Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Groups/G0049
MITRE ATT&CK Group

OilRig (G0049)

COBALT GYPSYIRN2APT34Helix KittenEvasive SerpensHazel SandstormEUROPIUMITG13Earth SimnavazCrambusTA452
ShareXLinkedInRedditHN

[OilRig](https://attack.mitre.org/groups/G0049) is a suspected Iranian threat group that has targeted Middle Eastern and international victims since at least 2014. The group has targeted a variety of sectors, including financial, government, energy, chemical, and telecommunications. It appears the group carries out supply chain attacks, leveraging the trust relationship between organizations to attack their primary targets. The group works on behalf of the Iranian government based on infrastructure details that contain references to Iran, use of Iranian infrastructure, and targeting that aligns with nation-state interests.(Citation: FireEye APT34 Dec 2017)(Citation: Palo Alto OilRig April 2017)(Citation: ClearSky OilRig Jan 2017)(Citation: Palo Alto OilRig May 2016)(Citation: Palo Alto OilRig Oct 2016)(Citation: Unit42 OilRig Playbook 2023)(Citation: Unit 42 QUADAGENT July 2018)

▪Techniques used (81)

T1588.003Code Signing CertificatesT1555.004Windows Credential ManagerT1082System Information DiscoveryT1003.001LSASS MemoryT1008Fallback ChannelsT1071.001Web ProtocolsT1005Data from Local SystemT1686.003Windows Host FirewallT1059.003Windows Command ShellT1021.001Remote Desktop ProtocolT1505.003Web ShellT1587.001MalwareT1608.001Upload MalwareT1036MasqueradingT1219Remote Access ToolsT1218.001Compiled HTML FileT1046Network Service DiscoveryT1087.001Local AccountT1137.004Outlook Home PageT1069.002Domain GroupsT1113Screen CaptureT1025Data from Removable MediaT1007System Service DiscoveryT1556.002Password Filter DLLT1059.001PowerShellT1070.004File DeletionT1588.002ToolT1204.002Malicious FileT1133External Remote ServicesT1078.002Domain AccountsT1201Password Policy DiscoveryT1586.002Email AccountsT1087.002Domain AccountT1003.004LSA SecretsT1140Deobfuscate/Decode Files or InformationT1553.002Code SigningT1048.003Exfiltration Over Unencrypted Non-C2 ProtocolT1110Brute ForceT1059.005Visual BasicT1566.002Spearphishing LinkT1112Modify RegistryT1120Peripheral Device DiscoveryT1071.004DNST1105Ingress Tool TransferT1049System Network Connections DiscoveryT1543.003Windows ServiceT1195Supply Chain CompromiseT1204.001Malicious LinkT1078Valid AccountsT1573.002Asymmetric CryptographyT1566.001Spearphishing AttachmentT1053.005Scheduled TaskT1119Automated CollectionT1583.001DomainsT1056.001KeyloggingT1036.005Match Legitimate Resource Name or LocationT1033System Owner/User DiscoveryT1566.003Spearphishing via ServiceT1572Protocol TunnelingT1047Windows Management InstrumentationT1021.004SSHT1555Credentials from Password StoresT1115Clipboard DataT1003.005Cached Domain CredentialsT1027.013Encrypted/Encoded FileT1069.001Local GroupsT1552.001Credentials In FilesT1057Process DiscoveryT1555.003Credentials from Web BrowsersT1016System Network Configuration DiscoveryT1203Exploitation for Client ExecutionT1012Query RegistryT1059Command and Scripting InterpreterT1497.001System ChecksT1068Exploitation for Privilege EscalationT1027.005Indicator Removal from ToolsT0865Spearphishing AttachmentT0853ScriptingT0869Standard Application Layer ProtocolT0859Valid AccountsT0817Drive-by Compromise

▪Software used (30)

S0189ISMInjectormalwareS1170ODAgentmalwareS0495RDATmalwareS0096SysteminfotoolS0269QUADAGENTmalwareS0264OopsIEmalwareS0508ngroktoolS0057TasklisttoolS0039NettoolS0160certutiltoolS1151ZeroClearemalwareS0075RegtoolS0184POWRUNERmalwareS0104netstattoolS1166SolarmalwareS0100ipconfigtoolS0349LaZagnetoolS0360BONDUPDATERmalwareS0610SideTwistmalwareS0170HelminthmalwareS1169MangomalwareS1172OilBoostermalwareS1168SampleCheck5000malwareS0029PsExectoolS0185SEASHARPEEmalwareS0002MimikatztoolS1173PowerExchangemalwareS1171OilCheckmalwareS0258RGDoormalwareS0095ftptool
G0049on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.