OilRig is an Iranian state-linked cyber-espionage threat actor commonly tracked as APT34 and widely associated with Iran’s Ministry of Intelligence and Security (MOIS). The group is known for persistent regional espionage operations, particularly against government, telecommunications, energy, financial, and technology-related targets in the Middle East, with repeated reporting on activity affecting Israel and Iraq. Common aliases include APT34, Hazel Sandstorm, Evasive Serpens, Cobalt Gypsy, Crambus, Europium, Helix Kitten, IRN2, ITG13, and TA452. Lyceum, also known as Hexane and SiameseKitten, is frequently assessed as a subgroup or closely related cluster within the broader OilRig ecosystem. OilRig is characterized by long-duration intrusion activity, modular malware development, and frequent use of legitimate cloud and enterprise services to blend command-and-control into normal traffic. Reported tradecraft includes abuse of Microsoft-hosted services, attachment-based tasking and exfiltration workflows, dead-drop style command channels, and secondary recovery mechanisms to restore cloud access when primary communications fail. The actor has also been associated with credential theft, registry and system discovery, remote administration abuse, and post-compromise reconnaissance using native commands and custom tooling. The group has historically focused on intelligence collection rather than overt disruption, seeking political, diplomatic, and telecommunications intelligence from regional targets. Public reporting has linked OilRig to operations against Iraqi government infrastructure and to broader espionage campaigns targeting Israeli entities. More recent reporting has described low-confidence overlaps between OilRig and activity clusters using the Cavern or Project CAV3RN framework, including malware that abuses Microsoft 365 calendars and Microsoft Graph API for covert command-and-control and exfiltration. Those links are based on behavioral similarities and ecosystem overlap rather than definitive proof, and some reporting instead places the activity closer to Lyceum or the separately tracked Cavern Manticore cluster. Operationally, OilRig is known for iterative tooling changes, modular .NET-heavy malware, and use of compromised regional infrastructure and trusted third-party pathways. Techniques associated with the actor include system information discovery, peripheral and removable-media discovery, registry querying, credential access, cloud account abuse, encrypted command-and-control over web protocols, and exfiltration over application-layer channels. OilRig’s activity fits the broader pattern of MOIS-linked Iranian cyber operations centered on stealthy access development, espionage, and selective follow-on exploitation rather than indiscriminate destructive attacks.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
49 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
46 malware families attributed to this actor across reporting.
41 additional families tracked in Mallory.
12 CVEs this actor has used in observed campaigns. 12 of them exploited in the wild.
OilRig has exploited CVE-2024-30088 to run arbitrary code in the context of SYSTEM .
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
we did produce two reports revolving around the use of a zero-day exploit (CVE-2017-0199). The most notable involved an actor we refer to as BlackOasis and their usage of the exploit in-the-wild prior to its discovery.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
7 more CVEs tied to this actor tracked in Mallory.
217 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Iran MOIS-linked threat actor referenced because Lyceum is identified as its subgroup in the attribution discussion.
Named as the likely associated Iran-linked espionage group behind Project CAV3RN, but attribution remains low confidence.
Associated with Project CAV3RN cyberespionage activity targeting Israel, using a modular framework with Microsoft Graph/Outlook calendar events for C2 and DNS AAAA-based recovery of cloud C2 configuration.
Likely conducting cyberespionage against entities in Israel using the modular Project CAV3RN framework, including a new Outlook calendar/Microsoft Graph-based C2 module with DNS AAAA fallback configuration retrieval.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.