Inside APT34 Saudi Arabia Attacks: TTPs and Mitigations
While hacktivists launch noisy DDoS attacks to generate headlines, state-sponsored ghosts prefer to operate in the shadows. Recent…
> CLASSIFIED_DOSSIER :: THREAT_ACTOR_PROFILE
/actor/oilrig/ · 1 intel report
OilRig, tracked by various researchers as APT34, is a sophisticated Iranian state-sponsored threat actor attributed to either the Ministry of Intelligence and Security (MOIS) or the Islamic Revolutionary Guard Corps (IRGC), and assessed to be one of Tehran's most capable and long-running cyber espionage tools. Active since at least 2014, OilRig's primary mandate centres on intelligence collection against governments, critical infrastructure operators, financial institutions, and technology companies across the Middle East , with particular focus on nations in the Gulf Cooperation Council (GCC) region.
OilRig's tradecraft is distinguished by highly tailored spear-phishing campaigns using geopolitically relevant lure documents, combined with a continuously evolving suite of custom malware tools including POWRUNER, BONDUPDATER, RDAT, and TONEDEAF. The group frequently uses legitimate web services including social media platforms and cloud storage for command-and-control communications, blending malicious traffic with normal business internet usage to evade detection.
A significant chapter in OilRig's history occurred in 2019, when a Telegram channel called "Lab Dookhtegan" published the group's complete toolset, source code, infrastructure, and victim list , an unprecedented exposure of a nation-state threat actor's operational details, likely perpetrated by an insider or rival intelligence service. Despite this exposure, OilRig continued operations with new tooling, demonstrating Iranian state cyber capabilities' resilience to exposure.
OilRig has been linked to attacks against Saudi Aramco's IT systems, multiple Gulf state government ministries, telecom providers across the Middle East, and international organisations with regional operations , making them a persistent and high-priority threat for organisations operating in the Middle East energy and government sectors.
Threat Mitigation and Strategic Hardening: Network defense against campaigns linked to OilRig requires continuous threat surface management, dark web monitoring for stolen employee credentials, and automated telemetry correlation. Organizations should reference our Cyber Risk Checker and report critical indicators via Secure Drop.
While hacktivists launch noisy DDoS attacks to generate headlines, state-sponsored ghosts prefer to operate in the shadows. Recent…