OilRig (APT34) is a long-running Iranian state espionage group operating since at least 2014, specializing in Gulf-focused intrusions against government, energy, financial, and telecom targets, frequently via supply-chain and trust-relationship abuse.
Additional names this actor is known by across other vendors' naming schemes — cross-referenced from external crosswalk sources, not RaqibCTI's own curated aliases (shown at the top of this page). Each source is attributed to its own licence.
OilRig has been publicly tracked since 2014 and is assessed to work on behalf of the Iranian government, with reporting most recently aligning it to the Ministry of Intelligence and Security (MOIS). Infrastructure details referencing Iran, the use of Iranian hosting, and consistently nation-state-aligned targeting underpin this attribution with high confidence.
The group is known for methodical, long-dwell espionage. It leans on spearphishing, web shells on internet-facing servers (notably Microsoft Exchange), custom backdoors, DNS-tunneling C2, and credential theft. A defining trait is supply-chain and trust-relationship abuse: compromising one organization to pivot into a higher-value primary target. Unit 42's published OilRig 'playbook' catalogues its extensive and evolving toolset.
MENA is OilRig's core theater. Victims cluster in Saudi Arabia, the UAE, Iraq, Jordan, Israel, Kuwait, and Qatar across government, energy, chemical, financial, and telecom sectors. Under the Trend Micro cluster name Earth Simnavaz, late-2024 reporting documented intrusions against UAE and Gulf-state government entities using a backdoor dubbed StealHook to siphon credentials from on-premises Exchange servers, chained with exploitation of a Windows kernel privilege-escalation vulnerability (CVE-2024-30088).
OilRig remained active through 2025, with reporting describing sustained intrusions against energy and defense organizations in Europe and the Middle East leveraging compromised Microsoft 365 accounts and Azure persistence — an assessed shift toward cloud-identity tradecraft. The group is one of the largest and most durable Iranian espionage actors still operating. Check Point Research reporting (corroborated via secondary sources; primary CPR URL unverified) attributes 2024 intrusions into Iraqi government offices — using the Veaty passive-IIS backdoor and Spearal DNS-tunneling backdoor — to the group.
+127 more relationships — see the relationships browser.
These entities are frequently mentioned together in source material; co-occurrence is not a verified relationship.