basicsecurity.net
Proof, not just disclosure.
Threats / Actors / OilRig
G0049 Nation-stateour call,
not MITRE’s
ATT&CK Group

OilRig

How MITRE ATT&CK characterizes this group1: OilRig is a suspected Iranian threat group that has targeted Middle Eastern and international victims since at least 2014. The group has targeted a variety of sectors, including financial, government, energy, chemical, and telecommunications. It appears the group carries out supply chain attacks, leveraging the trust relationship between organizations to attack their primary targets. The group works on behalf of the Iranian government based on…

Attributed to Iran — MOIS-aligned by government advisory.111

Also tracked as: COBALT GYPSY IRN2 APT34 Helix Kitten Evasive Serpens Hazel Sandstorm EUROPIUM ITG13 Earth Simnavaz Crambus TA452 — ATT&CK group page1
Read this as · tier is our editorial call, not MITRE’s

Read as a state-directed operator, not a smash-and-grab.

A nation-state classification means patience, tradecraft, and an intelligence objective. When this name attaches to a vulnerability, the question shifts from “will someone exploit it” to “has a well-resourced service already built it into an operation.” All tradecraft below is sourced to MITRE ATT&CK.

76
Techniques
ATT&CK count1
30
Named tools / malware
ATT&CK count2
2
Attributed campaigns
ATT&CK count1
12
Tactics spanned
ATT&CK count1
~2021–2022approx.
Activity bounds (campaign floor)
approximate1
01

Known for

— signature moves, each sourced to ATT&CK
CampaignOuter Space. ATT&CK tracks this attributed operation as C0042.109
CampaignJuicy Mix. ATT&CK tracks this attributed operation as C0044.110
ArsenalNamed tooling. ATT&CK attributes 30 tools/malware to this group, including Mimikatz, PsExec, Net, Tasklist.79
ReachFurthest outcome. This actor's cited tradecraft reaches as far as outcome 4 — Data at risk — exfiltration. (editorial mapping over ATT&CK tactics).
02

Tradecraft heatmap

— ATT&CK techniques mapped onto the five attacker-outcome narratives

Each row is a documented technique (MITRE ATT&CK). Each column is one of the five attacker-outcome narratives a defender funds against. A filled cell means this technique’s own ATT&CK tactic defensibly advances that outcome. The mapping of technique→outcome is our editorial alignment over ATT&CK's tactic data, not a separately-sourced MITRE edge. A filled cell means one of the technique's own ATT&CK tactics defensibly advances that outcome; enabler tactics (C2, Defense Evasion, Discovery) heat no column.

1Front door
2Keys to the kingdom
3Lateral reach
4Data at risk
5Lights out

Reach: this actor’s cited techniques light columns 1·2·3·4 — furthest is 4 · Data at risk. (furthest-position idiom, reused from the landing map).

A dot = this technique advances that outcomeColumn 5 (Lights out) is empty — Compare: a ransomware or wiper actor lights column 5.
Editorial: the technique→outcome alignment is our call over ATT&CK’s tactic data, not a separately-sourced MITRE edge — same basis the landing page declares. Enabler tactics (C2, defense evasion, discovery) heat no column.1
03

Arsenal

— named tools & malware ATT&CK attributes to this group
MimikatzS0002 · Tool
PsExecS0029 · Tool
NetS0039 · Tool
TasklistS0057 · Tool
RegS0075 · Tool
ftpS0095 · Tool
SysteminfoS0096 · Tool
ipconfigS0100 · Tool
+22 moreCoverage

ATT&CK attributes 30 tools/malware to G0049 in total; the full list is on the group page.

04

Campaign highlights

— attributed operations in the ATT&CK record
A

Outer Space — ATT&CK Campaign C0042

Attributed operation
ATT&CK records Outer Space (C0042) — roughly 2021–2021 as an operation attributed to this group.109
Open ATT&CK C0042 ↗
B

Juicy Mix — ATT&CK Campaign C0044

Attributed operation
ATT&CK records Juicy Mix (C0044) — roughly 2022–2022 as an operation attributed to this group.110
Open ATT&CK C0044 ↗
05

Latest activity

— with explicit confidence, and what we cannot yet claim
ATT&CK
snapshot

The most recent cited activity in this card is the ATT&CK record itself. We do not paste a “last seen this week” line we cannot source. Recency from secondary reporting appears here only when attached to a named advisory.

ATT&CK snapshot, compiled 2026-06-22Coverage gap — live “currently active” status not asserted
CVE ↔ actor bridge — Known exploits / Linked CVEs every link below traces to a named source; tier is explicit
Inferred / reported — lower confidence, never headline attribution 2 link(s)

These are not confirmed attribution. An inferred link is a structural ATT&CK chain (this group uses a tool whose reference cites the CVE); it is back-cited to the original report and never claims the source names the group.

CVE-2017-11882 →

ATT&CK attributes BONDUPDATER (S0360) to this group, and that software’s ATT&CK reference cites CVE-2017-11882. Structural chain — not a statement that the report names the group.

original report (cited on the ATT&CK software page) ↗
CVE-2017-11882 →

ATT&CK attributes POWRUNER (S0184) to this group, and that software’s ATT&CK reference cites CVE-2017-11882. Structural chain — not a statement that the report names the group.

original report (cited on the ATT&CK software page) ↗
06

Coverage & confidence

— what we know, and what we don’t

Established (cited)

  • Group identity, aliases, description — MITRE ATT&CK group page
  • 76 techniques — ATT&CK technique pages (linked per row)
  • 30 software (arsenal) — ATT&CK software pages
  • 2 attributed campaign(s) — ATT&CK campaign pages
  • Origin / sponsor (Iran — MOIS-aligned) — curated government advisory (cited)
  • 16 third-party research citations — ATT&CK external references
  • Coverage gaps — stated, not hidden

  • Threat tier is OUR editorial classification (rule-based), not a MITRE field — labeled as such.
  • Technique → outcome heatmap is editorial alignment over ATT&CK tactic data, not a separately-sourced MITRE edge.
  • Activity bounds are a floor from attributed-campaign dates only — flagged approx., not a true active-since range.
  • ATT&CK has no first-class group→CVE relationship; this card asserts no specific CVE without a named advisory.
  • Empty heatmap column(s): Lights out — consistent with this actor's nature, stated as a finding.