Threat actor · all actors
OilRigG0049 state
🇮🇷 IR · MOIS
aka OilRig, COBALT GYPSY, IRN2, APT34, Helix Kitten, Evasive Serpens, Hazel Sandstorm, EUROPIUM, ITG13, Earth Simnavaz, Crambus, TA452, Twisted Kitten, APT 34, ATK40, G0049, SOLAR ION, Greenbug, CHRYSENE
Last updated: 2026-08-22
About this actor
[OilRig](https://attack.mitre.org/groups/G0049) is a suspected Iranian threat group that has targeted Middle Eastern and international victims since at least 2014. The group has targeted a variety of sectors, including financial, government, energy, chemical, and telecommunications. It appears the group carries out supply chain attacks, leveraging the trust relationship between organizations to attack their primary targets. The group works on behalf of the Iranian government based on infrastructure details that contain references to Iran, use of Iranian infrastructure, and targeting that aligns with nation-state interests.(Citation: FireEye APT34 Dec 2017)(Citation: Palo Alto OilRig April 2017)(Citation: ClearSky OilRig Jan 2017)(Citation: Palo Alto OilRig May 2016)(Citation: Palo Alto OilRig Oct 2016)(Citation: Unit42 OilRig Playbook 2023)(Citation: Unit 42 QUADAGENT July 2018)
Source: MITRE ATT&CK
Names & naming systems
Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.
MITRE ATT&CKG-number catalogue id
Microsoftweather-system names
CrowdStrikenation-animal names
Mandiant / genericAPT numbering
Secureworkscolour-metal names
ProofpointTA threat-actor id
Unclassifiedno scheme matched
How we know this
- Data origin
- MITRE ATT&CK Imported from the MITRE ATT&CK STIX bundle as an intrusion-set object.
- Techniques
- MITRE ATT&CK STIX mappings — 103 ATT&CK techniques on file.
- Named victims
- None on file.
See how actor data is built for the full pipeline.
Activity timeline
- 2026 — 1 CVE published
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
CVE-2026-20929 | 5.9 | 7.5 | 0.0116 | 2026-01-13 | see CVE |
T1003OS Credential Dumping ↗T1003.001LSASS Memory ↗T1003.004LSA Secrets ↗T1003.005Cached Domain Credentials ↗T1005Data from Local System ↗T1007System Service Discovery ↗T1008Fallback Channels ↗T1012Query Registry ↗T1016System Network Configuration Discovery ↗T1021Remote Services ↗T1021.001Remote Desktop Protocol ↗T1021.004SSH ↗T1025Data from Removable Media ↗T1027Obfuscated Files or Information ↗T1027.005Indicator Removal from Tools ↗T1027.013Encrypted/Encoded File ↗T1033System Owner/User Discovery ↗T1036Masquerading ↗T1036.005Match Legitimate Resource Name or Location ↗T1046Network Service Discovery ↗T1047Windows Management Instrumentation ↗T1048Exfiltration Over Alternative Protocol ↗T1048.003Exfiltration Over Unencrypted Non-C2 Protocol ↗T1049System Network Connections Discovery ↗T1053Scheduled Task/Job ↗T1053.005Scheduled Task ↗T1056Input Capture ↗T1056.001Keylogging ↗T1057Process Discovery ↗T1059Command and Scripting Interpreter ↗T1059.001PowerShell ↗T1059.003Windows Command Shell ↗T1059.005Visual Basic ↗T1068Exploitation for Privilege Escalation ↗T1069Permission Groups Discovery ↗T1069.001Local Groups ↗T1069.002Domain Groups ↗T1070Indicator Removal ↗T1070.004File Deletion ↗T1071Application Layer Protocol ↗T1071.001Web Protocols ↗T1071.004DNS ↗T1078Valid Accounts ↗T1078.002Domain Accounts ↗T1082System Information Discovery ↗T1087Account Discovery ↗T1087.001Local Account ↗T1087.002Domain Account ↗T1105Ingress Tool Transfer ↗T1110Brute Force ↗T1112Modify Registry ↗T1113Screen Capture ↗T1115Clipboard Data ↗T1119Automated Collection ↗T1120Peripheral Device Discovery ↗T1133External Remote Services ↗T1137Office Application Startup ↗T1137.004Outlook Home Page ↗T1140Deobfuscate/Decode Files or Information ↗T1195Supply Chain Compromise ↗T1201Password Policy Discovery ↗T1203Exploitation for Client Execution ↗T1204User Execution ↗T1204.001Malicious Link ↗T1204.002Malicious File ↗T1218System Binary Proxy Execution ↗T1218.001Compiled HTML File ↗T1219Remote Access Tools ↗T1497Virtualization/Sandbox Evasion ↗T1497.001System Checks ↗T1505Server Software Component ↗T1505.003Web Shell ↗T1543Create or Modify System Process ↗T1543.003Windows Service ↗T1552Unsecured Credentials ↗T1552.001Credentials In Files ↗T1553Subvert Trust Controls ↗T1553.002Code Signing ↗T1555Credentials from Password Stores ↗T1555.003Credentials from Web Browsers ↗T1555.004Windows Credential Manager ↗T1556Modify Authentication Process ↗T1556.002Password Filter DLL ↗T1566Phishing ↗T1566.001Spearphishing Attachment ↗T1566.002Spearphishing Link ↗T1566.003Spearphishing via Service ↗T1572Protocol Tunneling ↗T1573Encrypted Channel ↗T1573.002Asymmetric Cryptography ↗T1583Acquire Infrastructure ↗T1583.001Domains ↗T1586Compromise Accounts ↗T1586.002Email Accounts ↗T1587Develop Capabilities ↗T1587.001Malware ↗T1588Obtain Capabilities ↗T1588.002Tool ↗T1588.003Code Signing Certificates ↗T1608Stage Capabilities ↗T1608.001Upload Malware ↗T1686Disable or Modify System Firewall ↗T1686.003Windows Host Firewall ↗
Mitigating controls (NIST 800-53)
| Control | Techniques covered | Coverage |
|---|---|---|
SI-4 | 65 / 103 | 63% |
CM-6 | 61 / 103 | 59% |
CM-2 | 56 / 103 | 54% |
CM-7 | 45 / 103 | 44% |
SI-3 | 44 / 103 | 43% |
AC-6 | 43 / 103 | 42% |
CA-7 | 41 / 103 | 40% |
AC-3 | 40 / 103 | 39% |
AC-2 | 38 / 103 | 37% |
AC-4 | 29 / 103 | 28% |
SC-7 | 27 / 103 | 26% |
SI-7 | 27 / 103 | 26% |
AC-5 | 25 / 103 | 24% |
IA-2 | 24 / 103 | 23% |
CM-5 | 23 / 103 | 22% |
Co-occurring actors
- Ajax Security Team 1 shared CVEs
- APT29 1 shared CVEs
- APT38 1 shared CVEs
- Sandworm Team 1 shared CVEs
- Tonto Team 1 shared CVEs
- GOLD SOUTHFIELD 1 shared CVEs
- Scattered Spider 1 shared CVEs
- Indrik Spider 1 shared CVEs
- Mustang Panda 1 shared CVEs
- SolarWinds Compromise 1 shared CVEs
Similar actors
Similar TTPs
- Operation Wocao 0.38
- Threat Group-3390 0.37
- FIN7 0.36
- APT32 0.35
- Mustang Panda 0.35
Overlapping CVEs
- C0027 1.00
- APT12 1.00
- APT28 1.00
- FIN7 1.00
- Tropic Trooper 1.00
Active in same years
- Operation Dream Job 1.00
- SolarWinds Compromise 1.00
- C0027 1.00
- SharePoint ToolShell Exploitation 1.00
- Ke3chang 1.00
Same nation-state
- HomeLand Justice 1.00
- Outer Space 1.00
- Juicy Mix 1.00
- Cleaver 1.00
- CopyKittens 1.00
Same category
- Night Dragon 1.00
- FunnyDream 1.00
- C0011 1.00
- Operation Wocao 1.00
- Operation Dream Job 1.00