Iranian hackers OilRig (also known as APT34) appear to have compromised at least a dozen computersbelonging to a Middle Easternand maintained access for eight months (between February and September 2023).

The OilRig group is linked to Iran's Ministry of Intelligence and Security (MOIS), and has been linked to cyberattacks against the US, the Middle East, and Albania.
Attacks observed by researchers at Symantec, part of Broadcom, were used to steal passwords and data, as well as install a PowerShell backdoor called “PowerExchange”.
PowerExchange was first documented in a report by Fortinet in May 2023. The company attributed the backdoor to APT34. The samples were recovered from compromised systems of a government agency in the United Arab Emirates.
See also: Lazarus hackers target users with fake interviews via trojanized VNC apps
In the attacks observed by Symantec, the malware connects to an Exchange Server using the provided credentials and monitors incoming emails for “@@” in the subject line, which indicates that the email contains a base64-encoded attachment with commands to execute.
After executing arbitrary PowerShell commands, which typically involve writing or extracting files, the malware moves the messages to “Deleted Items” to minimize the likelihood of detection.
The output of the executed commands is then sent by email to the attackers.
The Exchange in these attacks allows the Iranian OilRig hackers to blend their activities with standard network traffic.
According to researchers, the hacking group is also using other tools in this recent attack:
- Backdoor.Tokel: Executes PowerShell commands and downloads files.
- Mimikatz: Steals credentials.
- Trojan.Dirps: Enumerates files and executes PowerShell commands.
- Infostealer.Clipog: Steals clipboard data and records keystrokes.
- Plink: Command-line tool for PuTTY SSH client.
OilRig attack on Middle Eastern government network lasted 8 months
The attacks observed by Symantec began on February 1, 2023, and used various tools and malware.
The attack began with the introduction of a PowerShell script (joper.ps1), which was executed multiple times in the first week.
See also: Lazarus and Andariel hackers exploit TeamCity bug for network breaches
On February 5, the attackers compromised a second computer on the network and used a disguised version of Plink ('mssh.exe') to set up RDP access . Towards the end of February, the ' netstat /an ' command was detected running on a web server.
Two months later, in April, OilRig compromised two more systems, executing unknown batch files (“p2.bat”) and deploying Mimikatz to steal credentials.
In June, the hackers executed Backdoor.Tokel and PowerExchange on the compromised machines, which is how the main phase of the attack began.
In July, attackers deployed TrojanDirps and Infostealer.Clipog and created SSH tunnels with Plink.
In August, the hackers performed Nessus for Log4j vulnerabilities and by the end of the month, they had compromised a second web server, installing Infostealer.Clipog.
In September, three more computers, using certutil to download Plink on them and executing Wireshark commands on the second webserver to capture USB traffic packets. Two more computers were compromised on September 5, executing the Backdoor.Token implant on them. The activity on the second webserver continued until September 9.
According to Symantec researchers, malicious activity was observed on at least 12 computers on the victim's network, but there is evidence that backdoors and keyloggers had been deployed on dozens of others.
As shown by this recent attack, the Iranian OilRig hackers use a combination of tools, scripts, malware, and techniques to expand and maintain access to a compromised network.
See also: Russian hackers “Sandworm” breached 11 telecom providers in Ukraine
Symantec concludes that despite OilRig facing an existential threat in 2019 when toolset , it is now stronger than ever.
Cyberattacks
In the age of technology, cybersecurity has become an integral part of our daily lives. Cyberattacks are multiplying exponentially and protection against them is becoming an imperative.
Cyber threats are increasing in frequency and complexity, creating a challenging environment for those attempting to address them. Protecting systems and data from existing and new threats requires the continuous updating of defense strategies and technological means.
The devastation that a successful cyberattack can cause to an organization can be devastating, with consequences that can extend to reputation, financial stability, and of course, customer trust in it.
Source: www.bleepingcomputer.com
