APT34, also tracked as OilRig and Helix Kitten, ran targeted phishing campaigns that used malicious Microsoft Word documents to deliver new malware closely related to the SideTwist backdoor. One lure posed as a Seychelles Licensing Authority registration form with pricing in Saudi riyals, indicating likely targeting in Saudi Arabia, while another impersonated marketing services firm GGMS to reach enterprise victims. In both cases, the documents dropped .NET payloads—identified as Menorah and SystemFailureReporter.exe—that gave the operators espionage capabilities including host fingerprinting, command execution, file listing, file upload, and file download.
The malware established persistence through scheduled tasks, including OneDriveStandaloneUpdater and another task triggered every five minutes via an update.xml file. The implants communicated over HTTP with command-and-control infrastructure including tecforsc-001-site1.gtempurl.com and 11.0.188.38:443, with one report noting that the latter, a U.S. Department of Defense-owned IP address, was likely a decoy or testing endpoint intended to shield operational infrastructure. Researchers said the activity shows APT34 continuing to evolve SideTwist-style tooling while relying on straightforward phishing and persistence methods for cyberespionage in the Middle East and against enterprise targets.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
NSFOCUS states that APT34, also known as OilRig or Helix Kitten, has been active since 2014 and has conducted cyber espionage and sabotage operations in the Middle East.
Trend Micro analyzed Menorah as a cyberespionage malware family with system fingerprinting, command execution, file listing, upload, and download capabilities, communicating with tecforsc-001-site1.gtempurl.com over HTTP every 32 seconds. The report found significant similarities between Menorah and the SideTwist backdoor, including victim fingerprinting and command-and-control communication patterns.
Trend Micro described a targeted phishing attack attributed to APT34 that used a malicious Word document, “MyCv.doc,” disguised as a Seychelles Licensing Authority registration form with Saudi Riyal pricing, suggesting a likely Saudi Arabian target. The document’s macros dropped Menorah.exe and created a scheduled task named “OneDriveStandaloneUpdater” for persistence.
NSFOCUS analyzed the dropped malware as a SideTwist variant that communicated over HTTP with 11.0.188.38:443, collected host identifiers, used an update.xml anti-sandbox check, and parsed commands hidden in HTML script tags. The malware supported command execution, file download, and file upload, and NSFOCUS assessed the DoD-owned IP likely served as a testing or decoy C2 rather than an active operational server.
NSFOCUS Security Labs reported a new phishing campaign attributed to APT34 in which attackers impersonated Ganjavi Global Marketing Services and used a malicious Word document, “GGMS Overview.doc,” to target enterprise victims. The macro dropped SystemFailureReporter.exe, created update.xml, and established persistence with a scheduled task running every five minutes.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.