Clankerusecase
Threat-actor profile
← Back to main site
Home/ Threat Actors/ APT34

🇮🇷APT34

🇮🇷 APT34 is a tracked threat actor in the Clankerusecase corpus. Attributed to IR. Primary motivation: State. We map 26 detection use cases to this actor across 96 MITRE ATT&CK techniques, with 2 threat-intel articles citing them. Active in our corpus from 2026-02-26 to 2026-03-12.

crit 2
View full actor card → All threat actors MITRE ATT&CK group spec (G0049) ↗
26Use cases
2Articles
96Techniques
5IOCs

Known aliases

APT34OilRigHelix KittenCobalt GypsyHazel SandstormCOBALT GYPSYIRN2Evasive SerpensEUROPIUMITG13Earth SimnavazCrambusTA452

Top techniques

All other tracked techniques

T1003 · OS Credential DumpingT1003.001 · LSASS MemoryT1003.004 · LSA SecretsT1003.005 · Cached Domain CredentialsT1005 · Data from Local SystemT1007 · System Service DiscoveryT1008 · Fallback ChannelsT1012 · Query RegistryT1016 · System Network Configuration DiscoveryT1021.001 · Remote Desktop ProtocolT1021.002 · SMB/Windows Admin SharesT1021.004 · SSHT1025 · Data from Removable MediaT1027 · Obfuscated Files or InformationT1027.005 · Indicator Removal from ToolsT1027.013 · Encrypted/Encoded FileT1033 · System Owner/User DiscoveryT1036 · MasqueradingT1036.005 · Match Legitimate Resource Name or LocationT1046 · Network Service DiscoveryT1047 · Windows Management InstrumentationT1048.003 · Exfiltration Over Unencrypted Non-C2 ProtocolT1049 · System Network Connections DiscoveryT1053.005 · Scheduled TaskT1056.001 · KeyloggingT1057 · Process DiscoveryT1059 · Command and Scripting InterpreterT1059.001 · PowerShellT1059.003 · Windows Command ShellT1059.005 · Visual BasicT1068 · Exploitation for Privilege EscalationT1069.001 · Local GroupsT1069.002 · Domain GroupsT1070.004 · File DeletionT1071 · Application Layer ProtocolT1071.001 · Web ProtocolsT1071.004 · DNST1078 · Valid AccountsT1078.002 · Domain AccountsT1082 · System Information DiscoveryT1087 · Account DiscoveryT1087.001 · Local AccountT1087.002 · Domain AccountT1098.005 · Device RegistrationT1105 · Ingress Tool TransferT1110 · Brute ForceT1110.003 · Password SprayingT1112 · Modify RegistryT1113 · Screen CaptureT1115 · Clipboard DataT1119 · Automated CollectionT1120 · Peripheral Device DiscoveryT1127.001 · MSBuildT1133 · External Remote ServicesT1137.004 · Outlook Home PageT1140 · Deobfuscate/Decode Files or InformationT1195 · Supply Chain CompromiseT1199 · Trusted RelationshipT1201 · Password Policy DiscoveryT1203 · Exploitation for Client ExecutionT1204.001 · Malicious LinkT1204.002 · Malicious FileT1204.004 · Malicious Copy and PasteT1218 · System Binary Proxy ExecutionT1218.001 · Compiled HTML FileT1219 · Remote Access ToolsT1486 · Data Encrypted for ImpactT1497.001 · System ChecksT1505.003 · Web ShellT1543.003 · Windows ServiceT1547.001 · Registry Run Keys / Startup FolderT1552.001 · Credentials In FilesT1553.002 · Code SigningT1555 · Credentials from Password StoresT1555.003 · Credentials from Web BrowsersT1555.004 · Windows Credential ManagerT1556.002 · Password Filter DLLT1556.006 · Multi-Factor AuthenticationT1566.001 · Spearphishing AttachmentT1566.002 · Spearphishing LinkT1566.003 · Spearphishing via ServiceT1569.002 · Service ExecutionT1572 · Protocol TunnelingT1573.002 · Asymmetric CryptographyT1574.002 · T1574.002T1583.001 · DomainsT1586.002 · Email AccountsT1587.001 · MalwareT1588.002 · ToolT1588.003 · Code Signing CertificatesT1608.001 · Upload MalwareT1621 · Multi-Factor Authentication Request GenerationT1686.003 · Windows Host Firewall

Detection use cases (26)

APT34 (OilRig) DNS-tunnel C2 — high-entropy long subdomain beaconing under a single parent domain AI · profile SDD APT34 (OilRig / Helix Kitten) Outlook Home Page WebView persistence (Ruler-style) AI · profile SΣDD MuddyWater SimpleHelp RMM client spawning shell or recon LOLBin Bespoke Iran-aligned MFA push-bombing followed by new auth method registered (AA24-290A) Bespoke Phishing-link click correlated to endpoint execution Internal Email attachment opened from external sender Internal Office app spawning script/LOLBin child process Internal Fake CAPTCHA / clipboard-injected PowerShell (ClickFix / FakeCaptcha) Internal Ransomware-style mass file rename / extension change Internal LSASS process access / dump (credential theft) Internal Remote service execution — PsExec / SMB lateral movement Internal RMM tool installed by non-IT user — remote-access utility for hands-on-keyboard Internal Trusted vendor binary / installer launching unusual children Internal PlugX phishing lure — 'Meeting Invitation' email linking to gesecole.net ZIP Bespoke 1Password failed sign-in burst MITRE match 1Password impossible-travel sign-in MITRE match 1Password item exfiltration attempt MITRE match 1Password vault export attempted MITRE match Auth-Bypass on Public-Facing Service → Post-Exploit Action on Same Host (≤10 min) MITRE match Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes MITRE match Cross-category credential-store enumeration with rapid egress to anonymizing tunnel/CDN MITRE match Cross-Platform ClickFix Paste-to-Pipe Loader (UI-Parent Shell with Decode-and-Execute Payload) MITRE match Developer package install spawning script-host with non-registry C2 within 5 minutes MITRE match Developer/Data-tooling Daemon Spawns Shell Child Seconds After POST to Runner/Exec Endpoint MITRE match Edge-service post-exploitation chain: internet-facing daemon → child shell or token redemption within 10 min of external request MITRE match Internet-Facing Service Process Spawning Unix Shell or Ingress-Tool LOLBin (Edge Zero-Day Post-Exploit) MITRE match

Threat-intel articles (2)

Tracked indicators

Domains (5)

decoorat.net decoraat.net gesecole.net onedow.gesecole.net onedown.gesecole.net