OilRig
G00493 reportsAnalyst assessment — key judgments
- Signature techniques: T1589.001 (Credentials), T1588.006 (Vulnerabilities), T1027.003 (Steganography).
- Primary targeting: IR, US, IL, AE.
- Steady activity: 0 report(s) in last 30d vs 0 prior (+0%).
- Hunt coverage 67% of 15 observed techniques (5 gap(s)).
- Assessment confidence: medium (62).
Activity & trend
Overview
OilRig is a suspected Iranian threat group that has targeted Middle Eastern and international victims since at least 2014. The group has targeted a variety of sectors, including financial, government, energy, chemical, and telecommunications. It appears the group carries out supply chain attacks, leveraging the trust relationship between organizations to attack their primary targets. The group works on behalf of the Iranian government based on infrastructure details that contain references to Iran, use of Iranian infrastructure, and targeting that aligns with nation-state interests.(Citation: FireEye APT34 Dec 2017)(Citation: Palo Alto OilRig April 2017)(Citation: ClearSky OilRig Jan 2017)(Citation: Palo Alto OilRig May 2016)(Citation: Palo Alto OilRig Oct 2016)(Citation: Unit42 OilRig Playbook 2023)(Citation: Unit 42 QUADAGENT July 2018)
ATT&CK technique matrix
- T1589.001 · Credentialsconf 703
- T1588.006 · Vulnerabilitiesconf 652
- T1027.003 · Steganographyconf 652
- T1001.002 · Steganographyconf 652
- T1069.001 · Local Groupsconf 601
- T1590.005 · IP Addressesconf 601
- T1552.004 · Private Keysconf 601
- T1204.002 · Malicious Fileconf 601
- T1574.014 · AppDomainManagerconf 601
- T1684 · Social Engineeringconf 601
- T1491 · Defacementconf 601
- T1087.004 · Cloud Accountconf 601
Threat catalogue · engineering roadmap
Uncovered techniques you flagged for hunt / detection build-out, aggregated across every actor you visit. Stored locally in your browser.
Infrastructure
Relationships
Activity
| Title | Source | Severity | Collected |
|---|