home.social

#oilrig — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #oilrig, aggregated by home.social.

  1. New Project CAV3RN .NET Native AOT communication module

    Kaspersky identified a new .NET Native AOT communication module for Project CAV3RN, a sophisticated cyberespionage framework targeting Israel. This module replaces the previous HTTP/WebSocket component by exchanging commands through Outlook calendar events accessed via Microsoft Graph API. Commands and results are stored in a fixed time window (2050-05-13 22:00-23:00 UTC) using specific subject patterns to identify heartbeats, commands, and outputs. The module implements RSA and AES-GCM encryption for secure communications. If Microsoft Graph authentication fails, it retrieves replacement configuration settings through DNS AAAA record responses from actor-controlled nameservers. The infrastructure analysis and behavioral patterns suggest low-confidence attribution to OilRig (APT34), based on the use of Microsoft-hosted services for command and control and compromised regional infrastructure.

    Pulse ID: 6a5f55d6d75eaa9d17122eea
    Pulse Link: otx.alienvault.com/pulse/6a5f5
    Pulse Author: AlienVault
    Created: 2026-07-21 11:19:50

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #APT34 #CyberSecurity #Cyberespionage #DNS #Encryption #Espionage #HTTP #InfoSec #Israel #Kaspersky #Microsoft #NET #OTX #OilRig #OpenThreatExchange #Outlook #RAT #Troll #bot #AlienVault

  2. New Project CAV3RN .NET Native AOT communication module

    Kaspersky identified a new .NET Native AOT communication module for Project CAV3RN, a sophisticated cyberespionage framework targeting Israel. This module replaces the previous HTTP/WebSocket component by exchanging commands through Outlook calendar events accessed via Microsoft Graph API. Commands and results are stored in a fixed time window (2050-05-13 22:00-23:00 UTC) using specific subject patterns to identify heartbeats, commands, and outputs. The module implements RSA and AES-GCM encryption for secure communications. If Microsoft Graph authentication fails, it retrieves replacement configuration settings through DNS AAAA record responses from actor-controlled nameservers. The infrastructure analysis and behavioral patterns suggest low-confidence attribution to OilRig (APT34), based on the use of Microsoft-hosted services for command and control and compromised regional infrastructure.

    Pulse ID: 6a5f55d6d75eaa9d17122eea
    Pulse Link: otx.alienvault.com/pulse/6a5f5
    Pulse Author: AlienVault
    Created: 2026-07-21 11:19:50

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #APT34 #CyberSecurity #Cyberespionage #DNS #Encryption #Espionage #HTTP #InfoSec #Israel #Kaspersky #Microsoft #NET #OTX #OilRig #OpenThreatExchange #Outlook #RAT #Troll #bot #AlienVault

  3. New Project CAV3RN .NET Native AOT communication module

    Kaspersky identified a new .NET Native AOT communication module for Project CAV3RN, a sophisticated cyberespionage framework targeting Israel. This module replaces the previous HTTP/WebSocket component by exchanging commands through Outlook calendar events accessed via Microsoft Graph API. Commands and results are stored in a fixed time window (2050-05-13 22:00-23:00 UTC) using specific subject patterns to identify heartbeats, commands, and outputs. The module implements RSA and AES-GCM encryption for secure communications. If Microsoft Graph authentication fails, it retrieves replacement configuration settings through DNS AAAA record responses from actor-controlled nameservers. The infrastructure analysis and behavioral patterns suggest low-confidence attribution to OilRig (APT34), based on the use of Microsoft-hosted services for command and control and compromised regional infrastructure.

    Pulse ID: 6a5f55d6d75eaa9d17122eea
    Pulse Link: otx.alienvault.com/pulse/6a5f5
    Pulse Author: AlienVault
    Created: 2026-07-21 11:19:50

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #APT34 #CyberSecurity #Cyberespionage #DNS #Encryption #Espionage #HTTP #InfoSec #Israel #Kaspersky #Microsoft #NET #OTX #OilRig #OpenThreatExchange #Outlook #RAT #Troll #bot #AlienVault

  4. New Project CAV3RN .NET Native AOT communication module

    Kaspersky identified a new .NET Native AOT communication module for Project CAV3RN, a sophisticated cyberespionage framework targeting Israel. This module replaces the previous HTTP/WebSocket component by exchanging commands through Outlook calendar events accessed via Microsoft Graph API. Commands and results are stored in a fixed time window (2050-05-13 22:00-23:00 UTC) using specific subject patterns to identify heartbeats, commands, and outputs. The module implements RSA and AES-GCM encryption for secure communications. If Microsoft Graph authentication fails, it retrieves replacement configuration settings through DNS AAAA record responses from actor-controlled nameservers. The infrastructure analysis and behavioral patterns suggest low-confidence attribution to OilRig (APT34), based on the use of Microsoft-hosted services for command and control and compromised regional infrastructure.

    Pulse ID: 6a5f55d6d75eaa9d17122eea
    Pulse Link: otx.alienvault.com/pulse/6a5f5
    Pulse Author: AlienVault
    Created: 2026-07-21 11:19:50

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #APT34 #CyberSecurity #Cyberespionage #DNS #Encryption #Espionage #HTTP #InfoSec #Israel #Kaspersky #Microsoft #NET #OTX #OilRig #OpenThreatExchange #Outlook #RAT #Troll #bot #AlienVault

  5. New Project CAV3RN .NET Native AOT communication module

    Kaspersky identified a new .NET Native AOT communication module for Project CAV3RN, a sophisticated cyberespionage framework targeting Israel. This module replaces the previous HTTP/WebSocket component by exchanging commands through Outlook calendar events accessed via Microsoft Graph API. Commands and results are stored in a fixed time window (2050-05-13 22:00-23:00 UTC) using specific subject patterns to identify heartbeats, commands, and outputs. The module implements RSA and AES-GCM encryption for secure communications. If Microsoft Graph authentication fails, it retrieves replacement configuration settings through DNS AAAA record responses from actor-controlled nameservers. The infrastructure analysis and behavioral patterns suggest low-confidence attribution to OilRig (APT34), based on the use of Microsoft-hosted services for command and control and compromised regional infrastructure.

    Pulse ID: 6a5f55d6d75eaa9d17122eea
    Pulse Link: otx.alienvault.com/pulse/6a5f5
    Pulse Author: AlienVault
    Created: 2026-07-21 11:19:50

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #APT34 #CyberSecurity #Cyberespionage #DNS #Encryption #Espionage #HTTP #InfoSec #Israel #Kaspersky #Microsoft #NET #OTX #OilRig #OpenThreatExchange #Outlook #RAT #Troll #bot #AlienVault

  6. Cavern Manticore: Exposing Iran-Linked Modular C2 Framework

    Check Point Research tracks Cavern Manticore, an Iran-nexus threat actor targeting Israeli government and IT sectors. The actor deploys a modular C2 framework built on .NET but compiled into different formats including Mixed-Mode C++/CLI and Native AOT, creating significant anti-analysis challenges. The framework consists of core agents and specialized post-exploitation modules providing capabilities for file system operations, database browsing, LDAP querying, network reconnaissance, and tunneling. Initial access is achieved through abuse of Remote Monitoring and Management software like SysAid. The actor demonstrates supply-chain compromise tactics, using IT providers as stepping stones to reach higher-value targets. Technical overlaps link Cavern Manticore to Iranian MOIS-aligned groups including MuddyWater and Lyceum subgroup of OilRig.

    Pulse ID: 6a4bb565cb9499639bf4125b
    Pulse Link: otx.alienvault.com/pulse/6a4bb
    Pulse Author: AlienVault
    Created: 2026-07-06 14:02:13

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CheckPoint #CyberSecurity #Government #ICS #InfoSec #Iran #Israel #MuddyWater #NET #OTX #OilRig #OpenThreatExchange #RAT #SysAid #bot #AlienVault

  7. Cavern Manticore: Exposing Iran-Linked Modular C2 Framework

    Check Point Research tracks Cavern Manticore, an Iran-nexus threat actor targeting Israeli government and IT sectors. The actor deploys a modular C2 framework built on .NET but compiled into different formats including Mixed-Mode C++/CLI and Native AOT, creating significant anti-analysis challenges. The framework consists of core agents and specialized post-exploitation modules providing capabilities for file system operations, database browsing, LDAP querying, network reconnaissance, and tunneling. Initial access is achieved through abuse of Remote Monitoring and Management software like SysAid. The actor demonstrates supply-chain compromise tactics, using IT providers as stepping stones to reach higher-value targets. Technical overlaps link Cavern Manticore to Iranian MOIS-aligned groups including MuddyWater and Lyceum subgroup of OilRig.

    Pulse ID: 6a4bb565cb9499639bf4125b
    Pulse Link: otx.alienvault.com/pulse/6a4bb
    Pulse Author: AlienVault
    Created: 2026-07-06 14:02:13

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CheckPoint #CyberSecurity #Government #ICS #InfoSec #Iran #Israel #MuddyWater #NET #OTX #OilRig #OpenThreatExchange #RAT #SysAid #bot #AlienVault

  8. Cavern Manticore: Exposing Iran-Linked Modular C2 Framework

    Check Point Research tracks Cavern Manticore, an Iran-nexus threat actor targeting Israeli government and IT sectors. The actor deploys a modular C2 framework built on .NET but compiled into different formats including Mixed-Mode C++/CLI and Native AOT, creating significant anti-analysis challenges. The framework consists of core agents and specialized post-exploitation modules providing capabilities for file system operations, database browsing, LDAP querying, network reconnaissance, and tunneling. Initial access is achieved through abuse of Remote Monitoring and Management software like SysAid. The actor demonstrates supply-chain compromise tactics, using IT providers as stepping stones to reach higher-value targets. Technical overlaps link Cavern Manticore to Iranian MOIS-aligned groups including MuddyWater and Lyceum subgroup of OilRig.

    Pulse ID: 6a4bb565cb9499639bf4125b
    Pulse Link: otx.alienvault.com/pulse/6a4bb
    Pulse Author: AlienVault
    Created: 2026-07-06 14:02:13

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CheckPoint #CyberSecurity #Government #ICS #InfoSec #Iran #Israel #MuddyWater #NET #OTX #OilRig #OpenThreatExchange #RAT #SysAid #bot #AlienVault

  9. Cavern Manticore: Exposing Iran-Linked Modular C2 Framework

    Check Point Research tracks Cavern Manticore, an Iran-nexus threat actor targeting Israeli government and IT sectors. The actor deploys a modular C2 framework built on .NET but compiled into different formats including Mixed-Mode C++/CLI and Native AOT, creating significant anti-analysis challenges. The framework consists of core agents and specialized post-exploitation modules providing capabilities for file system operations, database browsing, LDAP querying, network reconnaissance, and tunneling. Initial access is achieved through abuse of Remote Monitoring and Management software like SysAid. The actor demonstrates supply-chain compromise tactics, using IT providers as stepping stones to reach higher-value targets. Technical overlaps link Cavern Manticore to Iranian MOIS-aligned groups including MuddyWater and Lyceum subgroup of OilRig.

    Pulse ID: 6a4bb565cb9499639bf4125b
    Pulse Link: otx.alienvault.com/pulse/6a4bb
    Pulse Author: AlienVault
    Created: 2026-07-06 14:02:13

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CheckPoint #CyberSecurity #Government #ICS #InfoSec #Iran #Israel #MuddyWater #NET #OTX #OilRig #OpenThreatExchange #RAT #SysAid #bot #AlienVault

  10. Cavern Manticore: Exposing Iran-Linked Modular C2 Framework

    Check Point Research tracks Cavern Manticore, an Iran-nexus threat actor targeting Israeli government and IT sectors. The actor deploys a modular C2 framework built on .NET but compiled into different formats including Mixed-Mode C++/CLI and Native AOT, creating significant anti-analysis challenges. The framework consists of core agents and specialized post-exploitation modules providing capabilities for file system operations, database browsing, LDAP querying, network reconnaissance, and tunneling. Initial access is achieved through abuse of Remote Monitoring and Management software like SysAid. The actor demonstrates supply-chain compromise tactics, using IT providers as stepping stones to reach higher-value targets. Technical overlaps link Cavern Manticore to Iranian MOIS-aligned groups including MuddyWater and Lyceum subgroup of OilRig.

    Pulse ID: 6a4bb565cb9499639bf4125b
    Pulse Link: otx.alienvault.com/pulse/6a4bb
    Pulse Author: AlienVault
    Created: 2026-07-06 14:02:13

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CheckPoint #CyberSecurity #Government #ICS #InfoSec #Iran #Israel #MuddyWater #NET #OTX #OilRig #OpenThreatExchange #RAT #SysAid #bot #AlienVault

  11. The Beast is down… but what does that mean for Alaska’s fragile tundra? 🌨️🛢️ Only frozen ground may have stopped disaster from spreading. Click to see the potential environmental fallout 👉 tinyurl.com/5n84x2a2 #AlaskaNews #NorthSlope #OilRig #Environment #Alaska #AlaskaHeadlineLiving #NewsUpdate #EnvironmentalImpact

  12. The Beast is down… but what does that mean for Alaska’s fragile tundra? 🌨️🛢️ Only frozen ground may have stopped disaster from spreading. Click to see the potential environmental fallout 👉 tinyurl.com/5n84x2a2 #AlaskaNews #NorthSlope #OilRig #Environment #Alaska #AlaskaHeadlineLiving #NewsUpdate #EnvironmentalImpact

  13. The Beast is down… but what does that mean for Alaska’s fragile tundra? 🌨️🛢️ Only frozen ground may have stopped disaster from spreading. Click to see the potential environmental fallout 👉 tinyurl.com/5n84x2a2 #AlaskaNews #NorthSlope #OilRig #Environment #Alaska #AlaskaHeadlineLiving #NewsUpdate #EnvironmentalImpact

  14. The Beast is down… but what does that mean for Alaska’s fragile tundra? 🌨️🛢️ Only frozen ground may have stopped disaster from spreading. Click to see the potential environmental fallout 👉 tinyurl.com/5n84x2a2 #AlaskaNews #NorthSlope #OilRig #Environment #Alaska #AlaskaHeadlineLiving #NewsUpdate #EnvironmentalImpact

  15. The Beast is down… but what does that mean for Alaska’s fragile tundra? 🌨️🛢️ Only frozen ground may have stopped disaster from spreading. Click to see the potential environmental fallout 👉 tinyurl.com/5n84x2a2 #AlaskaNews #NorthSlope #OilRig #Environment #Alaska #AlaskaHeadlineLiving #NewsUpdate #EnvironmentalImpact

  16. #Greece Honorable mention: Infrastructural (#Switzerland)

    alumil.com/arxellence3/awarded

    #Arxellence3 is an Open, One-Stage International Transdisciplinary Architectural ideas #competition that seeks a holistic approach from the participants to preserve historical memory and promote sustainable development on the Cycladic island of #Gyaros

    project “infrastructural: benhuser.com/2025/05/25/gyaros

    #architecture #landscapeplanning #urbanplanning #infrastructure #museum #walkthrough #offshore #oilrig #reuse

  17. #Greece Honorable mention: Infrastructural (#Switzerland)

    alumil.com/arxellence3/awarded

    #Arxellence3 is an Open, One-Stage International Transdisciplinary Architectural ideas #competition that seeks a holistic approach from the participants to preserve historical memory and promote sustainable development on the Cycladic island of #Gyaros

    project “infrastructural: benhuser.com/2025/05/25/gyaros

    #architecture #landscapeplanning #urbanplanning #infrastructure #museum #walkthrough #offshore #oilrig #reuse

  18. #Greece Honorable mention: Infrastructural (#Switzerland)

    alumil.com/arxellence3/awarded

    #Arxellence3 is an Open, One-Stage International Transdisciplinary Architectural ideas #competition that seeks a holistic approach from the participants to preserve historical memory and promote sustainable development on the Cycladic island of #Gyaros

    project “infrastructural: benhuser.com/2025/05/25/gyaros

    #architecture #landscapeplanning #urbanplanning #infrastructure #museum #walkthrough #offshore #oilrig #reuse

  19. #Greece Honorable mention: Infrastructural (#Switzerland)

    alumil.com/arxellence3/awarded

    #Arxellence3 is an Open, One-Stage International Transdisciplinary Architectural ideas #competition that seeks a holistic approach from the participants to preserve historical memory and promote sustainable development on the Cycladic island of #Gyaros

    project “infrastructural: benhuser.com/2025/05/25/gyaros

    #architecture #landscapeplanning #urbanplanning #infrastructure #museum #walkthrough #offshore #oilrig #reuse

  20. #Greece Honorable mention: Infrastructural (#Switzerland)

    alumil.com/arxellence3/awarded

    #Arxellence3 is an Open, One-Stage International Transdisciplinary Architectural ideas #competition that seeks a holistic approach from the participants to preserve historical memory and promote sustainable development on the Cycladic island of #Gyaros

    project “infrastructural: benhuser.com/2025/05/25/gyaros

    #architecture #landscapeplanning #urbanplanning #infrastructure #museum #walkthrough #offshore #oilrig #reuse