LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G0049: OilRig

OilRig is a suspected Iranian threat group that has targeted Middle Eastern and international victims since at least 2014. The group has targeted a variety of sectors, including financial, government, energy, chemical, and telecommunications. It appears the group carries out supply chain attacks, leveraging the trust relationship between organizations to attack their primary targets. The group works on behalf of the Iranian government based on infrastructure details that contain references to Iran, use of Iranian infrastructure, and targeting that aligns with nation-state interests.CitationFireEye APT34 Dec 2017CitationPalo Alto OilRig April 2017CitationClearSky OilRig Jan 2017CitationPalo Alto OilRig May 2016CitationPalo Alto OilRig Oct 2016CitationUnit42 OilRig Playbook 2023CitationUnit 42 QUADAGENT July 2018

EnterpriseG0049GroupObject v5.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

OilRig is a suspected Iranian group in ATT&CK associated with long-running targeting of Middle Eastern and international organizations, including financial, government, energy, chemical, and telecommunications sectors. The business issue is not just the group name; it is the pattern of trusted-relationship and supply-chain abuse plus use of common administrative utilities, credential tools, PowerShell backdoors, web shells, and downloader/backdoor campaigns. Leaders should treat this as a test of whether the organization can recognize suspicious use of legitimate tools, investigate identity compromise, and validate third-party trust paths before an incident becomes a broader operational problem.

Executive priority

Prioritize OilRig-relevant readiness where the organization has exposure in the cited sectors, operates in or with the Middle East/Israel, depends on trusted partner connectivity, or runs critical Windows and web server infrastructure. Executive questions should focus on: whether supplier and partner access is logged and reviewable, whether credential theft and lateral movement evidence can be produced quickly, whether incident response can distinguish normal administration from adversary use of tools such as PsExec, Net, Reg, certutil, ftp, and PowerShell, and whether audit/compliance evidence exists for monitoring privileged access and remote administration.

Technical view

ATT&CK provides no official detection text, tactics, or platform list for the group object, so defensive validation should be driven by the relationship context. OilRig is linked to campaigns Outer Space and Juicy Mix, and to tools including Mimikatz, PsExec, Net, Tasklist, Reg, ftp, Systeminfo, ipconfig, netstat, certutil, Helminth, POWRUNER, SEASHARPEE, ISMInjector, RGDoor, OopsIE, QUADAGENT, LaZagne, BONDUPDATER, and RDAT. Many related tools are Windows utilities or Windows malware, while ftp and LaZagne have broader platform references. SOC teams should validate visibility for command-line execution, PowerShell activity, credential access indicators, remote execution, IIS/web shell activity, file transfer, and outbound command-and-control-like communications, while avoiding assumptions that every instance of these tools is malicious.

Likely telemetry

  • Endpoint process creation and command-line logs for Windows utilities such as Net, Reg, Tasklist, Systeminfo, ipconfig, netstat, certutil, ftp, and PsExec
  • PowerShell execution logs, script block/module logging where available, and encoded or remote command execution evidence
  • Credential access telemetry related to tools such as Mimikatz and LaZagne, including LSASS access or suspicious credential store access where locally collected
  • Windows authentication, privileged account use, service creation, administrative share access, and remote execution logs
  • Web server and IIS logs, file integrity evidence, and web shell indicators relevant to SEASHARPEE and RGDoor relationship context

Detection direction

  • Build detections around suspicious combinations rather than single tool names: for example, discovery commands followed by credential access tooling, PsExec-style remote execution, file transfer, or PowerShell backdoor behavior.
  • Tune heavily for administrative false positives. PsExec, Net, Reg, certutil, ftp, ipconfig, netstat, systeminfo, and tasklist are legitimate tools; useful detections require baselines for admin accounts, management servers, change windows, and expected command arguments.
  • Validate PowerShell coverage for related backdoors such as POWRUNER, QUADAGENT, BONDUPDATER, and Helminth, but do not rely only on malware names; focus on suspicious script execution, network callbacks, and file staging patterns.
  • Review web-facing Windows/IIS servers for logging depth and investigation readiness because related software includes IIS/web shell backdoors such as RGDoor and SEASHARPEE.
  • Use the campaign relationships as threat-intelligence context, especially Outer Space and Juicy Mix targeting Israeli organizations, but require local telemetry before escalating to attribution.

Mitigation priorities

  • First, reduce identity blast radius: enforce least privilege for administrator accounts, review privileged group membership, and protect credentials likely to be targeted by credential dumping tools.
  • Second, constrain and monitor remote administration: limit where PsExec-style execution and administrative shares are allowed, and require strong logging for privileged remote activity.
  • Third, harden PowerShell and script execution controls using policy, logging, and review of allowed administrative use cases.
  • Fourth, improve web server hygiene for externally reachable services, including patching, file integrity monitoring, access logging, and rapid web shell triage procedures.
  • Fifth, govern supplier and partner trust paths with named owners, access reviews, logging requirements, and incident contact procedures because the official description notes supply-chain and trust-relationship abuse.
Additional notes and limits

OilRig has many aliases in the supplied ATT&CK data, including APT34, COBALT GYPSY, Helix Kitten, Evasive Serpens, Hazel Sandstorm, EUROPIUM, Earth Simnavaz, Crambus, and TA452. APT34 is shown as revoked into OilRig, including an ICS-domain revoked object, but the supplied OilRig object is enterprise-attack and has no explicit ICS tactics or platforms. Treat alias matching carefully in threat intelligence workflows to avoid duplicate reporting or overconfident attribution.

The supplied object does not include official detection guidance, tactics, labels, or platforms. The technical emphasis on Windows, PowerShell, IIS, credentials, and administrative utilities comes from the listed software relationships, not from an explicit group platform field. Any decision about exposure, detection coverage, or incident attribution requires local logs, asset context, and validated intelligence.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

OilRig

OilRig is a suspected Iranian threat group that has targeted Middle Eastern and international victims since at least 2014. The group has targeted a variety of sectors, including financial, government, energy, chemical, and telecommunications. It appears the group carries out supply chain attacks, leveraging the trust relationship between organizations to attack their primary targets. The group works on behalf of the Iranian government based on infrastructure details that contain references to Iran, use of Iranian infrastructure, and targeting that aligns with nation-state interests.CitationFireEye APT34 Dec 2017CitationPalo Alto OilRig April 2017CitationClearSky OilRig Jan 2017CitationPalo Alto OilRig May 2016CitationPalo Alto OilRig Oct 2016CitationUnit42 OilRig Playbook 2023CitationUnit 42 QUADAGENT July 2018

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

Relationship explorer

All related ATT&CK context

No relationships are available in the current normalized data for this object.

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
5.0
Created
Modified
Raw hash
74d7f9e30c9d8e47...
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.