Skip to content
Auto-CTI
Back to all actors

APT34

Nation-state Espionage Iran Dormant

Aliases: OilRig ยท Helix Kitten ยท Hazel Sandstorm ยท Cobalt Gypsy ยท Earth Simnavaz

Also seen as: OilRig

Mentions
1
First seen
21 Jul 2026
Last seen
21 Jul 2026

Relevant to you ยท Relevant

Threat focus:
espionage / apt

Origin

Iran โ€” Iranian MOIS

Profile

APT34, an Iranian threat group, is linked to a new module called Project CAV3RN. This module abuses Outlook calendar events for command and control and DNS AAAA records for configuration recovery.

Affected vendors

Microsoft

Associated malware / tools

Project CAV3RN

Activity (8 weeks)

31
32
33
34
35
36
37
38

Recent activity

ESC

โ€ฆ