Iran-linked threat group OilRig (also tracked as APT34, Crambus, and in some reporting linked with Lyceum/Hexane) has conducted a long-running cyberespionage campaign against government, diplomatic, technology, medical, energy, and utility targets across the Middle East and nearby regions. Researchers tied the group to spear-phishing operations that used compromised business email accounts, fake University of Oxford conference and job sites, trojanized VPN installers, and malicious Office documents to deliver malware including Helminth, ALMA Communicator, Marlin, and other custom backdoors. In one notable case, malware was digitally signed with a legitimate AI Squared code-signing certificate, making the payloads appear trustworthy and highlighting either certificate theft or compromise.
The intrusions evolved into deeper post-compromise operations featuring credential theft, webshell deployment, lateral movement, and covert command-and-control. Reports described OilRig-linked operators using Mimikatz, PsExec, Plink, scheduled tasks, SSH tunnels, spoofed webmail portals, and IIS backdoors such as RGDoor, while newer tradecraft included DNS tunneling, OneDrive API communications, and the PowerExchange technique that abused a compromised Exchange mailbox for C2. A later campaign against a Middle Eastern government reportedly compromised at least 12 systems, stole files and passwords, enabled remote RDP access, and deployed malware families including Backdoor.Tokel, Trojan.Dirps, and Infostealer.Clipog, underscoring that OilRig remains an active and adaptable Iranian espionage threat.

TTPs, infrastructure, and targeting history in one profile.
43 events from the most recent confirmed update back to the earliest known activity.
On September 3, 2023, the attackers used Wireshark utilities on Web Server 2 to enumerate capture interfaces, enabled RDP on Computer 3 by changing the fDenyTSConnections registry value, and mounted an administrative c$ share with stolen credentials.
On September 1, 2023, the attackers used Certutil to download Plink to Computers 5, 6, and 7 and executed joper.ps1 on Web Server 2.
On August 30, 2023, the attackers compromised a second web server, used Plink to expose RDP access from 91.132.92[.]90, and installed Infostealer.Clipog as fs-tool.exe.
On August 7 and again on August 12, 2023, Plink was downloaded to the domain controller and saved as \ProgramData\Adobe.exe.
On August 6, 2023, the attackers executed a PowerShell script on the domain controller, observed Nessus scans looking for Log4j vulnerabilities, enumerated firewall rules and local groups, listed mapped drives, and used WMI to run Plink for remote RDP access.
On July 11, 2023, Infostealer.Clipog was installed on Computer 3 as poluniq.exe, and Symantec observed it executed again on July 18.
On July 9 and 10, 2023, Trojan.Dirps was repeatedly executed on Computer 3 under the filename virtpackage.exe.
On July 8, 2023, the attackers used the domain controller to create an auto-start service on remote host 10.75.45[.]222 to run a script named pl.bat.
On June 20, 2023, Backdoor.PowerExchange was executed on Computer 3 as setapp.ps1, enabling command-and-control through Exchange email workflows.
On April 23, 2023, Symantec first observed Backdoor.Tokel on Computer 3 under the filename telecomm.exe.
On April 9, 2023, the attackers ran netstat and Mimikatz on the domain controller identified as Computer 4.
On April 8, 2023, the attackers accessed Computer 3, used Plink to forward RDP traffic, executed batch files, and later ran Mimikatz from the TEMP directory.
On February 21, 2023, the attackers executed netstat on a web server, relaunched Plink for remote RDP access, and used PowerShell to mount another computer’s C: drive.
On February 5, 2023, the attackers used a renamed Plink binary, msssh.exe, on a second computer to configure remote RDP access through an SSH tunnel to 151.236.19[.]91.
Trend Micro reported that APT34 used a newly rewritten .NET first-stage payload in a recent Middle East compromise and adapted its tooling away from heavier DNS-based communications toward Exchange/SMTP mail-channel exfiltration. The report linked the operation to APT34 through similarities with prior Saitama activity, including use of the EWS Managed API and continued targeting of Middle Eastern government entities.
Symantec reported that Crambus, also known as OilRig and APT34, carried out an espionage intrusion against a Middle Eastern government from February through September 2023, compromising at least 12 computers and likely many more.
Symantec said the first observed malicious activity in the Crambus intrusion occurred on February 1, 2023, when a PowerShell script named joper.ps1 ran on an initial compromised computer.
ESET concluded that OilRig was connected to the Iranian threat group Lyceum based on numerous and specific overlaps in tools, tactics, and backdoor design.
Attacks detected in August 2021 used the Marlin data-collection backdoor, which communicates through Microsoft's OneDrive API rather than OilRig's more typical DNS and HTTPS channels.
In April 2021, the actor targeted a Lebanese entity using an implant called SideTwist, according to ESET's retrospective on the Out to Sea campaign.
ESET said the related Lyceum activity evolved in 2021 from earlier DanBot infections to the Shark and Milan backdoors.
ESET reported that APT34 deployed the ToneDeaf malware family against a broad range of industries in the Middle East in July 2019.
Unit 42 reported on a publicly leaked 2019 dataset it assessed as consistent with OilRig operations, containing stolen credentials, webshells, backdoors, DNS hijacking scripts, and screenshots of operational systems. The analysis identified nearly 13,000 stolen credentials, more than 100 deployed webshells, and activity affecting 97 organizations across 27 countries, while mapping internal tool names to known malware families and DNSpionage-related tooling.
FireEye published research on a global DNS hijacking campaign involving DNS record manipulation at scale. The report documented a distinct operational development associated with Iranian threat activity later linked in broader OilRig-related reporting.
Cisco Talos published research on the DNSpionage campaign, describing DNS hijacking activity targeting organizations in the Middle East. This reporting documented the campaign before later broader reporting on global DNS hijacking activity.
In August 2018, OilRig conducted a spear-phishing campaign against a Middle Eastern government organization using a malicious Word document to install an updated PowerShell-based BONDUPDATER Trojan. Palo Alto said the new variant preserved DNS-tunneling backdoor functions while adding command-and-control support over DNS TXT records, using withyourface[.]com as the C2 domain.
ESET said OilRig began its long-running Out to Sea espionage campaign in April 2018, targeting diplomatic, technology, and medical organizations in Israel, Tunisia, and the United Arab Emirates.
FireEye published research on a targeted attack in the Middle East attributed to suspected Iranian group APT34/OilRig that used the CVE-2017-11882 Microsoft Office Equation Editor exploit. The report added a new technical development in the group's tooling and intrusion methods.
On November 15, 2017, Unit 42 observed an OilRig developer make 22 rapid modifications to a TwoFace webshell loader variant over about 16 minutes to identify which code elements triggered antivirus detection. The testing showed detections were tied to both the embedded encrypted webshell payload and code that allowed remote updating of that payload, and the actor ended with a zero-detection version after removing the update functionality.
Unit 42 published research describing OilRig actors' internal development and testing efforts, providing technical insight into how the group built and refined its malware and operational tooling. This added a new disclosure about the group's workflow rather than a new victim or phishing incident.
Forbes reported that AI Squared was the only known private American business identified as a victim in the OilRig espionage campaign and that its stolen certificates were used to make OilRig malware appear legitimate.
AI Squared stated in a website notification that its digital certificate used for newer ZoomText and Window-Eyes products had been compromised and would be revoked on or around January 26. ClearSky noted this statement in an update dated February 11, 2017.
Symantec warned AI Squared in January 2017 that certificates used to guarantee the authenticity of its software had been compromised, prompting an internal investigation by VFO Group.
In early January 2017, ClearSky reported that OilRig used stolen or fraudulently obtained AI Squared code-signing certificates to sign malware used against targets in the Middle East, Europe, and the United States.
In January 2017, SecureWorks reported that OilRig sent malware-laden job-offer emails from legitimate addresses belonging to Saudi Arabia’s National Technology Group and Egypt’s ITWorx. The attachments contained the PupyRAT remote access trojan and targeted an unnamed Middle East entity.
In November 2016, OilRig ran fake Oxford University-themed websites, including conference registration and job application pages, to lure victims into downloading malware-laced tools such as a registration form and CV creator.
Palo Alto Networks published research describing OilRig campaign updates, including expanded targeting and related phishing activity. Forbes later referenced this prior publication as documenting similar malicious emails sent to multiple government organizations worldwide.
A July 2016 phishing email targeted three officials at Turkey’s foreign ministry, including personnel linked to Turkey’s UN mission and embassy in Riga. The lure appeared to come from a Turkish Airlines check-in address and used an Excel attachment to solicit credentials and execute Helminth.
AI Squared, the Vermont accessibility software company later identified as a victim in the OilRig campaign, was acquired by Florida-based VFO Group.
In May 2016, OilRig attempted a phishing attack using infrastructure that email metadata indicated was inside Saudi government contractor and IT security supplier Al-Elm. The malicious message was injected into an ongoing thread between Al-Elm and Samba and carried an Excel attachment containing Helminth malware.
Symantec published reporting on two Iran-based groups, Cadelle and Chafer, which ClearSky later cited in discussing infrastructure overlap with OilRig-related activity.
Unit 42 reported that an August 2015 ZIP archive hosted on doosan[.]com may have delivered the executable Helminth variant via a fake job-offer lure, using the HerHer dropper. This established an earlier observed phase of the OilRig campaign before the later May 2016 Saudi targeting wave.
ClearSky reported that OilRig had been targeting organizations in Israel and other Middle East countries since the end of 2015, including Israeli IT vendors, financial institutions, and the Israeli Post Office.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 145 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
17 references tracked. Mallory keeps watching after this page renders.
symantec-enterprise-blogs.security.com
Open sourcetrendmicro.com
Open sourcethehackernews.com
Open sourceunit42.paloaltonetworks.com
Open sourceiranthreats.github.io
Open sourceclearskysec.com
Open sourceresearchcenter.paloaltonetworks.com
Open sourceresearchcenter.paloaltonetworks.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.