OilRig — what to detect, and what we don’t know.

The Gulf energy and telecom operator-set, worked continuously for a decade.

76 techniques 19 detection behaviours 30 tools mapped Kuwait, Saudi Arabia

Also tracked as  Twisted Kitten · Cobalt Gypsy · Crambus · Helix Kitten · APT 34 · APT34 · IRN2 · ATK40 · G0049 · Evasive Serpens · Hazel Sandstorm · EUROPIUM

Attributed to
IR Iran (Islamic Republic of)
Gulf victimology
4 Kuwait, Saudi Arabia, Qatar
Techniques
76 across 13 tactics
Tooling
30 18 actor-specific · 12 commodity
Reporting
30 11 outlets · 35 research hosts

Summary

The short version

OilRig is a threat actor attributed to Iran (Islamic Republic of), assessed as espionage-motivated. Its recorded targeting runs to chemical, energy, engineering, finance and adjacent sectors across 8 countries in the open reporting we hold — Kuwait, Saudi Arabia, Qatar, Middle East among them.

Across 76 attributed ATT&CK techniques we resolve 19 distinct behaviours — the things they do that a detection can be written against. The two that account for most of their observed tradecraft are discovery command burst on one host and valid account abuse or account creation. Their toolkit is 30 named items: 18 we see only in this actor's reporting and 12 commodity or dual-use. That ratio is the point — the first group is what identifies them, the second is what they share with every other group and with red teams.

For a Gulf defender the relevant line is the victimology: Kuwait, Saudi Arabia, Qatar, Middle East appear in the reporting behind this record. That is evidence of past targeting, not a forecast, and it is drawn from what vendors chose to publish — an actor working quietly in a market nobody reports on looks identical to one that is absent.

As MITRE describes them: “OilRig is an Iranian threat group operating primarily in the Middle East by targeting organizations in this region that are in a variety of different industries; however, this group has occasionally targeted organizations outside of the Middle East as well. It also appears OilRig carries out supply chain attacks, where the threat group leverages the trust relationship between organizations to attack their primary targets. OilRig is an active and organized threat group, which is evident based on their systematic targeting of specific organizations that appear to be carefully chosen for strategic purposes. Attacks ” — MITRE ATT&CK, CC BY 4.0.

On the name. “OilRig” labels a cluster of related activity tracked under one name — not a verified organisation. Whether one team, several contractors or a rotating cast sits behind it is not something this record establishes, and the vendor names below are separate groupings that only mostly overlap.

02 — The detection plan

What to detect, ranked by what survives their retooling

Most actor profiles hand you indicators that expire in days. These are the behaviours the actor cannot drop without changing how they operate, each with the reason it holds. Weight is our own: how much of the actor's observed tradecraft the behaviour accounts for.

D1

Persistence pointing into world-writable staging

Tier 1–2

The persistence mechanism and the directory it points at both outlive the payload. The discriminator is the TARGET PATH, not the task or key name, which the actor can change freely.

8 techniques · weight 5

D2

Credential access against LSASS

Tier 3–5

Few legitimate processes read LSASS memory, so precision is high in most estates once the agents that do are excluded.

2 techniques · weight 5

D3

Web shell written into a served directory

Tier 3

A script file appearing under a web root outside a deployment window is close to a binary signal, and it catches the entry vector rather than the aftermath.

2 techniques · weight 5

D4

User-facing application spawning an interpreter

Tier 3

The delivery wrapper changes constantly; an office, archive or browser process parenting a shell is the same shape across all of them.

8 techniques · weight 5

D7

Security tooling stopped, unloaded or blinded

Tier 3

Nothing legitimate disables the estate's own defences at endpoint scale, and the action reliably precedes the part of the intrusion you care about.

9 techniques · weight 5

D5

Credential store or keystroke capture

Tier 3

Kept separate from the LSASS rule because it needs different telemetry and tunes differently — a browser credential store read by a non-browser process is its own signal.

8 techniques · weight 4

D6

Vendor-suggestive name outside that vendor's paths

Tier 4

Encodes the naming RULE rather than the filenames, so it survives every rename. The convention is a habit; the names are inventory.

6 techniques · weight 4

D8

Encoded or obfuscated interpreter invocation

Tier 3

The command-line SHAPE — the flag combination, not the payload — is stable for months to years and cheap to match.

8 techniques · weight 4

D16

Execution brokered through WMI or a native API

Tier 3

Chosen to avoid a shell, so command-line rules miss it entirely. The broker is a stable choice; what it runs is not.

6 techniques · weight 4

D9

Password spraying or credential stuffing

Context

Visible only in identity telemetry, and the failure-then-success shape is what distinguishes it from ordinary user error.

6 techniques · weight 3

D10

Living-off-the-land download of a second stage

Tier 5

The set of system binaries that can fetch a file is small and changes with the OS, not with the actor.

5 techniques · weight 3

D11

Remote service or share used to move laterally

Tier 3

Lateral movement leaves a service-creation or admin-share write that is the same regardless of the tool that made it.

6 techniques · weight 3

D12

Collection staged into an archive before egress

Tier 3

Staging is a step the actor cannot skip, and it happens before the data leaves — the last cheap place to catch it.

7 techniques · weight 3

D13

Exploitation of an internet-facing service

Context

Not a durable behavioural signature but the entry vector for a large public estate — worth an exposure control even where the detection is weak.

3 techniques · weight 3

D14

Propagation through removable media

Context

Only worth building where removable media is permitted at all — check the policy before spending tuning hours on it.

5 techniques · weight 3

D15

Protocol tunnelling or an internal proxy hop

Tier 5

The tunneller is a tool choice that persists for months, and the traffic shape is visible even when the payload is not.

8 techniques · weight 3

D17

Valid account abuse or account creation

Tier 5

Produces no malware event at all — the only trace is in identity telemetry, which is why an endpoint-only programme has a blind spot exactly here.

10 techniques · weight 3

D18

Beaconing to attacker infrastructure over web protocols

Tier 6–7

The URI shape and cadence are cheap to match and hold for weeks to months — but the destination itself rotates in days, so match the pattern rather than the host.

7 techniques · weight 3

D19

Discovery command burst on one host

Context

No single discovery command is worth an alert. The DENSITY is — several distinct recon binaries on one host inside an hour is a shape ordinary use does not produce.

17 techniques · weight 2

How to score it

No single behaviour here is worth waking someone. Summed weights of 6 on one host inside a window is an alert; 10 is an incident. The pair that most reliably means this actor rather than commodity crime is Persistence pointing into world-writable staging + Credential access against LSASS — seen together, treat as an incident regardless of total.

03 — Tooling

30 named tools, and what each is for

Purpose is derived, not asserted: each tool's own ATT&CK techniques are resolved to tactics, and the tactics it spends most of its techniques in are what it is for.

Actor-specific means we have no record of it outside this actor's reporting — those are the names that identify them. Commodity covers everything sold, published or shared: Cobalt Strike and Brute Ratel are licensed red-team software every pentester owns, Mimikatz and Impacket are public, and backdoors like ShadowPad circulate between unrelated groups. Finding a commodity tool tells you far less, which is exactly why the split is drawn. ATT&CK's own “malware vs tool” type answers a different question — whether the software is malicious — so it is not used for this.

Actor-specific — 18 items

Helminth Actor-specific

Gathering data and staying resident.

S0170  ·  21 techniques  ·  Collection, Persistence, Exfiltration
POWRUNER Actor-specific

Gathering data and network reconnaissance.

S0184  ·  20 techniques  ·  Collection, Discovery, Command and Control
RDAT Actor-specific

Moving data out and gathering data.

S0495  ·  20 techniques  ·  Exfiltration, Collection, Persistence
OopsIE Actor-specific

Gathering data and moving data out.

S0264  ·  19 techniques  ·  Collection, Exfiltration, Stealth
QUADAGENT Actor-specific

Evading defences and remote control.

S0269  ·  17 techniques  ·  Stealth, Command and Control, Execution
SideTwist Actor-specific

Gathering data and moving data out.

S0610  ·  15 techniques  ·  Collection, Exfiltration, Command and Control
OilBooster Actor-specific

Moving data out and gathering data.

S1172  ·  15 techniques  ·  Exfiltration, Collection, Command and Control
Mango Actor-specific

Moving data out and remote control.

S1169  ·  13 techniques  ·  Exfiltration, Command and Control, Discovery
SampleCheck5000 Actor-specific

Gathering data and moving data out.

S1168  ·  10 techniques  ·  Collection, Exfiltration, Command and Control
ODAgent Actor-specific

Moving data out and remote control.

S1170  ·  9 techniques  ·  Exfiltration, Command and Control, Execution
Solar Actor-specific

Moving data out and remote control.

S1166  ·  8 techniques  ·  Exfiltration, Command and Control, Discovery
ZeroCleare Actor-specific

Destruction or extortion and privilege escalation.

S1151  ·  8 techniques  ·  Impact, Privilege Escalation, Execution
BONDUPDATER Actor-specific

Remote control and running code.

S0360  ·  7 techniques  ·  Command and Control, Execution, Stealth
RGDoor Actor-specific

Gathering data and staying resident.

S0258  ·  7 techniques  ·  Collection, Persistence, Command and Control
PowerExchange Actor-specific

Moving data out and remote control.

S1173  ·  5 techniques  ·  Exfiltration, Command and Control, Execution
SEASHARPEE Actor-specific

Staying resident and remote control.

S0185  ·  4 techniques  ·  Persistence, Command and Control, Execution
ISMInjector Actor-specific

Evading defences and running code.

S0189  ·  4 techniques  ·  Stealth, Execution
OilCheck Actor-specific

Moving data out and remote control.

S1171  ·  3 techniques  ·  Exfiltration, Command and Control

Commodity and dual-use — 12 items

Mimikatz Commodity

Credential theft and moving between hosts.

S0002  ·  17 techniques  ·  Credential Access, Lateral Movement, Persistence
Net Commodity

Staying resident and moving between hosts.

S0039  ·  16 techniques  ·  Persistence, Lateral Movement, Discovery
LaZagne Commodity

Credential theft.

S0349  ·  10 techniques  ·  Credential Access
PsExec Commodity

Moving between hosts and staying resident.

S0029  ·  5 techniques  ·  Lateral Movement, Persistence, Execution
ngrok Commodity

Moving data out and remote control.

S0508  ·  5 techniques  ·  Exfiltration, Command and Control
certutil Commodity

Gathering data and remote control.

S0160  ·  4 techniques  ·  Collection, Command and Control, Defense Impairment
ftp Commodity

Moving data out and moving between hosts.

S0095  ·  3 techniques  ·  Exfiltration, Lateral Movement, Command and Control
Tasklist Commodity

Network reconnaissance.

S0057  ·  3 techniques  ·  Discovery
Reg Commodity

Credential theft and disabling defences.

S0075  ·  3 techniques  ·  Credential Access, Defense Impairment, Discovery
netstat Commodity

Network reconnaissance.

S0104  ·  1 techniques  ·  Discovery
ipconfig Commodity

Network reconnaissance.

S0100  ·  1 techniques  ·  Discovery
Systeminfo Commodity

Network reconnaissance.

S0096  ·  1 techniques  ·  Discovery
No data

File hashes for OilRig’s own tooling

We hold none. Our corpus carries 9,780 hashes, but they come from live feeds covering current commodity campaigns — not the decade-old actor-specific backdoors in the list above. ATT&CK itself publishes no sample hashes; it is a technique knowledge base. Where a sample would have to come from a third party’s family tag rather than from this actor’s reporting, we leave the row empty instead of implying an attribution we cannot support.

04 — Coverage, honestly counted

Where the 76 techniques actually go

Of the techniques attributed to OilRig, 58 fold into the detection plan above, 6 describe preparation you cannot see from inside your network, and 12 are uncatalogued — we have not yet placed them. That last number is published on purpose; it is the honest size of the gap.

Discovery14
Stealth10
Execution9
Credential Access8
Command and Control7
Collection6
Resource Development6
Defense Impairment4
Initial Access4
Persistence4
Lateral Movement2
Exfiltration1
Privilege Escalation1

05 — The chain

The order it happens in

The same techniques as above, sequenced. Useful for deciding where to spend a detection: the earlier a tactic sits, the more of the intrusion you still get to prevent.

01
Resource Development
6 techniques
02
Initial Access
4 techniques
03
Execution
9 techniques
04
Persistence
4 techniques
05
Privilege Escalation
1 technique
06
Credential Access
8 techniques
07
Discovery
14 techniques
08
Lateral Movement
2 techniques
09
Collection
6 techniques
10
Command and Control
7 techniques
11
Exfiltration
1 technique
12
Stealth
10 techniques
13
Defense Impairment
4 techniques

06 — Tradecraft artefacts

Concrete strings, each with the report it came from

Pulled from primary vendor research and kept attributed. These are hunt starting points, not detections — a path an actor used once is worth a query, not a rule.

ArtefactKind First reported byDate
%programdata%\PolGuid\in.txt file path The Hacker News 2026-03-05
%programdata%\PolGuid file path Zscaler 2026-03-02
%programdata%\PolGuid.zip file path Zscaler 2026-03-02
%programdata%\PolGuid\.The file path Zscaler 2026-03-02
%programdata%\PolGuid\VLC\VLC.exe file path Zscaler 2026-03-02
%programdata%\PolGuid\WingetUI\WingetUI.exe file path Zscaler 2026-03-02
%programdata%\PolGuid\WingetUI\WingetUI.exe.Creates file path Zscaler 2026-03-02
%programdata%\PolGuid\out.txt.Persistence file path Zscaler 2026-03-02
%programdata%\WinDir\WinDirStat.exe file path Check Point Research 2026-07-06
%programdata%\WinWebex file path Zscaler 2026-03-02
HKCU\Software\Microsoft\Windows\CurrentVersion\Run registry The Hacker News 2026-04-30
HKCU\Software\Classes\.wdlp registry Unit 42 2026-03-16

07 — Sourcing, graded

Who told us, and how much that is worth

NATO Admiralty grading. The letter is the source's reliability, the number the credibility of the claim. We separate primary vendor research from outlets reporting on it, because ten articles derived from one report is one report.

GradeSourceBasis
B2MITRE actor record65 references across 35 distinct research hosts
C3Cloudsek6 items — reporting on other vendors' research
B2ESET5 items — primary vendor research
B2Group-IB4 items — primary vendor research
C3The Hacker News4 items — reporting on other vendors' research
B2Zscaler2 items — primary vendor research
B2Check Point Research2 items — primary vendor research
—Estate telemetryno data — absent, not negative

30 items · 11 outlets · 20% of reporting traces to a single outlet

08 — What we do not know

The gaps, published

Every vendor profile has these. Most omit them, which leaves you unable to tell a quiet actor from an unobserved one.

NO DATA

C2 URI fingerprints

No URI paths, headers or beacon sequences for any family we hold, and no URL indicators at all to derive them from — the indicator set is hashes, hosts and addresses.

NO DATA

Infrastructure

No domains are attributed to this actor in our holdings, so no naming convention, TLD preference or hosting pattern can be derived.

09 — Outlook

Forward judgements

Probability language is ICD 203. Likelihood and confidence are stated separately: how likely we think it is, and how good our basis is for thinking so.

Remains active
our newest reporting on this actor is from 2026-07-21, 60 days ago
ALMOST CERTAINconf HIGH
persistence pointing into world-writable staging continues
a tier-1–2 behaviour, which outlives the tooling that expresses it
VERY LIKELYconf MODERATE

10 — Primary sources

Every reference behind this record

65 of them. Published in full so the page can be checked rather than believed.

blog.morphisec.comhttps://blog.morphisec.com/iranian-fileless-cyberattack-on-israel-word-vulnerabilityunit42.paloaltonetworks.comhttps://unit42.paloaltonetworks.com/unit42-striking-oil-closer-look-adversary-infrastructure/unit42.paloaltonetworks.comhttps://unit42.paloaltonetworks.com/unit42-introducing-the-adversary-playbook-first-up-oilrig/unit42.paloaltonetworks.comhttps://unit42.paloaltonetworks.com/unit42-oopsie-oilrig-uses-threedollars-deliver-new-trojan/unit42.paloaltonetworks.comhttps://unit42.paloaltonetworks.com/unit42-oilrig-uses-rgdoor-iis-backdoor-targets-middle-east/unit42.paloaltonetworks.comhttps://unit42.paloaltonetworks.com/unit42-twoface-webshell-persistent-access-point-lateral-moveunit42.paloaltonetworks.comhttps://unit42.paloaltonetworks.com/unit42-oilrig-actors-provide-glimpse-development-testing-effunit42.paloaltonetworks.comhttps://unit42.paloaltonetworks.com/unit42-analyzing-oilrigs-ops-tempo-testing-weaponization-delunit42.paloaltonetworks.comhttps://unit42.paloaltonetworks.com/unit42-oilrig-malware-campaign-updates-toolset-and-expands-tunit42.paloaltonetworks.comhttps://unit42.paloaltonetworks.com/unit42-oilrig-uses-updated-bondupdater-target-middle-easternunit42.paloaltonetworks.comhttps://unit42.paloaltonetworks.com/unit42-oilrig-group-steps-attacks-new-delivery-documents-newunit42.paloaltonetworks.comhttps://unit42.paloaltonetworks.com/unit42-oilrig-targets-technology-service-provider-governmentunit42.paloaltonetworks.comhttps://unit42.paloaltonetworks.com/the-oilrig-campaign-attacks-on-saudi-arabian-organizations-dpan-unit42.github.iohttps://pan-unit42.github.io/playbook_viewer/fireeye.comhttps://www.fireeye.com/blog/threat-research/2016/05/targeted_attacksaga.htmlfireeye.comhttps://www.fireeye.com/blog/threat-research/2017/12/targeted-attack-in-middle-east-by-apt34.htmgov.ilhttps://www.gov.il/BlobFolder/reports/attack_il/he/CERT-IL-ALERT-W-120.pdfforbes.comhttps://www.forbes.com/sites/thomasbrewster/2017/02/15/oilrig-iran-hackers-cyberespionage-us-turraw.githubusercontent.comhttps://raw.githubusercontent.com/pan-unit42/playbook_viewer/master/playbook_json/oilrig.jsoncfr.orghttps://www.cfr.org/interactive/cyber-operations/oilrigcfr.orghttps://www.cfr.org/interactive/cyber-operations/apt-34crowdstrike.comhttps://www.crowdstrike.com/blog/meet-crowdstrikes-adversary-of-the-month-for-november-helix-kitsymantec-blogs.broadcom.comhttps://symantec-blogs.broadcom.com/blogs/threat-intelligence/shamoon-destructive-threat-re-emerweb.archive.orghttps://web.archive.org/web/20120818235442/https://www.symantec.com/connect/blogs/shamoon-attackcommunity.broadcom.comhttps://community.broadcom.com/symantecenterprise/communities/community-home/librarydocuments/viclearskysec.comhttps://www.clearskysec.com/oilrig/securingtomorrow.mcafee.comhttps://securingtomorrow.mcafee.com/other-blogs/mcafee-labs/shamoon-attackers-employ-new-tool-kiattack.mitre.orghttps://attack.mitre.org/groups/G0049/unit42.paloaltonetworks.comhttps://unit42.paloaltonetworks.com/oilrig-novel-c2-channel-steganography/secureworks.comhttps://www.secureworks.com/research/threat-profiles/cobalt-gypsyfireeye.comhttps://www.fireeye.com/content/dam/collateral/en/mtrends-2018.pdfwired.comhttps://www.wired.com/story/apt-34-iranian-hackers-critical-infrastructure-companies/unit42.paloaltonetworks.comhttps://unit42.paloaltonetworks.com/atoms/evasive-serpens/microsoft.comhttps://www.microsoft.com/security/blog/2022/09/08/microsoft-investigates-iranian-attacks-againstrendmicro.comhttps://www.trendmicro.com/en_us/research/24/j/earth-simnavaz-cyberattacks.htmlmicrosoft.comhttps://www.microsoft.com/en-us/security/blog/2021/11/16/evolving-trends-in-iranian-threat-actorcloud.google.comhttps://cloud.google.com/blog/topics/threat-intelligence/updated-cyber-threat-actor-naming-systeapt.etda.or.thhttps://apt.etda.or.th/cgi-bin/showcard.cgi?u=eeb31f97-edcf-4836-b621-a1865305b91esymantec.comhttps://www.symantec.com/connect/blogs/shamoon-attackssymantec.comhttps://www.symantec.com/connect/blogs/shamoon-back-dead-and-destructive-everunit42.paloaltonetworks.comhttps://unit42.paloaltonetworks.com/unit42-shamoon-2-return-disttrack-wiper/unit42.paloaltonetworks.comhttps://unit42.paloaltonetworks.com/unit42-second-wave-shamoon-2-attacks-identified/symantec.comhttps://www.symantec.com/blogs/threat-intelligence/shamoon-destructive-threat-re-emerges-new-stifireeye.comhttps://www.fireeye.com/blog/threat-research/2019/07/hard-pass-declining-apt34-invite-to-join-thsecurityintelligence.comhttps://securityintelligence.com/posts/new-destructive-wiper-zerocleare-targets-energy-sector-inintezer.comhttps://intezer.com/blog-new-iranian-campaign-tailored-to-us-companies-uses-updated-toolset/

Run it against your own estate

Which of these 19 behaviours do you already detect?

The library is the part we can publish. The platform runs the same detection plan against your own estate, tells you which of these behaviours you already cover, and retro-hunts the rest — on your hardware, with nothing leaving the building.

❯ ESC

THE TRACE · LOCAL INFERENCE · REASONING SHOWN STEP-BY-STEP

Try: “which of our vendors were hit by qilin” · “fortios exposure” · “what changed on our perimeter this week”