Skip to main content
QUIETLYTIC
Threat Actor

OilRig

Suspected Iranian threat group, per MITRE ATT&CK, targeting Middle Eastern and international victims since at least 2014 via supply-chain trust relationships.

Threat Level
HIGH
Attribution
Suspected to work on behalf of the Iranian government, per MITRE ATT&CK's group profile
Also Known As
COBALT GYPSY, IRN2, APT34, Helix Kitten, Evasive Serpens, Hazel Sandstorm, EUROPIUM, ITG13, Earth Simnavaz, Crambus, TA452
Targets
Financial, government, energy, chemical, and telecommunications sectors, Middle Eastern and international organizations

Overview

OilRig (MITRE ATT&CK ID G0049) is a suspected Iranian threat group MITRE ATT&CK documents as having targeted Middle Eastern and international victims since at least 2014, across financial, government, energy, chemical, and telecommunications sectors. Per MITRE’s profile, the group appears to carry out supply-chain attacks, leveraging trust relationships between organizations to reach their primary targets. MITRE states the group is assessed to work on behalf of the Iranian government based on infrastructure details referencing Iran, use of Iranian infrastructure, and targeting that aligns with nation-state interests.

Known tools and malware (per MITRE ATT&CK relationship data)

Our ingested data links OilRig to a large, largely custom toolset: QUADAGENT, OopsIE, RDAT, BONDUPDATER, SideTwist, Helminth, RGDoor, SEASHARPEE, PowerExchange, ISMInjector, ODAgent, OilBooster, OilCheck, Mango, and ZeroCleare, alongside dual-use tools like Mimikatz, PsExec, certutil, and LaZagne.

Notable techniques (per MITRE ATT&CK relationship data)

Techniques linked to OilRig in our data include Asymmetric Cryptography (T1573.002), Automated Collection (T1119), Brute Force (T1110), Cached Domain Credentials (T1003.005), Code Signing (T1553.002) and Code Signing Certificates (T1588.003), and Command and Scripting Interpreter (T1059).

Per MITRE ATT&CK’s relationship data, OilRig is linked to campaigns “Juicy Mix” and “Outer Space” in our ingested data.

What we don’t have

MITRE’s ingested data doesn’t include a first-seen/last-seen activity date range for groups — we report “active since at least 2014” per MITRE’s description text. We have no independent telemetry or IOC data beyond MITRE’s STIX bundle, and MITRE’s own phrasing (“suspected Iranian,” “appears to carry out”) reflects an assessed rather than formally confirmed attribution.

Frequently Asked Questions

What is OilRig? A suspected Iranian threat group, per MITRE ATT&CK, active since at least 2014, known for supply-chain attacks against financial, government, energy, and telecom sectors.

Is OilRig the same as APT34? Yes — MITRE ATT&CK tracks APT34 as an alias of the same group designation, alongside Helix Kitten, Hazel Sandstorm, and several others used by different vendors.

What malware is OilRig linked to? Per MITRE ATT&CK’s relationship data: QUADAGENT, OopsIE, RDAT, BONDUPDATER, and SideTwist, among others.


Data sourced from MITRE ATT&CK® (https://attack.mitre.org), group ID G0049, aggregated September 3, 2026. This product uses MITRE ATT&CK data but is not endorsed or certified by MITRE. See more threat actor profiles.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Related intelligence


Cross-referenced intelligence


Analyst tools