EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/espionage-operation/oilrig-campaign
299/430

File EL-0132HighResolvedEspionage Operation / Nation-State Cyber Espionage

OilRig Campaign

Also filed as APT34 · Iran-linked cyber espionage campaign

The OilRig campaign was a sophisticated cyber espionage operation attributed to Iranian state actors, targeting critical infrastructure and government entities across the Middle East and North Africa (MENA). The attackers gained initial access through spear-phishing emails and deployed custom malware to exfiltrate sensitive political, military, and economic data. The operation demonstrated a clear geopolitical focus on gathering intelligence on regional rivals.

  • #iran
  • #apt34
  • #cyber-espionage
  • #mena
  • #oilrig
Notoriety7/10
Event
1 Jan 2014
Disclosed
1 Jan 2014
Target
MENA Governments and Financial Institutions
Actor
OilRig
Scale
Unknown (estimated to be large, involving thousands of documents)
Status
Resolved

01Summary

The OilRig campaign, active around early 2014, was characterized by highly targeted spear-phishing attacks aimed at high-value individuals within government, military, and financial sectors across the MENA region. The attackers utilized custom malware, including backdoors and data stealers, to establish persistent access within victim networks. Once inside, the threat actors conducted extensive reconnaissance, mapping the network topology and identifying key data repositories. The primary objective was the exfiltration of classified documents, diplomatic cables, and financial records pertaining to regional stability and rival nations. The campaign's scope indicated a coordinated effort by a state-sponsored group to build a comprehensive intelligence profile of its geopolitical adversaries.

02Background

The geopolitical tensions in the Middle East and North Africa during the early 2010s provided a fertile ground for state-sponsored cyber conflict. Iran has historically been accused of engaging in cyber operations against regional rivals, making the OilRig campaign consistent with documented patterns of Iranian intelligence activity. The campaign specifically targeted nations perceived as threats to Iranian regional influence.

03Key revelations

  1. 01The successful targeting of multiple, geographically diverse, and politically opposed nations in the MENA region.
  2. 02The ability of the threat actor to penetrate high-security government and military networks.
  3. 03The focus on gathering intelligence related to regional power dynamics and rival leadership.

04Technical analysis

The threat actors employed a multi-stage attack chain, beginning with social engineering via spear-phishing. The initial payload often contained custom malware designed to evade signature-based detection. Once executed, the malware established persistence and facilitated lateral movement, allowing the attackers to escalate privileges and locate high-value data. The exfiltration process was typically slow and methodical, often tunneling data out through encrypted channels to avoid detection.

Attack vector
Spear-phishing emails
Attack method
Espionage and Data Exfiltration
Initial access
Spear-phishing
Lateral movement
Pass-the-hash or exploiting internal network vulnerabilities
Persistence
Scheduled tasks or registry modifications
Exfiltration
Encrypted channels (e.g., DNS tunneling or custom protocols)
Tool / malware
Custom malware (specific names often redacted or proprietary)
Malware type
Backdoor, Stealer

MITRE ATT&CK techniques

  • T1566.001
  • T1071.001
  • T1547.001

05Threat actor

OilRig is widely attributed to Iranian intelligence services, suggesting a high degree of state backing and resources. The group's operational tempo and diverse targeting suggest a mandate to gather intelligence supporting Iran's regional strategic goals.

Aliases

  • APT34
  • Iran

APT designations

  • APT34

MITRE groups

  • T1566.001
  • T1071.001

Attribution sources

  • Mandiant
  • FireEye
  • Cybersecurity Research Firms

06Victims and impact

Additional victims

  • Saudi Arabia
  • UAE
  • Qatar
  • Egypt

Countries affected

  • Saudi Arabia
  • United Arab Emirates
  • Qatar
  • Egypt
  • Jordan

07Data exposed

Data types

  • Diplomatic Cables
  • Financial Records
  • Military Plans
  • Political Correspondence
  • PII

Notable documents

  • Diplomatic cables concerning regional security
  • Financial transaction records of state-owned enterprises
  • Military strategic plans

08Financial damage

Damage is assessed in terms of intelligence loss and geopolitical instability, not direct financial theft.

09Timeline

  1. 2013-12-01Initial spear-phishing attacks begin against MENA targets.
  2. 2014-01-01The campaign is publicly disclosed by cybersecurity firms.
  3. 2014-06-01Observed activity significantly decreases, suggesting the end of the primary operational phase.

10Reaction and fallout

Public reaction

The disclosure heightened international awareness regarding the sophistication of state-sponsored cyber espionage in the Middle East. It prompted increased security spending and cooperation among regional intelligence agencies.

Political impact

The campaign contributed to the ongoing geopolitical tensions, reinforcing the narrative of cyber conflict between regional powers. It increased scrutiny on digital infrastructure security across the MENA region.

Geopolitical consequences

The incident underscored the weaponization of information and technology in regional conflicts, making cyber defense a critical component of national security strategy for Gulf Cooperation Council (GCC) states.

11Legal

No specific international legal action was taken, but the incident contributed to calls for stronger international norms of cyber warfare and attribution.

12Aftermath

Policy changes

  • Increased emphasis on national cyber defense strategies in GCC countries.

Regulatory changes

  • Adoption of stricter data localization and network segmentation policies in critical infrastructure sectors.

Security improvements

  • Mandatory implementation of advanced threat detection and incident response (IR) protocols.
  • Enhanced employee training against spear-phishing attacks.

13Significance and legacy

Significance

OilRig is a seminal example of state-sponsored cyber espionage targeting a specific, volatile geopolitical region. It demonstrated the capability of advanced persistent threats (APTs) to conduct long-term, low-profile intelligence gathering against multiple, high-value, and hostile targets simultaneously.

Legacy

The campaign contributed significantly to the modern understanding of cyber conflict in the Middle East, shifting the focus from simple data theft to comprehensive intelligence warfare. It solidified the concept of 'cyber deterrence' in the region.

14Disclosure and media

Authentication
Technical analysis of malware and network artifacts

Media partners

  • Mandiant
  • FireEye

Publishing organisations

  • Mandiant
  • FireEye

15Field notes

  1. 01The campaign's focus on the MENA region highlights the intersection of cyber conflict and oil/gas industry interests.
  2. 02The use of custom malware allowed the threat actors to bypass many commercial security solutions available at the time.

16Resolution

The campaign was attributed to Iranian state actors and served as a major warning to regional governments regarding the persistent threat of intelligence gathering.

17Sources

Official documents

  • Mandiant Threat Report (2014)

References

  1. [1]Mandiant
  2. [2]FireEye
Fact sheetEL-0132

Dates

Event
1 Jan 2014
Started
1 Dec 2013
Ended
1 Jun 2014
Duration
181 days
Discovered
1 Jan 2014
Disclosed
1 Jan 2014
Ongoing
No

Target

Organisation
MENA Governments and Financial Institutions
Type
Mixed
Sector
Government, Finance, Energy
Country
Multiple (MENA region)
Gov. level
Federal

Actor

Name
OilRig
Type
Nation-State Actor
Nationality
Iranian
Nation-state
Iran
Affiliation
Iranian intelligence services
Motivation
Geopolitical intelligence gathering, targeting regional rivals and critical infrastructure in the Middle East and North Africa (MENA).
Attribution
Medium
Status
Active
Arrested
No
Convicted
No

Data

Volume
Unknown (estimated to be large, involving thousands of documents)
Sensitivity
Top Secret
Published
No

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.