APT34
Nation-state Espionage Iran Dormant
Aliases: OilRig ยท Helix Kitten ยท Hazel Sandstorm ยท Cobalt Gypsy ยท Earth Simnavaz
Also seen as: OilRig
- Mentions
- 1
- First seen
- 21 Jul 2026
- Last seen
- 21 Jul 2026
Relevant to you ยท Relevant
- Threat focus:
- espionage / apt
Origin
Iran โ Iranian MOIS
Profile
APT34, an Iranian threat group, is linked to a new module called Project CAV3RN. This module abuses Outlook calendar events for command and control and DNS AAAA records for configuration recovery.
Affected vendors
Microsoft
Associated malware / tools
Project CAV3RN