s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

AI-SEARCH-apt34 medium

📛 Threat Title

AI threat search: APT34

Category: ai-threat-search First seen: Last updated:

Description

AI-discovered findings for topic: 'APT34'. Run at 2026-08-05T02:23:59.024062Z. DuckDuckGo returned 10 result(s); the AI Forensic Validator classified 1 IOC(s) as valid.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain treadstone71.com VT 0 / 91 UrlVoid 0 / 35

IOC database

Type
domain
Value
treadstone71.com
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
AI-search: APT34

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

Basic Properties
RegistrarGoDaddy.com, LLC
TLDcom
History
Creation date2002-03-16 23:08 UTC
Last analysis2026-05-12 09:19 UTC
Last modified on VirusTotal2026-05-22 07:33 UTC
Last WHOIS update2023-04-01 20:21 UTC
WHOIS record date2026-05-11 17:30 UTC

References (20)

  • Iran APT Threat Advisory — Operation Epic Fury | HAWK-EYE Threat ...

    Iran APT Threat Advisory Operation Epic Fury Comprehensive intelligence assessment of Iranian state-sponsored cyber operations following the US-Israel joint offensive (Operation Epic Fury / Operation Roaring Lion). Covers active APT campaigns, hacktivist coordination, GCC-specific threats , and actionable IOCs.

  • PDF APT34/OilRig DNS Tunneling & Sleeper Access Detection - Comprehensive ...

    Threat Overview APT34 represents one of Iran's most persistent and technically capable cyber espionage operations. The group has demonstrated sustained operational capability across more than a decade, surviving a major tool leak in April 2019 by rapidly developing an entirely new malware arsenal.

  • APT34 OilRig Iran: Critical Infrastructure Attacks 2026

    APT34 OilRig is an Iranian state-sponsored advanced persistent threat group attributed to Iran's Islamic Revolutionary Guard Corps (IRGC). Active since at least 2014, APT34 targets governments, critical infrastructure operators, telecommunications providers, and financial institutions that align with Iranian geopolitical adversaries.

  • INTELLIGENCE REPORT — APT34 - Marc Frederic Gomez Blog's

    1. IDENTIFICATION & ATTRIBUTION Designations: OilRig (CrowdStrike), Helix Kitten (CrowdStrike), APT34 (Mandiant/Google), IRN2 (SecureWorks), COBALT GYPSY (SecureWorks), Crambus (Symantec), Earth Simnavaz (Trend Micro), EUROPIUM (Microsoft) Origin: Iran Suspected sponsor: Iranian Ministry of Intelligence (MOIS — Vezarat-e Ettela'at va Amniat-e Keshvar) Sophistication level: High (confirmed ...

  • Hard Pass: Declining APT34's Invite to Join Their Professional Network

    APT34 aligns with elements of activity reported as OilRig and Greenbug, by various security researchers. This threat group has conducted broad targeting across a variety of industries operating in the Middle East; however, we believe APT34's strongest interest is gaining access to financial, energy, and government entities.

  • Researchers Discover New variants of APT34 Malware

    Booz Allen's DarkLabs Threat Hunt team exercised a combination of open-source reporting and acquired sources of threat intelligence , then merged this information with our own internally developed tools to expand and perform deep analysis on previously reported APT34 behaviors.

  • Threat Hunting Techniques for APT34 and APT39

    Strengthen Vulnerability Management: Proactively identify and remediate weaknesses that groups like APT34 exploit. Enhance Threat Intelligence : Stay informed about the TTPs (Tactics, Techniques, and Procedures) of relevant threat actors. By integrating these strategies, organizations can build a more resilient defense.

  • Iranian Threat Actors: What Defenders Need to Know

    Explore a technical breakdown of 33 active Iranian APT groups including APT33, APT34 , APT35, and MuddyWater, covering malware arsenals, TTPs, target sectors, and detection rules for SOC teams and threat hunters.

  • Inside APT34 (OilRig): Tools, Techniques, and Global Cyber Threats

    APT34 , also known as OilRig, Earth Simnavaz, and Helix Kitten, is a sophisticated, state-sponsored cyber threat group with suspected ties to Iran.

  • PDF Iranian_APT_TTP_Report_2026 (2) - horizon3.ai

    Executive Summary This report provides a comprehensive deep-dive into Iranian Advanced Persistent Threat (APT) groups active from 2023 through early 2026. Based on open-source intelligence (OSINT) from CISA advisories, Microsoft Threat Intelligence , Google Mandiant, Palo Alto Unit42, CrowdStrike, and other leading threat research organizations, this document profiles the primary Iranian state ...

  • PDF APT34 Intelligence Analysis Brief - treadstone71.com

    APT34 , a well-known Iranian state-sponsored threat actor, demonstrates sustained operational capacity across Middle Eastern and global targets through adaptive espionage strategies, modular malware families, AI-enhanced cognitive warfare, and deeply embedded infrastructure exploits. Continued escalation of its activities against Gulf-state infrastructure, supply chains, and geopolitical ...

  • Iranian APT Groups Intensify Cyberattacks on Critical Infrastructure ...

    Iranian APT Groups OilRig ( APT34 , Helix Kitten) employs phishing, web shells, and PowerShell for espionage against energy and telecom in the Middle East. Nozomi Threat Intelligence is tracking MuddyWater targeting organizations across the globe (Source : Nozomi Networks).

  • CybersecGen/APT34-Threat-Analysis - GitHub

    Project Overview This project simulates an APT34 -style attack to evaluate how a SOC would detect and respond to advanced threat behaviors. Focus: detection capability, investigation workflow, and security operations readiness using adversary-informed scenarios.

  • Iran APT Threat Advisory — Operation Epic Fury | HAWK-EYE Threat ...

    Iran APT Threat Advisory Operation Epic Fury Comprehensive intelligence assessment of Iranian state-sponsored cyber operations following the US-Israel joint offensive (Operation Epic Fury / Operation Roaring Lion). Covers active APT campaigns, hacktivist coordination, GCC-specific threats , and actionable IOCs.

  • PDF APT34 / OilRig - Threat Actor Profile | Intruvent

    Background APT34 (also known as OilRig) is a suspected Iranian threat group that has targeted Middle Eastern and international victims since at least 2014. The group targets a variety of sectors, including financial services, government, energy, chemical, and telecommunications.

  • APT34: The Evolution of Iran's Cyber Espionage Tactics

    Iran's APT34 has been adapting its tradecraft for over a decade. Organizations in targeted sectors — finance, energy, government — need threat intelligence that reflects how this group actually operates today. Noorstream delivers threat intelligence , vulnerability management, and offensive security assessments for high-risk environments.

  • APT34 Threat Actor Insights - Certfa Radar

    Explore simplified analysis and detailed threat intelligence about APT34 on Threat Actors Insight, collected by Certfa Radar. Stay informed about the activities and tactics of this threat actor associated with the Iranian state.

  • OilRig Exposed: Unveiling the Tools and Techniques of APT34

    Discover the tools, techniques, and tactics of OilRig ( APT34 ), a state-sponsored cyber threat group targeting critical sectors in the Middle East.

  • APT34: OilRig Threat Analysis 2014-2024

    The document provides an advanced persistent threat analysis of OilRig ( APT34 ), an Iranian cyber operations group active since 2014, focusing on their evolution, capabilities, and motivations. It highlights their sophisticated malware development, operational security, and strategic impact on critical infrastructure and financial sectors, emphasizing the need for coordinated international ...

  • OilRig, COBALT GYPSY, IRN2, APT34, Helix Kitten, Evasive Serpens, Hazel ...

    ID: G0049 ⓘ Associated Groups: COBALT GYPSY, IRN2, APT34 , Helix Kitten, Evasive Serpens, Hazel Sandstorm, EUROPIUM, ITG13, Earth Simnavaz, Crambus, TA452 Contributors: Robert Falcone; Bryan Lee; Dragos Threat Intelligence ; Jaesang Oh, KC7 Foundation Version: 5.0 Created: 14 December 2017

Remediations (10)

  • web:attack.mitre.org

    OilRig is a suspected Iranian threat group that has targeted Middle Eastern and international victims since at least 2014. The group has targeted a variety of sectors, including financial, government, energy, chemical, and telecommunications.

  • web:hawk-eye.io

    Iran APT Threat Advisory Operation Epic Fury Comprehensive intelligence assessment of Iranian state-sponsored cyber operations following the US-Israel joint offensive (Operation Epic Fury / Operation Roaring Lion). Covers active APT campaigns, hacktivist coordination, GCC-specific threats , and actionable IOCs.

  • web:noorstream.com

    Iran's APT34 has been adapting its tradecraft for over a decade. Organizations in targeted sectors — finance, energy, government — need threat intelligence that reflects how this group actually operates today. Noorstream delivers threat intelligence, vulnerability management, and offensive security assessments for high-risk environments.

  • web:rewterz.com

    Remediation Block all threat indicators at your respective controls. Search for Indicators of compromise (IOCs) in your environment utilizing your respective security controls. Do not download documents attached in emails from unknown sources and strictly refrain from enabling macros when the source isn't reliable.

  • web:www.picussecurity.com

    Explore a technical breakdown of 33 active Iranian APT groups including APT33, APT34 , APT35, and MuddyWater, covering malware arsenals, TTPs, target sectors, and detection rules for SOC teams and threat hunters.

  • web:www.researchgate.net

    Advanced Persistent Threats (APTs) are a formidable and ever-evolving threat to global cyber security, particularly against critical infrastructure, government networks, and cyber-physical systems.

  • web:www.scribd.com

    The document provides an advanced persistent threat analysis of OilRig ( APT34 ), an Iranian cyber operations group active since 2014, focusing on their evolution, capabilities, and motivations. It highlights their sophisticated malware development, operational security, and strategic impact on critical infrastructure and financial sectors, emphasizing the need for coordinated international ...

  • web:www.treadstone71.com

    APT34 , a well-known Iranian state-sponsored threat actor, demonstrates sustained operational capacity across Middle Eastern and global targets through adaptive espionage strategies, modular malware families, AI -enhanced cognitive warfare, and deeply embedded infrastructure exploits. Continued escalation of its activities against Gulf-state infrastructure, supply chains, and geopolitical ...

  • web:www.trendmicro.com

    Trend Micro's investigation into the recent activity of Earth Simnavaz provides new insights into the APT group's evolving tactics and the immediate threat it poses to sectors in the Middle East.

  • web:www.vectra.ai

    Detect Iranian APT activity across identity and network telemetry with six practical threat hunts. Run ready-to-use queries in the Vectra AI Platform to uncover credential abuse, C2 infrastructure, and early compromise signals.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.