{"data":{"slug":"oilrig-apt34","name":"OilRig","aliases":["APT34","Helix Kitten","Cobalt Gypsy","Earth Simnavaz"],"origin":"Iran (state-aligned)","motivation":"Espionage","active":"2014","sectors":["Government","Energy","Finance","Telecom"],"summary":"One of the most persistent espionage groups operating across the Gulf, OilRig conducts long-running intelligence collection against UAE and wider GCC government, energy, and financial targets. It favors patient, credential-driven access and custom backdoors that blend into normal network traffic.","ttps":["Spear-phishing with malicious documents","DNS tunneling for C2 (DNSExfiltrator-style)","Custom backdoors (Karkoff, RDAT, Saitama)","Webshells on internet-facing servers","Abuse of legitimate cloud and email services"],"notable":"Repeatedly observed exfiltrating data over DNS and webmail to evade perimeter controls — a reminder to monitor DNS and outbound mail patterns, not just web traffic.","severity":"Critical","mitreTechniques":[{"id":"T1566","name":"Phishing"},{"id":"T1059.001","name":"PowerShell"},{"id":"T1071.004","name":"DNS (C2)"},{"id":"T1572","name":"Protocol Tunneling"},{"id":"T1505.003","name":"Web Shell"},{"id":"T1078","name":"Valid Accounts"},{"id":"T1003","name":"OS Credential Dumping"},{"id":"T1114","name":"Email Collection"},{"id":"T1048","name":"Exfiltration Over Alternative Protocol"}]},"source":"Curated from open-source reporting + MITRE ATT&CK"}