home.social

#oilrig — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #oilrig, aggregated by home.social.

fetched live
  1. New Project CAV3RN .NET Native AOT communication module

    Kaspersky identified a new .NET Native AOT communication module for Project CAV3RN, a sophisticated cyberespionage framework targeting Israel. This module replaces the previous HTTP/WebSocket component by exchanging commands through Outlook calendar events accessed via Microsoft Graph API. Commands and results are stored in a fixed time window (2050-05-13 22:00-23:00 UTC) using specific subject patterns to identify heartbeats, commands, and outputs. The module implements RSA and AES-GCM encryption for secure communications. If Microsoft Graph authentication fails, it retrieves replacement configuration settings through DNS AAAA record responses from actor-controlled nameservers. The infrastructure analysis and behavioral patterns suggest low-confidence attribution to OilRig (APT34), based on the use of Microsoft-hosted services for command and control and compromised regional infrastructure.

    Pulse ID: 6a5f55d6d75eaa9d17122eea
    Pulse Link: otx.alienvault.com/pulse/6a5f5
    Pulse Author: AlienVault
    Created: 2026-07-21 11:19:50

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #APT34 #CyberSecurity #Cyberespionage #DNS #Encryption #Espionage #HTTP #InfoSec #Israel #Kaspersky #Microsoft #NET #OTX #OilRig #OpenThreatExchange #Outlook #RAT #Troll #bot #AlienVault

  2. New Project CAV3RN .NET Native AOT communication module

    Kaspersky identified a new .NET Native AOT communication module for Project CAV3RN, a sophisticated cyberespionage framework targeting Israel. This module replaces the previous HTTP/WebSocket component by exchanging commands through Outlook calendar events accessed via Microsoft Graph API. Commands and results are stored in a fixed time window (2050-05-13 22:00-23:00 UTC) using specific subject patterns to identify heartbeats, commands, and outputs. The module implements RSA and AES-GCM encryption for secure communications. If Microsoft Graph authentication fails, it retrieves replacement configuration settings through DNS AAAA record responses from actor-controlled nameservers. The infrastructure analysis and behavioral patterns suggest low-confidence attribution to OilRig (APT34), based on the use of Microsoft-hosted services for command and control and compromised regional infrastructure.

    Pulse ID: 6a5f55d6d75eaa9d17122eea
    Pulse Link: otx.alienvault.com/pulse/6a5f5
    Pulse Author: AlienVault
    Created: 2026-07-21 11:19:50

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #APT34 #CyberSecurity #Cyberespionage #DNS #Encryption #Espionage #HTTP #InfoSec #Israel #Kaspersky #Microsoft #NET #OTX #OilRig #OpenThreatExchange #Outlook #RAT #Troll #bot #AlienVault

  3. Cavern Manticore: Exposing Iran-Linked Modular C2 Framework

    Check Point Research tracks Cavern Manticore, an Iran-nexus threat actor targeting Israeli government and IT sectors. The actor deploys a modular C2 framework built on .NET but compiled into different formats including Mixed-Mode C++/CLI and Native AOT, creating significant anti-analysis challenges. The framework consists of core agents and specialized post-exploitation modules providing capabilities for file system operations, database browsing, LDAP querying, network reconnaissance, and tunneling. Initial access is achieved through abuse of Remote Monitoring and Management software like SysAid. The actor demonstrates supply-chain compromise tactics, using IT providers as stepping stones to reach higher-value targets. Technical overlaps link Cavern Manticore to Iranian MOIS-aligned groups including MuddyWater and Lyceum subgroup of OilRig.

    Pulse ID: 6a4bb565cb9499639bf4125b
    Pulse Link: otx.alienvault.com/pulse/6a4bb
    Pulse Author: AlienVault
    Created: 2026-07-06 14:02:13

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CheckPoint #CyberSecurity #Government #ICS #InfoSec #Iran #Israel #MuddyWater #NET #OTX #OilRig #OpenThreatExchange #RAT #SysAid #bot #AlienVault

  4. Cavern Manticore: Exposing Iran-Linked Modular C2 Framework

    Check Point Research tracks Cavern Manticore, an Iran-nexus threat actor targeting Israeli government and IT sectors. The actor deploys a modular C2 framework built on .NET but compiled into different formats including Mixed-Mode C++/CLI and Native AOT, creating significant anti-analysis challenges. The framework consists of core agents and specialized post-exploitation modules providing capabilities for file system operations, database browsing, LDAP querying, network reconnaissance, and tunneling. Initial access is achieved through abuse of Remote Monitoring and Management software like SysAid. The actor demonstrates supply-chain compromise tactics, using IT providers as stepping stones to reach higher-value targets. Technical overlaps link Cavern Manticore to Iranian MOIS-aligned groups including MuddyWater and Lyceum subgroup of OilRig.

    Pulse ID: 6a4bb565cb9499639bf4125b
    Pulse Link: otx.alienvault.com/pulse/6a4bb
    Pulse Author: AlienVault
    Created: 2026-07-06 14:02:13

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CheckPoint #CyberSecurity #Government #ICS #InfoSec #Iran #Israel #MuddyWater #NET #OTX #OilRig #OpenThreatExchange #RAT #SysAid #bot #AlienVault

  5. The Beast is down… but what does that mean for Alaska’s fragile tundra? 🌨️🛢️ Only frozen ground may have stopped disaster from spreading. Click to see the potential environmental fallout 👉 tinyurl.com/5n84x2a2 #AlaskaNews #NorthSlope #OilRig #Environment #Alaska #AlaskaHeadlineLiving #NewsUpdate #EnvironmentalImpact

  6. The Beast is down… but what does that mean for Alaska’s fragile tundra? 🌨️🛢️ Only frozen ground may have stopped disaster from spreading. Click to see the potential environmental fallout 👉 tinyurl.com/5n84x2a2 #AlaskaNews #NorthSlope #OilRig #Environment #Alaska #AlaskaHeadlineLiving #NewsUpdate #EnvironmentalImpact

  7. #Greece Honorable mention: Infrastructural (#Switzerland)

    alumil.com/arxellence3/awarded

    #Arxellence3 is an Open, One-Stage International Transdisciplinary Architectural ideas #competition that seeks a holistic approach from the participants to preserve historical memory and promote sustainable development on the Cycladic island of #Gyaros

    project “infrastructural: benhuser.com/2025/05/25/gyaros

    #architecture #landscapeplanning #urbanplanning #infrastructure #museum #walkthrough #offshore #oilrig #reuse

  8. #Greece Honorable mention: Infrastructural (#Switzerland)

    alumil.com/arxellence3/awarded

    #Arxellence3 is an Open, One-Stage International Transdisciplinary Architectural ideas #competition that seeks a holistic approach from the participants to preserve historical memory and promote sustainable development on the Cycladic island of #Gyaros

    project “infrastructural: benhuser.com/2025/05/25/gyaros

    #architecture #landscapeplanning #urbanplanning #infrastructure #museum #walkthrough #offshore #oilrig #reuse

  9. A #Yorkshireman working on a #NorthSea #oilrig rescued an #owl that had been blown nearly 300km off course by #StormAmy - he fed her for a few days and she was collected by a #wildlife sanctuary in #Shetland , checked over by #vets and released

    (it is impressive the lad was able to catch an owl and even had all the kit ready to look after her!)

    #Scotland #Yorkshire #UK #bird #wildlife

    bbc.co.uk/news/articles/cvgde0

  10. A #Yorkshireman working on a #NorthSea #oilrig rescued an #owl that had been blown nearly 300km off course by #StormAmy - he fed her for a few days and she was collected by a #wildlife sanctuary in #Shetland , checked over by #vets and released

    (it is impressive the lad was able to catch an owl and even had all the kit ready to look after her!)

    #Scotland #Yorkshire #UK #bird #wildlife

    bbc.co.uk/news/articles/cvgde0

  11. My cartoon in today's thepost.co.nz/nz-news/35025372

    The fast track bill... Here in Aotearoa New Zealand the collation government are hellbent on destroying the environment for big business. Allowing all the companies that were denied through court cases (yes even the highest court in NZ!) to bulldoze their way into our lands.

    #FastTrackBill #NzPol #EditorialCartoon #PoliticalCartoon #Aotearoa #NewZealand #OilRig #FossilFuels #30percent

  12. My cartoon in today's thepost.co.nz/nz-news/35025372

    The fast track bill... Here in Aotearoa New Zealand the collation government are hellbent on destroying the environment for big business. Allowing all the companies that were denied through court cases (yes even the highest court in NZ!) to bulldoze their way into our lands.

    #FastTrackBill #NzPol #EditorialCartoon #PoliticalCartoon #Aotearoa #NewZealand #OilRig #FossilFuels #30percent

  13. My cartoon in today's @sundaystartimes @thepostnz thepost.co.nz/nz-news/35010907

    It's #BirdOfTheYear again and the alarm is sounding. The German climate diplomat said there's no room for new oil or gas exploration. Yet we know old Luxo has said he will allow new permits on his campaign trail...

    #BirdOfTheYear2023 #Kiwi #Aotearoa #NewZealand #OilRig #Environment #Pollution #Toxic #NzPol

  14. The exact targets of these attacks are not yet known, but the use of decoys suggests that at least one of the organizations being targeted is located in Saudi Arabia.

    #Cybersecurity #Iran #HackerGroup #Malware #APT34 #Menorah #OilRig

    cybersec84.wordpress.com/2023/

  15. The exact targets of these attacks are not yet known, but the use of decoys suggests that at least one of the organizations being targeted is located in Saudi Arabia.

    #Cybersecurity #Iran #HackerGroup #Malware #APT34 #Menorah #OilRig

    cybersec84.wordpress.com/2023/

  16. Hromcová notes that OilRig continues to innovate and develop new implants with backdoor-like functionalities while discovering novel methods to execute commands on remote systems.

    #Cybersecurity #Backdoor #Iranian #OilRig

    cybersec84.wordpress.com/2023/

  17. Hromcová notes that OilRig continues to innovate and develop new implants with backdoor-like functionalities while discovering novel methods to execute commands on remote systems.

    #Cybersecurity #Backdoor #Iranian #OilRig

    cybersec84.wordpress.com/2023/

  18. #GretaThunberg travelled to the UK today to protest against the exploitation of the #Rosebank #oil field, off the coast of #Scotland.
    Rosebank is almost 3 times the size of #Cambo - the #oilfield that people coming together have successfully stopped in 2021.

    The #UK #parliament has deferred debating the licensing of the #oilrig to after recess, Sept 4th. It is therefore perfect timing now for #climateaction & sign the #petition change.org/p/tell-the-uk-gover #EndFossilFuels #stopRosebank

  19. #GretaThunberg travelled to the UK today to protest against the exploitation of the #Rosebank #oil field, off the coast of #Scotland.
    Rosebank is almost 3 times the size of #Cambo - the #oilfield that people coming together have successfully stopped in 2021.

    The #UK #parliament has deferred debating the licensing of the #oilrig to after recess, Sept 4th. It is therefore perfect timing now for #climateaction & sign the #petition change.org/p/tell-the-uk-gover #EndFossilFuels #stopRosebank

  20. This week's wrap-up of infosec news is out, just in time for your morning commute: opalsec.substack.com/p/soc-gou

    #Qakbot have gotten in on the #OneNote action - turns out so too has every other threat actor under the sun.

    Iran's #OilRig/#APT34 has been caught in the act, abusing the legitimate Password Filters feature to siphon creds, and exfiltrating them via compromised mail channels.

    Some interesting techniques were observed in a recent #SocGholish campaign, including passively enumerating usera through event logs and disabling Restricted Admin mode to enable the theft of creds from memory.

    A series of vulnerabilities in the Fortran GoAnywhere MFT file transfer application, QNAP NAS appliances, and VMWare ESXi servers should be top of your list this morning - make sure you're not exposed!

    All that and much more, to help you shake off the cobwebs this Monday morning: opalsec.substack.com/p/soc-gou

    #infosec #CyberAttack #cyber #news #cybernews #infosec #infosecnews #informationsecurity #cybersecurity #hacking #security #technology #hacker #vulnerability #vulnerabilities #malware #ransomware #dfir #redteam #soc #threatintel #threatintelligence #vmware #poc

  21. This week's wrap-up of infosec news is out, just in time for your morning commute: opalsec.substack.com/p/soc-gou

    #Qakbot have gotten in on the #OneNote action - turns out so too has every other threat actor under the sun.

    Iran's #OilRig/#APT34 has been caught in the act, abusing the legitimate Password Filters feature to siphon creds, and exfiltrating them via compromised mail channels.

    Some interesting techniques were observed in a recent #SocGholish campaign, including passively enumerating usera through event logs and disabling Restricted Admin mode to enable the theft of creds from memory.

    A series of vulnerabilities in the Fortran GoAnywhere MFT file transfer application, QNAP NAS appliances, and VMWare ESXi servers should be top of your list this morning - make sure you're not exposed!

    All that and much more, to help you shake off the cobwebs this Monday morning: opalsec.substack.com/p/soc-gou

    #infosec #CyberAttack #cyber #news #cybernews #infosec #infosecnews #informationsecurity #cybersecurity #hacking #security #technology #hacker #vulnerability #vulnerabilities #malware #ransomware #dfir #redteam #soc #threatintel #threatintelligence #vmware #poc

  22. Large oil rigs docked at harbor on the open sea under dramatic cloudy skies off the coast of Santa Cruz de Tenerife, Tenerife Canary Islands
    Komeil Karimi - KNZ_2454
    #santacruzdetenerife #tenerife #canaryislands #nature #landscape #ocean #clouds #cloudscape #opensea #ship #oilrig #palmtrees #industrial #harbour #port #visitspain #visittenerife