OilRig, also known as APT34, is an Iranian threat actor linked to Cavern with low confidence. It has used Microsoft-hosted services for C2 and secondary recovery mechanisms, as observed in OilBooster and other malware.
OilRig, also known as APT34, is an Iranian threat actor linked to Cavern with low confidence. It has used Microsoft-hosted services for C2 and secondary recovery mechanisms, as observed in OilBooster and other malware.