OilRig Group Steps Up Attacks with New Delivery Documents and New Injector TrojanPalo Alto Unit 42·Dec 17, 08:59 UTC · Dec 17, 2018MalwareCVE-2017-019947
OilRig targets Israel organizations with new lightweight downloadersHelp Net Security·Dec 15, 00:00 UTC · Dec 15, 2023Malware42
Iran-linked OilRig hacked group use a new Trojan in Middle East AttacksSecurity Affairs·Oct 10, 13:38 UTC · Oct 10, 2017Malware42
Analyzing OilRig’s malware that uses DNS TunnelingSecurity Affairs·Apr 18, 20:48 UTC · Apr 18, 2019Malware42
Experts analyzed how OilRIG hackers tested their weaponized docsSecurity Affairs·Nov 20, 09:31 UTC · Nov 20, 2018Malware42
OilRig Performs Tests on the TwoFace WebshellPalo Alto Unit 42·Nov 1, 10:59 UTC · Nov 1, 2018Malware30
New OilRig APT campaign leverages a new variant of the OopsIE TrojanSecurity Affairs·Sep 6, 17:13 UTC · Sep 6, 2018Malware42
Iran-linked group OilRig used a new Trojan called OopsIE in recent attacksSecurity Affairs·Feb 24, 09:18 UTC · Feb 24, 2018Malware42
Iranian Group OilRig is back and delivers digitally signed malwareSecurity Affairs·Oct 10, 12:20 UTC · Oct 10, 2017Malware42
OilRig Uses ISMDoor Variant; Possibly Linked to Greenbug Threat GroupPalo Alto Unit 42·Jan 10, 16:52 UTC · Jan 10, 2020Malware30
Iranian State-Sponsored OilRig Group Deploys 3 New Malware DownloadersThe Hacker News·Dec 15, 00:00 UTC · Dec 15, 2023Malware142
OilRig targets a Middle Eastern Government and Adds Evasion Techniques to OopsIEPalo Alto Unit 42·Nov 2, 11:28 UTC · Nov 2, 2018Malware55
The OilRig Campaign: Attacks on Saudi Arabian Organizations Deliver Helminth BackdoorPalo Alto Unit 42·Nov 1, 10:15 UTC · Nov 1, 2018Malware42
Iran-linked APT OilRig target IIS Web Servers with new RGDoor BackdoorSecurity Affairs·Feb 4, 17:23 UTC · Feb 4, 2018Malware42
Striking Oil: A Closer Look at Adversary InfrastructurePalo Alto Unit 42·Oct 15, 11:29 UTC · Oct 15, 2018Malware42
OilRig Malware Campaign Updates Toolset and Expands TargetsPalo Alto Unit 42·Nov 1, 10:23 UTC · Nov 1, 2018Malware42
Iranian Cyber Group OilRig Targets Iraqi Government in Sophisticated Malware AttackThe Hacker News·Sep 12, 10:49 UTC · Sep 12, 2024Malware42
Iranian APT Group OilRig Using New Menorah Malware for Covert OperationsThe Hacker News·Sep 30, 09:21 UTC · Sep 30, 2023Malware42
Iranian OilRig Hackers Using New Backdoor to Exfiltrate Data from Govt. OrganizationsThe Hacker News·Feb 3, 12:23 UTC · Feb 3, 2023Malware42
OilRig APT uses Karkoff malware along with DNSpionage in recent attacksSecurity Affairs·Apr 24, 10:41 UTC · Apr 24, 2019Malware42
Iran-linked hackers develop new malware downloaders to infect victims in IsraelThe Record·Dec 14, 16:44 UTC · Dec 14, 2023Malware30
Iran-Linked OilRig Targets Middle East Governments in 8The Hacker News·Oct 19, 10:15 UTC · Oct 19, 2023Malware42
Iran-Linked BladedFeline Hits Iraqi and Kurdish Targets with Whisper and Spearal MalwareThe Hacker News·Jun 5, 14:50 UTC · Jun 5, 2025Malware42
OilRig uses RGDoor IIS Backdoor on Targets in the Middle EastPalo Alto Unit 42·Nov 1, 11:00 UTC · Nov 1, 2018Malware42
Scarred Manticore Targets Middle East With Advanced MalwareInfosecurity Magazine·Oct 31, 16:30 UTC · Oct 31, 2023Malware42
Iran-Aligned Hacking Group Targets Middle Eastern GovernmentsInfosecurity Magazine·Jul 7, 16:00 UTC · Jul 7, 2025Malware55
Iranian Hackers Using New Marlin Backdoor in 'Out to Sea' Espionage CampaignThe Hacker News·Feb 9, 12:51 UTC · Feb 9, 2022Malware42
Triton malware was developed by Iran and used to target Saudi ArabiaSecurity Affairs·Dec 19, 20:11 UTC · Dec 19, 2017Malware55
Iranian hackers caught spying on governments and military in Middle EastThe Record·Oct 31, 19:35 UTC · Oct 31, 2023Malware42
New PowerExchange Backdoor Used in Iranian Cyber Attack on UAE GovernmentThe Hacker News·May 25, 13:39 UTC · May 25, 2023Malware42
TortoiseShell Group targets IT Providers in supply chain attacksSecurity Affairs·Sep 23, 05:54 UTC · Sep 23, 2019Malware42
The Hottest Malware Hits of the SummerThe Hacker News·Sep 11, 17:03 UTC · Sep 11, 2019MalwareCVE-2018-845360
Iranian hackers compromised the UK leader Theresa May’s email account along with other 9,000 emailsSecurity Affairs·Oct 16, 06:26 UTC · Oct 16, 2017Malware42
⚡ Weekly Recap: Chrome 0-Day, Data Wipers, Misused Tools and ZeroThe Hacker News·Jul 25, 08:27 UTC · Jul 25, 2026Malware in the wildCVE-2025-20286CVE-2025-49113CVE-2025-5419+8 CVEs60
HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050The Hacker News·Jul 20, 14:33 UTC · Jul 20, 2026Malware42
AI Has Enhanced Iran’s Asymmetric Playbook During the 2026 ConflictRecorded Future·Jul 16, 00:00 UTC · Jul 16, 2026Malware55
New Iran-Nexus Hacking Group Targets Israel Government and IT SectorsInfosecurity Magazine·Jul 6, 16:00 UTC · Jul 6, 2026Malware42