authenticate the said communication. Aside from using hardcoded accounts as exchange accounts, APT34 can add a new module that can monitor changes in passwords and use the new accounts to send mails
This pattern is consistent with OilRig's established tactic of compromising trusted IT vendors to gain access to their government and critical infrastructure clients.
in the two separate attacks using Karkoff ... and Saitama ... the group used macros inside Excel files as part of the first stage to send phishing emails since the group did not have access to the enterprise yet.
They use phishing emails to deliver weaponized Microsoft Excel documents... Between 2014 to 2016, the group's attack campaigns targeted banks and technology organizations in Saudi Arabia with phishing emails that included weaponized Microsoft Excel attachments.
Karkoff maintains persistence via scheduled tasks or registry run keys.
the group used macros inside Excel files as part of the first stage
Karkoff maintains persistence via scheduled tasks or registry run keys.
Karkoff maintains persistence via scheduled tasks or registry run keys.
The internal filename of the signed Karkoff sample, egatdmtools.exe, mimics tooling associated with EGAT (Electricity Generating Authority of Thailand)... A binary named egatdmtools.exe, signed by MOSCII's certificate, would appear entirely legitimate.
Stripped metadata: No internal name, company string, or product version is present. This removes static analysis anchors that analysts and YARA rules rely on.
Karkoff malware has a full backdoor module using a government exchange server as a communication channel via send/received commands over an exchanged server
They also created a new remote administration tool that supported HTTP and DNS communication.
the latest compromise seems to be rewritten to use the same technique but only to exfiltrate data over the mail channel.
Shifting to new data exfiltration techniques — from the heavy use of DNS-based command and control (C&C) communication to combining it with the legitimate simple mail transfer protocol (SMTP) mail traffic — to bypass any security policies enforced on the network perimeters.
48 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A lightweight, modular .NET backdoor used for persistent access and selective command execution. It communicates with C2 over HTTP/HTTPS, can persist via scheduled tasks or registry run keys, and is described as an OilRig-exclusive tool updated across multiple campaigns.
Earlier APT34 implant referenced as lineage for newer Veaty and Spearal backdoors.
Backdoor malware used by APT34 that communicates through a government Exchange server, authenticating with a hardcoded account and supporting command exchange over the mail channel.
Malware used in the DNSpionage campaign to execute code remotely on compromised hosts, with HTTP and DNS communication support.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.