Initial Access
2 techniques·derived
Job-offer and CV-themed lures aimed at energy and government staff.
MOIS operation against Gulf energy and government. Had its source code and operator identities leaked on Telegram — then kept operating.
APT34, widely known as OilRig, conducts long-duration espionage against government, energy, telecommunications, and financial targets across the Middle East, with a persistent focus on the Gulf states and on organisations connected to regional energy infrastructure.
Its technical signature is DNS tunnelling. The group encodes command and control inside DNS queries and responses — a protocol that must be permitted outbound in essentially every network, is rarely inspected, and often bypasses proxies and TLS interception entirely. Its DNS implants have been refined across many generations.
The group is also notable for two extraordinary reversals of fortune. In 2019 a persona called Lab Dookhtegan published its source code, operator handles, C2 server details, and victim credentials on Telegram — an apparent insider leak that exposed the operation from the inside. Separately, and unusually, APT34 has been on the receiving end of another state's tradecraft: in October 2019 the UK NCSC and NSA jointly disclosed that Russia's Turla had compromised OilRig's infrastructure and implants, and was running its own operations through them so that victims would attribute the activity to Iran.
Neither event stopped it. The group rebuilt and continues to operate, with recent campaigns using Microsoft Exchange servers as C2 channels — exfiltrating stolen data as email through the victim's own mail infrastructure.
Down to the named unit where public evidence supports it.
Assessed as operating on behalf of Iran's Ministry of Intelligence and Security, based on FireEye/Mandiant analysis of infrastructure and operator artifacts, the 2019 Lab Dookhtegan leak of internal tooling and operator identities, and consistent industry reporting. Targeting aligns closely with Iranian strategic interests in the Gulf. No individuals have been indicted specifically for APT34 operations.
Attributing sources
12 designators across 11 organisations.
2 designators are marked partial — the vendor's cluster overlaps this group but is not synonymous with it. Treating a partial correlation as an equivalence is the most common source of attribution error when pivoting between vendor reports.
Assigns a stable Gxxxx group ID and adopts the most widely used public name. Deliberately conservative — MITRE merges clusters only when public reporting supports it.
Weather-event family encodes the attributed origin; the adjective is arbitrary. Renamed from the older element taxonomy (STRONTIUM, NOBELIUM, HAFNIUM) in April 2023. 'Storm-####' is a temporary designator for a cluster still in development.
Animal denotes attributed nation-state or motive; the adjective distinguishes clusters. The original public adversary taxonomy, in use since 2012.
APTxx for state-nexus espionage, FINxx for financially motivated, UNCxxxx ('uncategorized') for clusters not yet graduated to a named group. Many UNC numbers are later merged into an APT/FIN designator.
Metal prefix encodes attributed origin, paired with an arbitrary uppercase codeword.
Constellation denotes attributed origin or motive, adopted in 2023 to replace ad-hoc naming.
Descriptive names, frequently derived from the group's flagship malware family.
Descriptive names, often coined from a distinctive string or artifact in the toolset.
'Earth <name>' for many state-nexus groups; older clusters retain descriptive names such as Pawn Storm.
Mineral names for groups with demonstrated or assessed intent against industrial control systems. A Dragos designator is a meaningful signal: it means OT/ICS capability, not just IT intrusion.
U.S. government advisories generally reference groups by the most common industry name plus the attributed unit. Joint advisories are the authoritative source for unit-level attribution.
Target sectors
Target geography
Custom tooling is a strong clustering signal; shared and commodity tooling is not.
Custom / bespoke
Signature capability — C2 encoded inside DNS queries and responses, traversing networks where all other outbound protocols are inspected.
PowerShell backdoors with DNS-based C2 and staged plugin loading.
Malpedia ↗Selective backdoor that fingerprints the host and executes only on intended targets.
C-based backdoor delivered via job-themed lure documents.
Exfiltration routed as email through the victim's own Exchange server, so stolen data leaves as ordinary mail traffic.
IIS backdoor providing a passive fallback channel when primary access is lost.
Malpedia ↗Shared, commodity & living-off-the-land
Credential dumping using recompiled variants to evade signature detection.
Filtered on the date this actor was first reported exploiting the flaw — not the CVE's publication date.
| CVE | Product | Usage by APT34 | ||
|---|---|---|---|---|
| CVE-2022-47966KEVransomware | 9.8 | Zoho ManageEngineZoho | 1 Jan 2023 | Zoho ManageEngine unauthenticated RCE exploited against government targets in the region.SRCUnit 42 ↗ |
| CVE-2021-26855KEVransomware | 9.8 | Microsoft Exchange ServerMicrosoft | 1 May 2021 | ProxyLogon exploited for Exchange access, aligning with the group's later use of Exchange as an exfiltration channel.SRCESET ↗ |
| CVE-2020-0688KEVransomware | 8.8 | Microsoft Exchange ServerMicrosoft | 1 Jun 2020 | Exchange validation key flaw exploited for SYSTEM-level code execution on mail servers.SRCMicrosoft Threat Intelligence ↗ |
| CVE-2017-11882KEVransomware | 7.8 | Microsoft OfficeMicrosoft | 1 Dec 2017 | Equation Editor overflow embedded in lure documents delivering POWRUNER against Middle East government targets.SRCMandiant / FireEye ↗ |
Actors sharing exploited CVEs
How this actor moves through an intrusion, stage by stage, titled by ATT&CK tactic. Read left to right.
2 techniques·derived
Job-offer and CV-themed lures aimed at energy and government staff.
2 techniques·derived
RGDoor IIS backdoor as passive fallback.
2 techniques·derived
Capturing plaintext passwords at change time on domain controllers.
1 technique·derived
Local Data Staging.
2 techniques·derived
The group's defining technique — DNS tunnelling across many implant generations.
1 technique·derived
Data exfiltrated as email through the victim's own Exchange server.
Scroll horizontally · characteristic chain across documented operations, not a single incident
Grouped in kill-chain order.
Job-offer and CV-themed lures aimed at energy and government staff
RGDoor IIS backdoor as passive fallback
Capturing plaintext passwords at change time on domain controllers
The group's defining technique — DNS tunnelling across many implant generations
Data exfiltrated as email through the victim's own Exchange server
A persona calling itself Lab Dookhtegan published OilRig's source code, operator handles, C2 server details, and victim credentials on Telegram — an apparent insider leak exposing an active state operation from the inside. The group rebuilt and resumed operations.
Relationship type and confidence stated explicitly — 'related' without qualification is not an assessment.
Turla compromised OilRig's infrastructure and implants and ran operations through them under Iranian cover — jointly disclosed by NCSC-UK and NSA in 2019.
Both MOIS-linked with overlapping regional targeting and occasional shared infrastructure.
Both Iranian state-nexus against energy targets; different services and distinct toolsets.
Curated links to the reports that established what is known about this group.