Earth Simnavaz (APT34) Targeting UAE and Gulf Regions (Campaign)
ID: eea778fe-7fd3-5ff3-82b7-276a8b1110f2
STIX ID: report--eea778fe-7fd3-5ff3-82b7-276a8b1110f2
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2024-10-11
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
Trend Micro researchers report that the APT group Earth Simnavaz (aka APT34/OilRig) is actively exploiting CVE-2024-30088 against Microsoft Exchange servers in the UAE and Gulf regions to escalate privileges, deploy backdoors, and steal credentials using .NET malware, PowerShell and IIS-based tools; attackers also leverage ngrok for covert remote access, posing ongoing risks to government and critical-sector organizations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
