Skip to content
IranState-SponsoredActiveMITRE G0049Malpedia ↗

APT34

MOIS operation against Gulf energy and government. Had its source code and operator identities leaked on Telegram — then kept operating.

Open MITRE Navigator layer ↗Download profile JSON
Active
2014–present
Motivation
Espionage
Aliases
12
Exploited CVEs
4
ATT&CK techniques
10
Cited sources
10

Overview

APT34, widely known as OilRig, conducts long-duration espionage against government, energy, telecommunications, and financial targets across the Middle East, with a persistent focus on the Gulf states and on organisations connected to regional energy infrastructure.

Its technical signature is DNS tunnelling. The group encodes command and control inside DNS queries and responses — a protocol that must be permitted outbound in essentially every network, is rarely inspected, and often bypasses proxies and TLS interception entirely. Its DNS implants have been refined across many generations.

The group is also notable for two extraordinary reversals of fortune. In 2019 a persona called Lab Dookhtegan published its source code, operator handles, C2 server details, and victim credentials on Telegram — an apparent insider leak that exposed the operation from the inside. Separately, and unusually, APT34 has been on the receiving end of another state's tradecraft: in October 2019 the UK NCSC and NSA jointly disclosed that Russia's Turla had compromised OilRig's infrastructure and implants, and was running its own operations through them so that victims would attribute the activity to Iran.

Neither event stopped it. The group rebuilt and continues to operate, with recent campaigns using Microsoft Exchange servers as C2 channels — exfiltrating stolen data as email through the victim's own mail infrastructure.

Attribution

Down to the named unit where public evidence supports it.

IranMOIS — Ministry of Intelligence and SecurityHigh confidence

Assessed as operating on behalf of Iran's Ministry of Intelligence and Security, based on FireEye/Mandiant analysis of infrastructure and operator artifacts, the 2019 Lab Dookhtegan leak of internal tooling and operator identities, and consistent industry reporting. Targeting aligns closely with Iranian strategic interests in the Gulf. No individuals have been indicted specifically for APT34 operations.

Attributing sources

Cross-vendor naming crosswalk

12 designators across 11 organisations.

2 designators are marked partial — the vendor's cluster overlaps this group but is not synonymous with it. Treating a partial correlation as an equivalence is the most common source of attribution error when pivoting between vendor reports.

MITRE ATT&CK

index ↗
  • OilRig

Assigns a stable Gxxxx group ID and adopts the most widely used public name. Deliberately conservative — MITRE merges clusters only when public reporting supports it.

Microsoft Threat Intelligence

index ↗
  • Hazel SandstormFormerly EUROPIUM
  • EUROPIUMRetired designator

Weather-event family encodes the attributed origin; the adjective is arbitrary. Renamed from the older element taxonomy (STRONTIUM, NOBELIUM, HAFNIUM) in April 2023. 'Storm-####' is a temporary designator for a cluster still in development.

CrowdStrike

index ↗
  • Helix Kitten

Animal denotes attributed nation-state or motive; the adjective distinguishes clusters. The original public adversary taxonomy, in use since 2012.

Mandiant / Google Threat Intelligence

index ↗
  • APT34

APTxx for state-nexus espionage, FINxx for financially motivated, UNCxxxx ('uncategorized') for clusters not yet graduated to a named group. Many UNC numbers are later merged into an APT/FIN designator.

Secureworks CTU

index ↗
  • COBALT GYPSY

Metal prefix encodes attributed origin, paired with an arbitrary uppercase codeword.

Palo Alto Networks Unit 42

index ↗
  • Evasive Serpens

Constellation denotes attributed origin or motive, adopted in 2023 to replace ad-hoc naming.

ESET Research

index ↗
  • OilRig

Descriptive names, frequently derived from the group's flagship malware family.

Kaspersky GReAT

index ↗
  • ChrysenepartialDragos designator for an overlapping ICS-adjacent cluster

Descriptive names, often coined from a distinctive string or artifact in the toolset.

Trend Micro

index ↗
  • Earth Simnavaz

'Earth <name>' for many state-nexus groups; older clusters retain descriptive names such as Pawn Storm.

Dragos

index ↗
  • CHRYSENEpartialDragos tracks the industrial-adjacent element of this activity

Mineral names for groups with demonstrated or assessed intent against industrial control systems. A Dragos designator is a meaningful signal: it means OT/ICS capability, not just IT intrusion.

CISA / NSA / FBI

index ↗
  • OilRig

U.S. government advisories generally reference groups by the most common industry name plus the attributed unit. Joint advisories are the authoritative source for unit-level attribution.

Targeting

Target geography

Saudi ArabiaUnited Arab EmiratesKuwaitQatarIsraelJordanLebanonUnited StatesUnited KingdomAlbania

Tools & malware

Custom tooling is a strong clustering signal; shared and commodity tooling is not.

Custom / bespoke

DNSExfiltrator / DNS tunnelling implantsbackdoor

Signature capability — C2 encoded inside DNS queries and responses, traversing networks where all other outbound protocols are inspected.

POWRUNER / BONDUPDATERbackdoor

PowerShell backdoors with DNS-based C2 and staged plugin loading.

Malpedia ↗
Karkoffbackdoor

Selective backdoor that fingerprints the host and executes only on intended targets.

SideTwistbackdoor

C-based backdoor delivered via job-themed lure documents.

Exchange as C2utility

Exfiltration routed as email through the victim's own Exchange server, so stolen data leaves as ordinary mail traffic.

Web shells (RGDoor)utility

IIS backdoor providing a passive fallback channel when primary access is lost.

Malpedia ↗

Shared, commodity & living-off-the-land

Mimikatz variantslotl

Credential dumping using recompiled variants to evade signature detection.

Exploited vulnerabilities

Filtered on the date this actor was first reported exploiting the flaw — not the CVE's publication date.

CVEUsage by APT34
CVE-2022-47966KEVransomware9.81 Jan 2023Zoho ManageEngine unauthenticated RCE exploited against government targets in the region.SRCUnit 42
CVE-2021-26855KEVransomware9.81 May 2021ProxyLogon exploited for Exchange access, aligning with the group's later use of Exchange as an exfiltration channel.SRCESET
CVE-2020-0688KEVransomware8.81 Jun 2020Exchange validation key flaw exploited for SYSTEM-level code execution on mail servers.SRCMicrosoft Threat Intelligence
CVE-2017-11882KEVransomware7.81 Dec 2017Equation Editor overflow embedded in lure documents delivering POWRUNER against Middle East government targets.SRCMandiant / FireEye

Kill chain

How this actor moves through an intrusion, stage by stage, titled by ATT&CK tactic. Read left to right.

6 stages · 10 techniques

Scroll horizontally · characteristic chain across documented operations, not a single incident

MITRE ATT&CK techniques

Grouped in kill-chain order.

Open in Navigator ↗
10 techniques across 6 tactics · 5 with actor-specific notes

Initial Access

2

Persistence

2

Credential Access

2

Command and Control

2

Exfiltration

1

Campaign timeline

  1. Lab Dookhtegan Source Code Leak

    A persona calling itself Lab Dookhtegan published OilRig's source code, operator handles, C2 server details, and victim credentials on Telegram — an apparent insider leak exposing an active state operation from the inside. The group rebuilt and resumed operations.

    GovernmentEnergyFinancial ServicesTelecommunications

Known to work with

Relationship type and confidence stated explicitly — 'related' without qualification is not an assessment.

Primary-source reporting

Curated links to the reports that established what is known about this group.