Introducing the Adversary Playbook: First up, OilRigPalo Alto Unit 42·Jan 10, 23:11 UTC · Jan 10, 2019Vulnerability42
OilRig Group Steps Up Attacks with New Delivery Documents and New Injector TrojanPalo Alto Unit 42·Dec 17, 08:59 UTC · Dec 17, 2018MalwareCVE-2017-019947
OilRig Targets Technology Service Provider and Government Agency with QUADAGENTPalo Alto Unit 42·Sep 5, 07:07 UTC · Sep 5, 2018Data breach57
OilRig targets Israel organizations with new lightweight downloadersHelp Net Security·Dec 15, 00:00 UTC · Dec 15, 2023Malware42
OilRig APT group: the evolution of attack techniques over timeSecurity Affairs·Aug 7, 13:47 UTC · Aug 7, 2019Threat actor57
Iran-linked OilRig hacked group use a new Trojan in Middle East AttacksSecurity Affairs·Oct 10, 13:38 UTC · Oct 10, 2017Malware42
Analyzing OilRig’s malware that uses DNS TunnelingSecurity Affairs·Apr 18, 20:48 UTC · Apr 18, 2019Malware42
Experts analyzed how OilRIG hackers tested their weaponized docsSecurity Affairs·Nov 20, 09:31 UTC · Nov 20, 2018Malware42
OilRig APT group targets high-ranking office in a Middle Eastern nationSecurity Affairs·Sep 14, 13:15 UTC · Sep 14, 2018Threat actor57
New OilRig APT campaign leverages a new variant of the OopsIE TrojanSecurity Affairs·Sep 6, 17:13 UTC · Sep 6, 2018Malware42
Iran-linked group OilRig used a new Trojan called OopsIE in recent attacksSecurity Affairs·Feb 24, 09:18 UTC · Feb 24, 2018Malware42
Iranian Group OilRig is back and delivers digitally signed malwareSecurity Affairs·Oct 10, 12:20 UTC · Oct 10, 2017Malware42
OilRig's Jason email hacking tool leaked online via TelegramSecurity Affairs·Jun 4, 13:56 UTC · Jun 4, 2019Threat actor57
Source code of tools used by OilRig APT leaked on TelegramSecurity Affairs·Apr 19, 12:07 UTC · Apr 19, 2019Data breach57
Iranian State-Sponsored OilRig Group Deploys 3 New Malware DownloadersThe Hacker News·Dec 15, 00:00 UTC · Dec 15, 2023Malware142
Iranian Nation-State Actor OilRig Targets Israeli OrganizationsThe Hacker News·Dec 14, 12:07 UTC · Dec 14, 2023Threat actor57
The OilRig Campaign: Attacks on Saudi Arabian Organizations Deliver Helminth BackdoorPalo Alto Unit 42·Nov 1, 10:15 UTC · Nov 1, 2018Malware42
Iran-linked APT OilRig target IIS Web Servers with new RGDoor BackdoorSecurity Affairs·Feb 4, 17:23 UTC · Feb 4, 2018Malware42
Striking Oil: A Closer Look at Adversary InfrastructurePalo Alto Unit 42·Oct 15, 11:29 UTC · Oct 15, 2018Malware42
Russia-Linked Turla APT group Hijacked C2 of the Iranian OilRigSecurity Affairs·Jun 21, 13:01 UTC · Jun 21, 2019Threat actor57
OilRig Malware Campaign Updates Toolset and Expands TargetsPalo Alto Unit 42·Nov 1, 10:23 UTC · Nov 1, 2018Malware42
OilRig Exploits Windows Kernel Flaw in Espionage Campaign Targeting UAE and GulfThe Hacker News·Oct 17, 08:42 UTC · Oct 17, 2024Threat actorCVE-2024-30088160
Iranian Cyber Group OilRig Targets Iraqi Government in Sophisticated Malware AttackThe Hacker News·Sep 12, 10:49 UTC · Sep 12, 2024Malware42
Iranian APT Group OilRig Using New Menorah Malware for Covert OperationsThe Hacker News·Sep 30, 09:21 UTC · Sep 30, 2023Malware42
Iranian OilRig Hackers Using New Backdoor to Exfiltrate Data from Govt. OrganizationsThe Hacker News·Feb 3, 12:23 UTC · Feb 3, 2023Malware42
OilRig APT uses Karkoff malware along with DNSpionage in recent attacksSecurity Affairs·Apr 24, 10:41 UTC · Apr 24, 2019Malware42
Iran-Linked OilRig Targets Middle East Governments in 8The Hacker News·Oct 19, 10:15 UTC · Oct 19, 2023Malware42
Iran-Linked BladedFeline Hits Iraqi and Kurdish Targets with Whisper and Spearal MalwareThe Hacker News·Jun 5, 14:50 UTC · Jun 5, 2025Malware42
Russian Turla APT masqueraded as Iranian hackersSecurity Affairs·Oct 21, 09:43 UTC · Oct 21, 2019Threat actor57
OilRig uses RGDoor IIS Backdoor on Targets in the Middle EastPalo Alto Unit 42·Nov 1, 11:00 UTC · Nov 1, 2018Malware42
Scarred Manticore Targets Middle East With Advanced MalwareInfosecurity Magazine·Oct 31, 16:30 UTC · Oct 31, 2023Malware42
Iranian Hackers Using New Marlin Backdoor in 'Out to Sea' Espionage CampaignThe Hacker News·Feb 9, 12:51 UTC · Feb 9, 2022Malware42
APT trends report Q2 2020Kaspersky Securelist·Jul 29, 10:00 UTC · Jul 29, 2020VulnerabilityCVE-2019-1014947
Iranian hackers caught spying on governments and military in Middle EastThe Record·Oct 31, 19:35 UTC · Oct 31, 2023Malware42
New PowerExchange Backdoor Used in Iranian Cyber Attack on UAE GovernmentThe Hacker News·May 25, 13:39 UTC · May 25, 2023Malware42
TortoiseShell Group targets IT Providers in supply chain attacksSecurity Affairs·Sep 23, 05:54 UTC · Sep 23, 2019Malware42