« Todas las amenazas

Grupo APTMITRE G0049

OilRig

También conocido como: apt 34, apt34, atk40, cobalt gypsy, crambus, earth simnavaz, europium, evasive serpens, g0049, hazel sandstorm, helix kitten, irn2

[OilRig](https://attack.mitre.org/groups/G0049) is a suspected Iranian threat group that has targeted Middle Eastern and international victims since at least 2014. The group has targeted a variety of sectors, including financial, government, energy, chemical, and telecommunications. It appears the group carries out supply chain attacks, leveraging the trust relationship between organizations to attack their primary targets. The group works on behalf of the Iranian government based on infrastructure details that contain references to Iran, use of Iranian infrastructure, and targeting that aligns with nation-state interests.(Citation: FireEye APT34 Dec 2017)(Citation: Palo Alto OilRig April 2017)(Citation: ClearSky OilRig Jan 2017)(Citation: Palo Alto OilRig May 2016)(Citation: Palo Alto OilRig Oct 2016)(Citation: Unit42 OilRig Playbook 2023)(Citation: Unit 42 QUADAGENT July 2018)

Víctimas en los últimos 90 días0

Países más afectados

Sin datos todavía.

Sectores más afectados

Sin datos todavía.

Mitigaciones prioritarias

Mitigaciones de MITRE ATT&CK que cubren más técnicas de las que usa este grupo.

  1. Gestión de cuentas de usuario (16 técnicas cubiertas)
  2. Formación de usuarios (13 técnicas cubiertas)
  3. Gestión de cuentas privilegiadas (11 técnicas cubiertas)
  4. Prevención de intrusiones en red (11 técnicas cubiertas)
  5. Prevención de ejecución (11 técnicas cubiertas)
  6. Políticas de contraseñas (10 técnicas cubiertas)
  7. Desactivar o eliminar funciones o programas (10 técnicas cubiertas)
  8. Auditoría (10 técnicas cubiertas)

Técnicas MITRE ATT&CK

T1588.003 · Code Signing CertificatesT1555.004 · Windows Credential ManagerT1082 · System Information DiscoveryT1003.001 · LSASS MemoryT1008 · Fallback ChannelsT1071.001 · Web ProtocolsT1005 · Data from Local SystemT1686.003 · Windows Host FirewallT1059.003 · Windows Command ShellT1021.001 · Remote Desktop ProtocolT1505.003 · Web ShellT1587.001 · MalwareT1608.001 · Upload MalwareT1036 · MasqueradingT1219 · Remote Access ToolsT1218.001 · Compiled HTML FileT1046 · Network Service DiscoveryT1087.001 · Local AccountT1137.004 · Outlook Home PageT1069.002 · Domain GroupsT1113 · Screen CaptureT1025 · Data from Removable MediaT1007 · System Service DiscoveryT1556.002 · Password Filter DLLT1059.001 · PowerShellT1070.004 · File DeletionT1588.002 · ToolT1204.002 · Malicious FileT1133 · External Remote ServicesT1078.002 · Domain AccountsT1201 · Password Policy DiscoveryT1586.002 · Email AccountsT1087.002 · Domain AccountT1003.004 · LSA SecretsT1140 · Deobfuscate/Decode Files or InformationT1553.002 · Code SigningT1048.003 · Exfiltration Over Unencrypted Non-C2 ProtocolT1110 · Brute ForceT1059.005 · Visual BasicT1566.002 · Spearphishing LinkT1112 · Modify RegistryT1120 · Peripheral Device DiscoveryT1071.004 · DNST1105 · Ingress Tool TransferT1049 · System Network Connections DiscoveryT1543.003 · Windows ServiceT1195 · Supply Chain CompromiseT1204.001 · Malicious LinkT1078 · Valid AccountsT1573.002 · Asymmetric CryptographyT1566.001 · Spearphishing AttachmentT1053.005 · Scheduled TaskT1119 · Automated CollectionT1583.001 · DomainsT1056.001 · KeyloggingT1036.005 · Match Legitimate Resource Name or LocationT1033 · System Owner/User DiscoveryT1566.003 · Spearphishing via ServiceT1572 · Protocol TunnelingT1047 · Windows Management Instrumentation

Víctimas recientes

Sin datos todavía.

Las reivindicaciones las publican los propios grupos criminales y no están verificadas hasta que la organización o la prensa las confirman. Los nombres de personas físicas (autónomos, profesionales individuales) se anonimizan conforme al RGPD. Nunca enlazamos a sitios de filtración ni a datos robados. Para solicitar la retirada o anonimización de una entrada, contacte con el administrador del sitio.

Fuentes: RansomLook (CC BY 4.0), MITRE ATT&CK®, MISP Galaxy, Google News.