OilRig: Iran’s Persistent Espionage Arm in Cyberspace
ID: 9a81b97d-20d9-5cb5-bc26-dfc8f0e2e804
STIX ID: report--9a81b97d-20d9-5cb5-bc26-dfc8f0e2e804
Feed Name: Brandefense Blog
OilRig (APT34) is profiled as an Iranian state-aligned cyber-espionage actor conducting sustained campaigns against government, energy, and defense organizations across the Middle East and Europe. The report documents spearphishing and credential-harvesting operations, use of cloud services for persistence and C2, modular implants (Tonedeaf, Helminth, Karkoff, etc.), DNS/HTTPS tunneling for exfiltration, and an evolution toward sophisticated cloud abuse; recommended mitigations include email hardening, cloud monitoring, EDR/behavioral detection, and MFA.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
