THREATOPS Actor Dossier
LIVE ← Dashboard

OilRig

G00493 reports
aliases · OilRig · COBALT GYPSY · IRN2 · APT34 · Helix Kitten · Evasive Serpens · Hazel Sandstorm · EUROPIUM · ITG13 · Earth Simnavaz · Crambus · TA452
Export dossier:
3
Reports
12
Techniques
9
Tactics
4
Countries
67%
Hunt coverage
12
Aliases

Analyst assessment — key judgments

  • Signature techniques: T1589.001 (Credentials), T1588.006 (Vulnerabilities), T1027.003 (Steganography).
  • Primary targeting: IR, US, IL, AE.
  • Steady activity: 0 report(s) in last 30d vs 0 prior (+0%).
  • Hunt coverage 67% of 15 observed techniques (5 gap(s)).
  • Assessment confidence: medium (62).

Activity & trend

SteadyLast 30d: 0 vs 0 prior (+0%)· first reported 2026-07-06 · last 2026-07-21
0
7d
0
30d
3
90d
3
All
0.2
Rpts/wk
Reporting timeline · 12 months

Overview

Analyst triage
Intelligence summary

OilRig is a suspected Iranian threat group that has targeted Middle Eastern and international victims since at least 2014. The group has targeted a variety of sectors, including financial, government, energy, chemical, and telecommunications. It appears the group carries out supply chain attacks, leveraging the trust relationship between organizations to attack their primary targets. The group works on behalf of the Iranian government based on infrastructure details that contain references to Iran, use of Iranian infrastructure, and targeting that aligns with nation-state interests.(Citation: FireEye APT34 Dec 2017)(Citation: Palo Alto OilRig April 2017)(Citation: ClearSky OilRig Jan 2017)(Citation: Palo Alto OilRig May 2016)(Citation: Palo Alto OilRig Oct 2016)(Citation: Unit42 OilRig Playbook 2023)(Citation: Unit 42 QUADAGENT July 2018)

Top co-occurring indicators
    Aliases & naming
      Targeting · countries
        Targeting · named victims

          ATT&CK technique matrix

          Coverage vs hunt library:
          Hunt-coverage gaps — prioritized

            Top techniques by observation

            Threat catalogue · engineering roadmap0

            Flagged detection-engineering queue

            Uncovered techniques you flagged for hunt / detection build-out, aggregated across every actor you visit. Stored locally in your browser.

              No techniques queued yet — flag a gap above to add it here.

              Infrastructure

              IOC type mix
              Tooling / malware families
                Tracked infrastructure

                Relationships

                Related actors (behavioral cluster)
                  Attributed malware
                  Campaigns
                  No behavioral cluster, attributed malware, or campaigns recorded for this actor yet.

                  Activity

                  30-day mention timeline
                  Recent reporting
                  TitleSourceSeverityCollected