In this article

Iran's APTs and the U.S. Enterprise in 2026: APT34 (OilRig)

Post 5 of 5. APT34 is Iran's most technically mature espionage operation. A decade of refinement turned it into a group that barely needs malware: it takes your credentials, your Exchange server, and more patience than your defenders have.

a black and red logo with the word ikela
By KELA Cyber Intelligence Center
a man in a suit and tie looking at the camera
Fact-check by Lewis Henderson, Director, Intelligence Communications

Published July 22, 2026

OilRig

In late 2024, APT34 slipped a single malicious DLL onto a victim's domain controller. From then on, every time someone changed their password, the new one was captured in plaintext surrendered by the organization's own authentication system. The stolen data left as routine email, routed through the victim's own Exchange server. Almost none of it looked like an attack.

If you read Post 4, the contrast closes the loop. Prince of Persia is the actor that refuses to die; APT34 is the one that needs no reframing to threaten a US enterprise. It has already breached a US government contractor, pairs long-dwell espionage with genuinely destructive wipers, and has spent recent years learning to run an entire intrusion on the tools and credentials already inside your network.

This post walks through APT34's tradecraft end to end, and why identity and your own infrastructure, not your perimeter, are where an intrusion like this is caught, or missed.

» Strengthen your cybersecurity with KELA's expertise

Who is APT 34?

APT34 is a state-sponsored cyber espionage group active since at least 2014, strongly linked to Iran's Ministry of Intelligence and Security (MOIS) and operating as a cyber contractor advancing the regime's national-security, geopolitical, and economic objectives.

Where several Iranian clusters are defined by persistence over polish, APT34 is defined by both. It sits inside a broader contractor ecosystem with documented operational overlaps with the IRGC and with groups such as APT33 and APT39, and while its primary mission is long-term intelligence collection, it has engaged in destructive sabotage when that aligns with Iranian state objectives.

» Find out why your organization needs cyber threat intelligence

APT34 (OilRig) at a Glance

  • Aliases: OilRig (Palo Alto Unit 42), APT34 (Mandiant), Helix Kitten / Twisted Kitten (CrowdStrike), Cobalt Gypsy (Secureworks), Crambus (Symantec), Earth Simnavaz (Trend Micro), Hazel Sandstorm (Microsoft, formerly EUROPIUM), Evasive Serpens (Palo Alto Unit 42), IRN2 (Area 1), ITG13 (IBM X-Force), TA452 (Proofpoint), ATK40 (Thales), G0049 (MITRE ATT&CK)
  • Operates from: Iran
  • Sponsor / Backing: Iranian Ministry of Intelligence and Security (MOIS), with operational overlaps with the IRGC, APT33, and APT39.
  • Active since: At least 2014
  • Ideology / motivation: State-directed espionage, asymmetric retaliation, and power projection without crossing borders, with destructive sabotage deployed when aligned with regime objectives.

Typical Victims

Middle East core, expanding to the U.S., Europe, and Asia.

The group primarily targets:

  • Government
  • Energy (oil and gas)
  • Chemical
  • Finance
  • Telecommunications
  • Aviation
  • IT service providers

Signature Tactics, Techniques, and Procedures (TTPs)

  • Email-based C2 over Exchange/EWS
  • DNS tunneling
  • IIS web shells
  • Password-filter DLLs
  • Living-off-the-land with stolen credentials

» Learn how leaked credentials differ from compromised accounts

Notable Activity (2025–2026)

Historically a Gulf-and-Israel problem targeting energy, government, finance, and telecommunications across Saudi Arabia, the UAE, Israel, Jordan, Iraq, and Bahrain APT34 has steadily globalized, with confirmed operations against U.S., European, and Asian entities.

Its most recent named activity in the KELA report, the Earth Simnavaz campaign of late 2024, exploited a Windows kernel flaw to plant a malicious password-filter DLL on a victim's Exchange server, harvested plaintext credentials the moment users changed them, and exfiltrated the results through legitimate email traffic.

For security leaders, the business impact is the kind that surfaces late, if at all. APT34 rarely arrives with malware—it logs in.

Stolen credentials, valid accounts, web shells on your Exchange server, and a password-filter DLL on a domain controller let it read mail, harvest credentials, and quietly exfiltrate data for months while the traffic reads as routine administration. Little of that is what an EDR is tuned to catch, so the cost is not a noisy incident but a prolonged, low-signal loss of sensitive data and a foothold that is hard to evict once the actor is operating as a legitimate user.

Two factors raise the ceiling:

  • The group reaches enterprises through trusted IT and telecommunications providers, so a U.S. organization with no Iran nexus of its own can still be compromised through a vendor that has one.
  • While espionage is the default, the Shamoon and ZeroCleare lineage means destructive capability is held in reserve.

The 2020 Westat breach already placed U.S. enterprises inside the target set, and APT34's doctrine is engineered to defeat the malware-centric defenses most of them still run.

» Here's everything you should know about credential compromise

Decade of Espionage: The Campaign Arc

Regional Rivalry and Social Engineering (2015–2017)

Emerging partly out of the Iran–Saudi Arabia rivalry, OilRig's early campaigns hit Saudi defense, financial, and technology targets, using the Helminth backdoor delivered through fake job offers and macro-laden "Clayslide" Excel documents.

By 2017, the group had expanded into Israel and matured its social engineering, most memorably through the fabricated LinkedIn persona "Mia Ash," used to cultivate and then compromise energy-sector personnel.

The pattern set here trust built before payload delivered still defines the group.

Wipers and Exposure (2018–2019)

APT34 was linked to destructive operations using wiper malware in the Shamoon v3 and ZeroCleare families against Middle Eastern critical infrastructure and energy targets, a reminder that espionage and sabotage live on the same toolbench.

Then, in March 2019, the pseudonymous "Lab Dookhtegan" leak dumped a large cache of OilRig tooling (including PoisonFrog and Glimpse) and victim data.

The exposure briefly stalled operations.

The instructive part is what happened next: the group retooled and upgraded its arsenal rather than disbanding, and resumed.

Escalation and the Move Toward the U.S. (2020)

After the assassination of Qasem Soleimani and tightening sanctions, APT34 widened its aperture beyond the region.

It targeted Westat, a U.S. government contractor, using updated Tonedeaf and ValueVault malware to harvest credentials, while the parallel Fox Kitten activity exploited unpatched VPNs to reach global infrastructure.

This is the inflection point U.S. defenders should anchor on the moment OilRig stopped being someone else's problem.

The Pivot to Living Off the Land (2023–2024)

The most recent named campaigns show the group's current doctrine.

In the Crambus intrusion (2023), an eight-month operation against Middle Eastern government entities, APT34 deployed PowerExchange, a PowerShell backdoor that watched a compromised Exchange server's inbox to receive commands and exfiltrate data as email.

In a 2024 breach of high-profile Iraqi government offices, it fielded the Veaty and Spearal families using passive IIS backdoors and DNS tunneling.

In late 2024, the Earth Simnavaz campaign against the Middle Eastern energy sector chained CVE-2024-30088, a Windows kernel elevation-of-privilege flaw, with a malicious password-filter DLL to lift plaintext credentials from Exchange and quietly mail them out.

Across all three, the through line is the same: less custom malware, more abuse of what is already in the environment.

TTPs: How APT34 Operates

Tradecraft Summary

Three characteristics define how APT34 operates today, and together they explain why it is so hard to detect.

  • First, it weaponizes identity and legitimate infrastructure. Stolen credentials, native administration tools, IIS web shells, and the victim's own Exchange server systematically blind signature- and malware-centric detection.
  • Second, it favors IT service providers and telecommunications providers as supply-chain entry points. A compromise can arrive through a trusted vendor rather than across the perimeter.
  • Third, it is patient. Intrusions are measured in months, with long-term intelligence collection as the objective and destructive capability held in reserve.

The implication for defenders is unambiguous: Hunting for malware will not reliably surface this actor. Identity resilience and zero-trust segmentation will.

APT34's tradecraft is best understood in five stages, with inline MITRE ATT&CK technique IDs hyperlinked to their canonical pages and the full mapping in the appendix.

» Here are the most targeted entry points by hackers

1. Initial Access and Reconnaissance

The group invests in reconnaissance before contact (T1590) and relies on three entry routes.

  • The first is spear-phishing. It uses malicious macro-enabled Office attachments such as Clayslide (T1566.001) and deceptive links (T1566.002).
  • The second is social engineering. This includes fabricated personas, recruiters and academics on LinkedIn, and spoofed portals such as fake University of Oxford job sites or counterfeit Juniper VPN logins, frequently delivered via legitimate services (T1566.003).
  • The third, and increasingly the preferred one, is the exploitation of public-facing applications (T1190). This includes unpatched VPNs (Pulse Secure and Fortinet) and Microsoft Exchange servers.

Where direct access is hard, APT34 reaches its target through supply-chain compromise (T1195), abusing the trusted access of IT service and telecommunications providers to pivot into downstream enterprises. The group also maintains entry through external remote services (T1133).

» Learn how to prevent phishing attacks before they catch you

2. Execution and Privilege Escalation

Once inside, APT34 leans heavily on native scripting to stay fileless: PowerShell (T1059.001), VBScript (T1059.005), and the Windows command shell (T1059.003) drive in-memory payloads that leave little on disk, typically after a user is induced to open a weaponized file (T1204.002).

For privilege escalation it is willing to burn exploits when the prize justifies it; the Earth Simnavaz campaign used CVE-2024-30088 to reach SYSTEM (T1068).

3. Persistence and Defense Evasion

This is where OilRig's identity-centric doctrine becomes most visible. After initial compromise it plants custom IIS web shells  TwoFace, RGDoor, and HighShell for lightweight, persistent access (T1505.003). On domain controllers it registers a malicious password-filter DLL such as psgfilter.dll (T1556.002), which captures every user password in plaintext at the moment it is changed a persistence and credential-harvesting mechanism in one.

The group schedules tasks to re-run its backdoors (T1053.005), abuses the Outlook Home Page feature for Exchange-resident persistence (T1137.004), and, above all, operates as valid users with stolen domain credentials (T1078.002), which is what makes it so difficult to separate from legitimate activity. Evasion is correspondingly low-noise: masquerading binaries to match legitimate names and locations (T1036.005), modifying or disabling host firewalls to clear tunnel paths (T1562.004), and deleting indicators on disk (T1070.004).

4. Credential Access

Credential theft is the engine of lateral movement. APT34 dumps OS credentials with tooling such as Mimikatz (T1003), runs custom browser stealers CDumper, EDumper, PICKPOCKET, and ValueVault against saved passwords and session cookies in Chrome and Edge (T1555.003) and against the Windows Credential Manager (T1555.004), captures keystrokes where needed (T1056.001), and will fall back to password spraying when it lacks a foothold (T1110.003). Combined with the password-filter DLL, the result is an actor that rarely needs to break in twice.

5. Command and Control and Exfiltration

APT34's C2 is engineered to look like ordinary traffic. The group is a long-standing practitioner of DNS tunneling ISMAgent, Saitama, and DNSpionage hide instructions inside benign-looking DNS queries and TXT records (T1071). More distinctively, its advanced backdoors (PowerExchange, Veaty, STEALHOOK) sit directly on Microsoft Exchange and use the Exchange Web Services API to receive commands and exfiltrate stolen data as email attachments, blending into normal corporate mail flow.

To move tooling in and out it relies on ingress tool transfer (T1105) and, to bypass firewalls, on legitimate remote-administration utilities notably ngrok and PuTTY Link (Plink) to stand up quiet tunnels back to its infrastructure. Bulk theft is staged over web services (T1567) or alternative protocols (T1048.002).

Sectors and Victimology

APT34's geographic core remains the Middle East, with heavy targeting of Saudi Arabia, Israel, the UAE, Jordan, Iraq, and Bahrain.

The trajectory, however, is outward. The group has expanded into Europe, the United States, and Asia, and the 2020 Westat and Fox Kitten activity confirms U.S. enterprises are inside the target set, not adjacent to it.

By sector, APT34 concentrates on targets tied to national security and economic stability, including:

  • Government agencies
  • Critical infrastructure
  • Energy and chemical (oil and gas)
  • Financial institutions
  • Telecommunications
  • Aviation
  • IT service providers

Two of those categories deserve specific attention from U.S. security leaders.

  • Energy and chemical operators are direct strategic targets, as the Earth Simnavaz campaign shows.
  • IT service and telecommunications providers are something more dangerous—they are the group's preferred lever for supply-chain access, valued less for their own data than for the trusted paths they hold into government and enterprise customers downstream.

A U.S. enterprise with no obvious Iran nexus can still be reached through a managed service provider that does.



Three Takeaways for the U.S. Enterprise

1. Treat Identity as the Actual Perimeter

APT34's current doctrine is built to defeat malware-centric defense. Stolen credentials, valid accounts, a password-filter DLL on a domain controller, and native tooling generate little of what an EDR is tuned to catch.

The countermeasures are identity first:

  • Phishing-resistant MFA
  • Tight privileged-access management
  • Monitoring for anomalous use of valid accounts
  • Alerting on new or modified password-filter DLLs (T1556.002)
  • Monitoring for unexpected scheduled tasks (T1053.005) on domain controllers and Exchange hosts

Detection content for these behaviors is maintained in the [CIC repo].

2. Instrument Your Email and Exchange Plane as a Control Surface, Not Just a Mailbox

OilRig's most distinctive capability is turning your own Exchange server into a C2 and exfiltration channel via the EWS API, while using DNS tunneling (T1071) as a covert backchannel.

Defenders should:

  • Baseline and monitor EWS usage
  • Alert on Outlook Home Page persistence (T1137.004)
  • Alert on Exchange-resident scripts
  • Add DNS-tunneling analytics—including anomalous TXT-record volume and high-entropy subdomains—to the hunting program

Starter hunt queries are linked in the [CIC repo].

3. Map and Monitor Your IT and Telecommunications Supply Chain

Because APT34 reaches enterprises through trusted providers (T1195), perimeter hardening alone is insufficient.

Organizations should:

  • Inventory which vendors hold privileged or persistent access into the environment
  • Require those vendors to attest to identity controls
  • Segment vendor access
  • Monitor vendor-originated authentication for the same valid-account anomalies you would hunt internally

Assume that a provider compromise is a viable path to you, and design detections accordingly.

Discover & Defend Against Sophisticated Adversaries

Discover how KELA helps organizations uncover, prioritize, and mitigate advanced threats with actionable cyber threat intelligence

Contact Us

The Iranian APT vs. U.S. Blog Series

This is the final post of a series of five on Iran's APTs and the US Enterprise in 2026. To read other threat actor based content, please visit our blog page that is constantly updated here