OilRig, APT 34, Helix Kitten, Chrysene

Description

OilRig is a threat group with suspected Iranian origins that has targeted Middle Eastern and international victims since at least 2014. The group has targeted a variety of industries, including financial, government, energy, chemical, and telecommunications, and has largely focused its operations within the Middle East. It appears the group carries out supply chain attacks, leveraging the trust relationship between organizations to attack their primary targets. FireEye assesses that the group works on behalf of the Iranian government based on infrastructure details that contain references to Iran, use of Iranian infrastructure, and targeting that aligns with nation-state interests. This group was previously tracked under two distinct groups, APT 34 and OilRig, but was combined due to additional reporting giving higher confidence about the overlap of the activity.

OilRig has 1 subgroup:

  1. Subgroup: Greenbug, Volatile Kitten

OilRig seems to be closely related to APT 33, Elfin, Magnallium since at least 2017 and perhaps DNSpionage. They also seem to overlap with Hexane.

Also see HomeLand Justice and Orangeworm.

Names

NameName-Giver
OilRigPalo Alto
APT 34FireEye
Helix KittenCrowdStrike
Twisted KittenCrowdStrike
CrambusSymantec
ChryseneDragos
Cobalt GypsySecureWorks
TA452Proofpoint
IRN2Area 1
ATK 40Thales
ITG13IBM
DEV-0861?
EUROPIUMMicrosoft
Hazel SandstormMicrosoft
Scarred ManticoreCheck Point
Evasive SerpensPalo Alto
Yellow MaeroPWC
Storm-0861Microsoft
UNC1860Mandiant
Earth SimnavazTrend Micro

Country

State-sponsored, Ministry of Intelligence and Security (MOIS)

Motivation

  • Information theft and espionage

First Seen

2014

Observed Sectors

Observed Countries

Tools

Operations

Counter Operations

Information

Mitre Attack

Playbook

Other Information

Uuid

eeb31f97-edcf-4836-b621-a1865305b91e

Last Card Change

2024-10-24