APT Intelligence Directory
Institute for Critical Infrastructure Cybersecurity
IR

OilRig

High ConfidenceHigh Threat

APT34 • Helix Kitten • COBALT GYPSY • Hazel Sandstorm • Crambus • ITG13

OilRig, also known as APT34 or Helix Kitten, is an Iranian cyber espionage group linked to the Ministry of Intelligence and Security (MOIS). Active since at least 2014, the group targets organizations in the Middle East, particularly in the financial, government, energy, telecommunications, and chemical sectors. OilRig is known for developing custom tools including POWRUNER, BONDUPDATER, and various DNS tunneling utilities. In 2019, their tools and victim data were leaked by a mysterious entity called 'Lab Dookhtegan,' exposing their operations. Despite this exposure, the group continues to operate with evolved tradecraft.

Origin: Iran
Sponsor: MOIS (Ministry of Intelligence and Security)
Active: 2014 - Present
Victims: 250+ organizations
Advanced
Active
EspionageIntelligence Collection
Risk Assessment
75
Composite Risk Score
High Risk
ARCS Compliance76
Escalation Risk74
Grievance Index78
Infrastructure Impact72
History & Evolution

OilRig, also known as APT34 or Helix Kitten, is an Iranian cyber espionage group linked to the Ministry of Intelligence and Security (MOIS). Active since at least 2014, the group targets organizations in the Middle East, particularly in the financial, government, energy, telecommunications, and chemical sectors. OilRig is known for developing custom tools including POWRUNER, BONDUPDATER, and various DNS tunneling utilities. In 2019, their tools and victim data were leaked by a mysterious entity called 'Lab Dookhtegan,' exposing their operations. Despite this exposure, the group continues to operate with evolved tradecraft.

Targeting

Target Sectors

GovernmentFinancialEnergyTelecommunicationsChemical

Target Regions

Middle EastUnited StatesEurope
Attribution & Affiliations

Attributed to MOIS (Ministry of Intelligence and Security) (Iran). Attribution confidence: High.

Intelligence Assessment
High
Threat Level
Moderately
Targeting
Moderately
Adaptability
High
Persistence
Continuous
Op Tempo
Active
Status

Future Outlook

OilRig is expected to continue operations targeting Government sectors.

Timeline of Key Events
2014
Major

First observed activity of OilRig

2024
Moderate

Continued active operations