← Back to all threat actors

OilRig

Also known as COBALT GYPSY, IRN2, APT34, Helix Kitten, Evasive Serpens, Hazel Sandstorm, EUROPIUM, ITG13, Earth Simnavaz, Crambus, TA452
Tracked as G0049

OilRig is a suspected Iranian threat group that has targeted Middle Eastern and international victims since at least 2014. The group has targeted a variety of sectors, including financial, government, energy, chemical, and telecommunications. It appears the group carries out supply chain attacks, leveraging the trust relationship between organizations to attack their primary targets. The group works on behalf of the Iranian government based on infrastructure details that contain references to Iran, use of Iranian infrastructure, and targeting that aligns with nation-state interests.

How we source and review actor profiles
Motivation
nation-state
Attributed nexus
IR
Sectors
energy, government, financial-services, telecom
Status
Active

Activity timeline

A dated ledger of actor-claimed victims, campaigns, indicators, identity mappings, relationships, and CVE links. Each date states what it measures. For extensive leak-site histories, victim entries are limited to the 100 most recent distinct listings.

Cataloged
IdentityAlias: COBALT GYPSY

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: IRN2

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: APT34

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Helix Kitten

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Evasive Serpens

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Hazel Sandstorm

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: EUROPIUM

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: ITG13

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Earth Simnavaz

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Crambus

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: TA452

Reviewed identity mapping approved on this date.

Cataloged
IdentityTracking identifier: G0049

Reviewed identity mapping approved on this date.

Last observed
CampaignJuicy Mix

Juicy Mix was a campaign conducted by OilRig throughout 2022 that targeted Israeli organizations with the Mango backdoor.(Citation: ESET OilRig Campaig…

Last observed
CampaignOuter Space

Outer Space was a campaign conducted by OilRig throughout 2021 that used the SampleCheck5000 downloader and [Solar](https://attack.mitre.org/software/S…

Identity and attribution

Exact names and tracking identifiers resolve to this canonical profile. Rebrands, affiliations, and overlapping clusters remain separate confidence-rated relationships.

Name map

OilRigCanonical Name
APT34Alias
COBALT GYPSYAlias
CrambusAlias
EUROPIUMAlias
Earth SimnavazAlias
Evasive SerpensAlias
Hazel SandstormAlias
Helix KittenAlias
IRN2Alias
ITG13Alias
TA452Alias
G0049Tracking Id

Loading CVEs, techniques, indicators, malware, victims, and activity...