🇮🇷APT34
🇮🇷 APT34 is a tracked threat actor in the Clankerusecase corpus. Attributed to IR. Primary motivation: State. We map 26 detection use cases to this actor across 106 MITRE ATT&CK techniques, with 4 threat-intel articles citing them. Active in our corpus from 2026-02-26 to 2026-07-21.
crit 2high 2
26Use cases
4Articles
106Techniques
20IOCs
Known aliases
APT34OilRigHelix KittenCobalt GypsyHazel SandstormCOBALT GYPSYIRN2Evasive SerpensEUROPIUMITG13Earth SimnavazCrambusTA452
All other tracked techniques
T1003 · OS Credential DumpingT1003.001 · LSASS MemoryT1003.004 · LSA SecretsT1003.005 · Cached Domain CredentialsT1005 · Data from Local SystemT1007 · System Service DiscoveryT1008 · Fallback ChannelsT1012 · Query RegistryT1016 · System Network Configuration DiscoveryT1021.001 · Remote Desktop ProtocolT1021.002 · SMB/Windows Admin SharesT1021.004 · SSHT1025 · Data from Removable MediaT1027 · Obfuscated Files or InformationT1027.005 · Indicator Removal from ToolsT1027.007 · Dynamic API ResolutionT1027.013 · Encrypted/Encoded FileT1033 · System Owner/User DiscoveryT1036 · MasqueradingT1036.005 · Match Legitimate Resource Name or LocationT1046 · Network Service DiscoveryT1047 · Windows Management InstrumentationT1048.003 · Exfiltration Over Unencrypted Non-C2 ProtocolT1049 · System Network Connections DiscoveryT1053.005 · Scheduled TaskT1056.001 · KeyloggingT1057 · Process DiscoveryT1059 · Command and Scripting InterpreterT1059.001 · PowerShellT1059.003 · Windows Command ShellT1059.005 · Visual BasicT1068 · Exploitation for Privilege EscalationT1069.001 · Local GroupsT1069.002 · Domain GroupsT1070.004 · File DeletionT1071 · Application Layer ProtocolT1071.001 · Web ProtocolsT1071.004 · DNST1072 · Software Deployment ToolsT1074.001 · Local Data StagingT1078 · Valid AccountsT1078.002 · Domain AccountsT1082 · System Information DiscoveryT1087 · Account DiscoveryT1087.001 · Local AccountT1087.002 · Domain AccountT1098.001 · Additional Cloud CredentialsT1098.005 · Device RegistrationT1102.002 · Bidirectional CommunicationT1105 · Ingress Tool TransferT1110 · Brute ForceT1110.003 · Password SprayingT1112 · Modify RegistryT1113 · Screen CaptureT1115 · Clipboard DataT1119 · Automated CollectionT1120 · Peripheral Device DiscoveryT1127.001 · MSBuildT1132.001 · Standard EncodingT1133 · External Remote ServicesT1137.004 · Outlook Home PageT1140 · Deobfuscate/Decode Files or InformationT1195 · Supply Chain CompromiseT1195.002 · Compromise Software Supply ChainT1199 · Trusted RelationshipT1201 · Password Policy DiscoveryT1203 · Exploitation for Client ExecutionT1204.001 · Malicious LinkT1204.004 · Malicious Copy and PasteT1218 · System Binary Proxy ExecutionT1218.001 · Compiled HTML FileT1219 · Remote Access ToolsT1486 · Data Encrypted for ImpactT1497.001 · System ChecksT1505.003 · Web ShellT1528 · Steal Application Access TokenT1543.003 · Windows ServiceT1547.001 · Registry Run Keys / Startup FolderT1550.001 · Application Access TokenT1552.001 · Credentials In FilesT1553.002 · Code SigningT1555 · Credentials from Password StoresT1555.003 · Credentials from Web BrowsersT1555.004 · Windows Credential ManagerT1556.002 · Password Filter DLLT1556.006 · Multi-Factor AuthenticationT1566.001 · Spearphishing AttachmentT1566.002 · Spearphishing LinkT1566.003 · Spearphishing via ServiceT1569.002 · Service ExecutionT1572 · Protocol TunnelingT1573.002 · Asymmetric CryptographyT1574.001 · DLLT1574.002 · T1574.002T1574.014 · AppDomainManagerT1583.001 · DomainsT1586.002 · Email AccountsT1587.001 · MalwareT1588.002 · ToolT1588.003 · Code Signing CertificatesT1608.001 · Upload MalwareT1621 · Multi-Factor Authentication Request GenerationT1686.003 · Windows Host Firewall
Detection use cases (26)
APT34/OilRig DNS-tunnel C2 (Helminth / BONDUPDATER / QUADAGENT) — long high-fan-out subdomains from non-browser process APT34 weaponized-macro delivery chain — Office → PowerShell → scheduled-task persistence (Helminth/SideTwist dropper) Cavern Manticore WinDirStat DLL side-load of fake uxtheme.dll (Cavern backdoor) Masqueraded uxtheme.dll dropped outside Windows dirs via SysAid/RMM deployment (Cavern Manticore) AppDomainManager hijacking config artifact dropped in user-writable path (Screening Serpens/UNC1549) Phishing-link click correlated to endpoint execution Email attachment opened from external sender Office app spawning script/LOLBin child process RMM tool installed by non-IT user — remote-access utility for hands-on-keyboard Trusted vendor binary / installer launching unusual children CAV3RN/HOLLOWGRAPH DNS AAAA config-recovery beaconing to cloudlanecdn[.]com CAV3RN AzureCommunication.dll config file 'logAzure.txt' written to disk CAV3RN framework module DLLs loaded/dropped (AzureCommunication / n-HTCommp / masqueraded uxtheme) Anomalous DLL-host process reaching Microsoft Graph/login.microsoftonline for calendar C2 1Password failed sign-in burst 1Password impossible-travel sign-in 1Password item exfiltration attempt 1Password vault export attempted AI-Agent Server (PraisonAI/MCP) Spawns OS Shell or Recon LOLBin — Unauthenticated RCE Exploitation AI/LLM Agent Framework Runtime Spawning Shell, Recon, or Egress Child Process AI/LLM Framework Web Service Spawns Shell or Network Tool (Agent-Framework Unauthenticated RCE) Auth-Bypass on Public-Facing Service → Post-Exploit Action on Same Host (≤10 min) Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes Cross-category credential-store enumeration with rapid egress to anonymizing tunnel/CDN Cross-Platform ClickFix Paste-to-Pipe Loader (UI-Parent Shell with Decode-and-Execute Payload) Developer package install spawning script-host with non-registry C2 within 5 minutesThreat-intel articles (4)
high New Project CAV3RN module abuses Outlook calendar events for C2 and DNS AAAA records for configuration recovery · 2026-07-21
crit PlugX Meeting Invitation via MSBuild and GDATA · 2026-02-26
Tracked indicators
Domains (18)
accesslinkssl.com clipeditskill.com cloudlanecdn.com co.il d.53466d4c67515a.0.p.clo decoorat.net decoraat.net dns1.registrar-servers.c dns2.registrar-servers.c gesecole.net google.com.ayalon-print. login.microsoftonline.co ns1.cloudlanecdn.com ns2.cloudlanecdn.com ns3.cloudlanecdn.com ns4.cloudlanecdn.com onedow.gesecole.net onedown.gesecole.netIP addresses (2)
144.172.108.205 216.126.237.197