OilRig
MISPNation-state
IR
Unknown
[OilRig](https://attack.mitre.org/groups/G0049) is a suspected Iranian threat group that has targeted Middle Eastern and international victims since at least 2014. The group has targeted a variety of sectors, including financial, government, energy, chemical, and telecommunications. It appears the group carries out supply chain attacks, leveraging the trust relationship between organizations to attack their primary targets. The group works on behalf of the Iranian government based on infrastructure details that contain references to Iran, use of Iranian infrastructure, and targeting that aligns with nation-state interests.(Citation: FireEye APT34 Dec 2017)(Citation: Palo Alto OilRig April 2017)(Citation: ClearSky OilRig Jan 2017)(Citation: Palo Alto OilRig May 2016)(Citation: Palo Alto OilRig Oct 2016)(Citation: Unit42 OilRig Playbook 2023)(Citation: Unit 42 QUADAGENT July 2018)
Tecniche Utilizzate (76)
| ID | ATT&CK | Tattiche |
|---|---|---|
| T1003.001 | LSASS Memory | - |
| T1003.004 | LSA Secrets | - |
| T1003.005 | Cached Domain Credentials | - |
| T1005 | Data from Local System | - |
| T1007 | System Service Discovery | - |
| T1008 | Fallback Channels | - |
| T1012 | Query Registry | - |
| T1016 | System Network Configuration Discovery | - |
| T1021.001 | Remote Desktop Protocol | - |
| T1021.004 | SSH | - |
| T1025 | Data from Removable Media | - |
| T1027.005 | Indicator Removal from Tools | - |
| T1027.013 | Encrypted/Encoded File | - |
| T1033 | System Owner/User Discovery | - |
| T1036 | Masquerading | - |
Riferimenti (10)
- blog.morphisec.com - Iranian Fileless Cyberattack On Israel Word Vulnerability
- unit42.paloaltonetworks.com - Unit42 Striking Oil Closer Look Adversary Infrastructure
- unit42.paloaltonetworks.com - Unit42 Introducing The Adversary Playbook First Up Oilrig
- unit42.paloaltonetworks.com - Unit42 Oopsie Oilrig Uses Threedollars Deliver New Trojan
- unit42.paloaltonetworks.com - Unit42 Oilrig Uses Rgdoor Iis Backdoor Targets Middle East
- unit42.paloaltonetworks.com - Unit42 Twoface Webshell Persistent Access Point Lateral Movement
- unit42.paloaltonetworks.com - Unit42 Oilrig Actors Provide Glimpse Development Testing Efforts
- unit42.paloaltonetworks.com - Unit42 Analyzing Oilrigs Ops Tempo Testing Weaponization Delivery
- unit42.paloaltonetworks.com - Unit42 Oilrig Malware Campaign Updates Toolset And Expands Targets
- unit42.paloaltonetworks.com - Unit42 Oilrig Uses Updated Bondupdater Target Middle Eastern Government
Alias (2586)
Malware Utilizzato (30)
Metadata
| ID: | 87 |
| Created: | 13/01/2026 17:48 |
| Updated: | 06/03/2026 04:00 |