Overview
OilRig (MITRE ATT&CK ID G0049) is a suspected Iranian threat group MITRE ATT&CK documents as having targeted Middle Eastern and international victims since at least 2014, across financial, government, energy, chemical, and telecommunications sectors. Per MITRE’s profile, the group appears to carry out supply-chain attacks, leveraging trust relationships between organizations to reach their primary targets. MITRE states the group is assessed to work on behalf of the Iranian government based on infrastructure details referencing Iran, use of Iranian infrastructure, and targeting that aligns with nation-state interests.
Known tools and malware (per MITRE ATT&CK relationship data)
Our ingested data links OilRig to a large, largely custom toolset: QUADAGENT, OopsIE, RDAT, BONDUPDATER, SideTwist, Helminth, RGDoor, SEASHARPEE, PowerExchange, ISMInjector, ODAgent, OilBooster, OilCheck, Mango, and ZeroCleare, alongside dual-use tools like Mimikatz, PsExec, certutil, and LaZagne.
Notable techniques (per MITRE ATT&CK relationship data)
Techniques linked to OilRig in our data include Asymmetric Cryptography (T1573.002), Automated Collection (T1119), Brute Force (T1110), Cached Domain Credentials (T1003.005), Code Signing (T1553.002) and Code Signing Certificates (T1588.003), and Command and Scripting Interpreter (T1059).
Related campaigns
Per MITRE ATT&CK’s relationship data, OilRig is linked to campaigns “Juicy Mix” and “Outer Space” in our ingested data.
What we don’t have
MITRE’s ingested data doesn’t include a first-seen/last-seen activity date range for groups — we report “active since at least 2014” per MITRE’s description text. We have no independent telemetry or IOC data beyond MITRE’s STIX bundle, and MITRE’s own phrasing (“suspected Iranian,” “appears to carry out”) reflects an assessed rather than formally confirmed attribution.
Frequently Asked Questions
What is OilRig? A suspected Iranian threat group, per MITRE ATT&CK, active since at least 2014, known for supply-chain attacks against financial, government, energy, and telecom sectors.
Is OilRig the same as APT34? Yes — MITRE ATT&CK tracks APT34 as an alias of the same group designation, alongside Helix Kitten, Hazel Sandstorm, and several others used by different vendors.
What malware is OilRig linked to? Per MITRE ATT&CK’s relationship data: QUADAGENT, OopsIE, RDAT, BONDUPDATER, and SideTwist, among others.
Data sourced from MITRE ATT&CK® (https://attack.mitre.org), group ID G0049, aggregated September 3, 2026. This product uses MITRE ATT&CK data but is not endorsed or certified by MITRE. See more threat actor profiles.