Clankerusecase
Threat-actor profile
← Back to main site
Home/ Threat Actors/ APT34

🇮🇷APT34

🇮🇷 APT34 is a tracked threat actor in the Clankerusecase corpus. Attributed to IR. Primary motivation: State. We map 24 detection use cases to this actor across 101 MITRE ATT&CK techniques, with 4 threat-intel articles citing them. Active in our corpus from 2026-02-26 to 2026-08-17.

crit 3high 1
View full actor card → All threat actors MITRE ATT&CK group spec (G0049) ↗
24Use cases
4Articles
101Techniques
6IOCs

Known aliases

APT34OilRigHelix KittenCobalt GypsyHazel SandstormCOBALT GYPSYIRN2Evasive SerpensEUROPIUMITG13Earth SimnavazCrambusTA452

Top techniques

All other tracked techniques

T1003 · OS Credential DumpingT1003.001 · LSASS MemoryT1003.004 · LSA SecretsT1003.005 · Cached Domain CredentialsT1005 · Data from Local SystemT1007 · System Service DiscoveryT1008 · Fallback ChannelsT1012 · Query RegistryT1016 · System Network Configuration DiscoveryT1021.001 · Remote Desktop ProtocolT1021.002 · SMB/Windows Admin SharesT1021.004 · SSHT1025 · Data from Removable MediaT1027 · Obfuscated Files or InformationT1027.005 · Indicator Removal from ToolsT1027.013 · Encrypted/Encoded FileT1033 · System Owner/User DiscoveryT1036 · MasqueradingT1036.005 · Match Legitimate Resource Name or LocationT1046 · Network Service DiscoveryT1047 · Windows Management InstrumentationT1048.003 · Exfiltration Over Unencrypted Non-C2 ProtocolT1049 · System Network Connections DiscoveryT1053.005 · Scheduled TaskT1056.001 · KeyloggingT1057 · Process DiscoveryT1059 · Command and Scripting InterpreterT1059.001 · PowerShellT1059.003 · Windows Command ShellT1059.005 · Visual BasicT1068 · Exploitation for Privilege EscalationT1069.001 · Local GroupsT1069.002 · Domain GroupsT1070.004 · File DeletionT1071 · Application Layer ProtocolT1071.001 · Web ProtocolsT1071.004 · DNST1072 · Software Deployment ToolsT1078 · Valid AccountsT1078.002 · Domain AccountsT1082 · System Information DiscoveryT1087 · Account DiscoveryT1087.001 · Local AccountT1087.002 · Domain AccountT1098.001 · Additional Cloud CredentialsT1098.005 · Device RegistrationT1105 · Ingress Tool TransferT1110 · Brute ForceT1110.003 · Password SprayingT1112 · Modify RegistryT1113 · Screen CaptureT1115 · Clipboard DataT1119 · Automated CollectionT1120 · Peripheral Device DiscoveryT1127.001 · MSBuildT1133 · External Remote ServicesT1137.004 · Outlook Home PageT1140 · Deobfuscate/Decode Files or InformationT1195 · Supply Chain CompromiseT1195.002 · Compromise Software Supply ChainT1199 · Trusted RelationshipT1201 · Password Policy DiscoveryT1203 · Exploitation for Client ExecutionT1204.001 · Malicious LinkT1204.002 · Malicious FileT1204.004 · Malicious Copy and PasteT1218 · System Binary Proxy ExecutionT1218.001 · Compiled HTML FileT1219 · Remote Access ToolsT1486 · Data Encrypted for ImpactT1497.001 · System ChecksT1505.003 · Web ShellT1528 · Steal Application Access TokenT1539 · Steal Web Session CookieT1543.003 · Windows ServiceT1547.001 · Registry Run Keys / Startup FolderT1552.001 · Credentials In FilesT1553.002 · Code SigningT1555 · Credentials from Password StoresT1555.003 · Credentials from Web BrowsersT1555.004 · Windows Credential ManagerT1556.002 · Password Filter DLLT1556.006 · Multi-Factor AuthenticationT1566.001 · Spearphishing AttachmentT1566.003 · Spearphishing via ServiceT1569.002 · Service ExecutionT1572 · Protocol TunnelingT1573.002 · Asymmetric CryptographyT1574.002 · T1574.002T1574.014 · AppDomainManagerT1583.001 · DomainsT1586.002 · Email AccountsT1587.001 · MalwareT1588.002 · ToolT1588.003 · Code Signing CertificatesT1608.001 · Upload MalwareT1621 · Multi-Factor Authentication Request GenerationT1686.003 · Windows Host Firewall

Detection use cases (24)

Beaconing — periodic outbound to small set of destinations Internal Network connections to article IPs / domains Internal Infostealer — non-browser process accessing browser cookie/login DBs Internal DNS tunneling / TXT-heavy domain queries Internal Phishing-link click correlated to endpoint execution Internal Email attachment opened from external sender Internal Office app spawning script/LOLBin child process Internal OAuth consent / suspicious app grant Internal Fake CAPTCHA / clipboard-injected PowerShell (ClickFix / FakeCaptcha) Internal Article-specific behavioural hunt — Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic Internal Cavern Manticore WinDirStat DLL side-load of fake uxtheme.dll (Cavern backdoor) Bespoke Masqueraded uxtheme.dll dropped outside Windows dirs via SysAid/RMM deployment (Cavern Manticore) Bespoke 1Password failed sign-in burst MITRE match 1Password impossible-travel sign-in MITRE match 1Password item exfiltration attempt MITRE match 1Password vault export attempted MITRE match AI-Agent Server (PraisonAI/MCP) Spawns OS Shell or Recon LOLBin — Unauthenticated RCE Exploitation MITRE match AI/LLM Agent Framework Runtime Spawning Shell, Recon, or Egress Child Process MITRE match AI/LLM Framework Web Service Spawns Shell or Network Tool (Agent-Framework Unauthenticated RCE) MITRE match Auth-Bypass on Public-Facing Service → Post-Exploit Action on Same Host (≤10 min) MITRE match Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes MITRE match Cross-category credential-store enumeration with rapid egress to anonymizing tunnel/CDN MITRE match Cross-Platform ClickFix Paste-to-Pipe Loader (UI-Parent Shell with Decode-and-Execute Payload) MITRE match Developer package install spawning script-host with non-registry C2 within 5 minutes MITRE match

Threat-intel articles (4)

Tracked indicators

Domains (6)

decoorat.net decoraat.net gesecole.net onedow.gesecole.net onedown.gesecole.net studiotikva.com