G0049

G0049OilRig

Description

[OilRig](https://attack.mitre.org/groups/G0049) is a suspected Iranian threat group that has targeted Middle Eastern and international victims since at least 2014. The group has targeted a variety of sectors, including financial, government, energy, chemical, and telecommunications. It appears the group carries out supply chain attacks, leveraging the trust relationship between organizations to attack their primary targets. FireEye assesses that the group works on behalf of the Iranian government based on infrastructure details that contain references to Iran, use of Iranian infrastructure, and targeting that aligns with nation-state interests.(Citation: Palo Alto OilRig April 2017)(Citation: ClearSky OilRig Jan 2017)(Citation: Palo Alto OilRig May 2016)(Citation: Palo Alto OilRig Oct 2016)(Citation: Unit42 OilRig Playbook 2023)(Citation: FireEye APT34 Dec 2017)(Citation: Unit 42 QUADAGENT July 2018)

References

  1. https://attack.mitre.org/groups/G0049
  2. https://research.checkpoint.com/2021/irans-apt34-returns-with-an-updated-arsenal/
  3. http://www.clearskysec.com/oilrig/
  4. http://researchcenter.paloaltonetworks.com/2016/05/the-oilrig-campaign-attacks-on-saudi-arabian-organizations-deliver-helminth-backdoor/
  5. http://researchcenter.paloaltonetworks.com/2017/04/unit42-oilrig-actors-provide-glimpse-development-testing-efforts/
  6. http://researchcenter.paloaltonetworks.com/2016/10/unit42-oilrig-malware-campaign-updates-toolset-and-expands-targets/
  7. https://researchcenter.paloaltonetworks.com/2018/07/unit42-oilrig-targets-technology-service-provider-government-agency-quadagent/
  8. https://www.crowdstrike.com/blog/meet-crowdstrikes-adversary-of-the-month-for-november-helix-kitten/
  9. https://www.fireeye.com/blog/threat-research/2017/12/targeted-attack-in-middle-east-by-apt34.html
  10. https://www.secureworks.com/research/threat-profiles/cobalt-gypsy

Software attributed to this5

TypeTargetConfidenceTier
SoftwareQUADAGENTs0269100%live
SoftwareSideTwists0610100%live
SoftwareBONDUPDATERs0360100%live
SoftwareSEASHARPEEs0185100%live
SoftwareOopsIEs026495%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Group
APT33
Group
HEXANE
Group
APT39
Group
DarkHydrus
Group
Leafminer
Group
MuddyWater
Sourced from MITRE ATT&CK Enterprise 14.1. Curated by Adam Lundqvist, SQUR.