logo

Earth Simnavaz (APT34) Targeting UAE and Gulf Regions (Campaign)

ID: eea778fe-7fd3-5ff3-82b7-276a8b1110f2

STIX ID: report--eea778fe-7fd3-5ff3-82b7-276a8b1110f2

Feed Name: Wiz Cloud Threat Landscape

Threat Score
85/100

Date Published: 2024-10-11

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

Trend Micro researchers report that the APT group Earth Simnavaz (aka APT34/OilRig) is actively exploiting CVE-2024-30088 against Microsoft Exchange servers in the UAE and Gulf regions to escalate privileges, deploy backdoors, and steal credentials using .NET malware, PowerShell and IIS-based tools; attackers also leverage ngrok for covert remote access, posing ongoing risks to government and critical-sector organizations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.