OilRig is an Iranian state-linked cyber espionage threat actor widely tracked as APT34 and associated with Iran’s Ministry of Intelligence and Security (MOIS). It has also been reported under aliases including Helix Kitten, Hazel Sandstorm, Cobalt Gypsy, Crambus, Earth Simnavaz, Europium, Evasive Serpens, IRN2, ITG13, and TA452. Lyceum, also known as Hexane and Siamese Kitten, is commonly assessed as a subgroup or closely related cluster within the broader OilRig ecosystem. OilRig has primarily conducted espionage and access operations against organizations in the Middle East, with victim sectors reported to include government, energy, telecommunications, transportation, financial services, chemical, and aerospace. The group is known for targeting regional strategic interests and for using both direct intrusions and trusted third-party relationships to reach intended victims. The actor is notable for extensive use of spearphishing, credential theft, and living-off-the-land tradecraft. Reported execution and delivery methods include malicious attachments, PowerShell-based payloads, abuse of signed Windows binaries such as Regsvr32 and Certutil, and remote script execution. OilRig has shown a longstanding preference for PowerShell-centric tooling and modular backdoors, while also using .NET components in some operations. Observed post-compromise behavior includes host reconnaissance and victim profiling through commands such as hostname and system information discovery, registry querying to identify remote access artifacts and environment details, and checks for attached peripherals or user-interaction indicators. The group has also been associated with privilege-escalation activity, persistence mechanisms, and broader hands-on-keyboard operations consistent with mature intrusion sets. OilRig has been linked to malware and frameworks including Poison Frog and its successor Glimpse, backdoors associated with DNS-based command and control, and other modular tooling used for espionage and long-term access. Public reporting has also described weaknesses in parts of its malware infrastructure, indicating that while the group is operationally persistent and effective, its tooling quality has varied over time. The broader Iranian intrusion landscape shows technical and operational overlap among OilRig, MuddyWater, and Lyceum-related activity. OilRig remains one of the most recognized Iranian espionage actors and is consistently tracked as a significant MOIS-aligned threat to regional government and enterprise networks.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
57 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
52 malware families attributed to this actor across reporting.
47 additional families tracked in Mallory.
12 CVEs this actor has used in observed campaigns. 12 of them exploited in the wild.
OilRig has exploited CVE-2024-30088 to run arbitrary code in the context of SYSTEM .
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
we did produce two reports revolving around the use of a zero-day exploit (CVE-2017-0199). The most notable involved an actor we refer to as BlackOasis and their usage of the exploit in-the-wild prior to its discovery.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
7 more CVEs tied to this actor tracked in Mallory.
201 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only as the parent group of Lyceum in attribution context for Cavern Manticore.
Referenced as the larger Iran-linked threat actor organization to which Lyceum is described as a subgroup, in connection with possible ties to Cavern Manticore.
Threat actor referenced because Lyceum is assessed to be a subgroup within it.
Listed as an annotation/tag associated with privilege escalation techniques in the detection content; no campaign or activity by the group is described in this reference.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.