The OilRig Campaign: Attacks on Saudi Arabian Organizations Deliver Helminth Backdoor - Palo Alto Networks BlogPalo Alto Networks Blog
ID: 2e4ec7e8-7dd5-4ce8-97d5-35c9d926d22a
STIX ID: report--2e4ec7e8-7dd5-4ce8-97d5-35c9d926d22a
Threat Score
78/100
Uploaded: 2026-08-21
Published Date: 2016-05-27
Last Modified Date: 2016-05-27
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
OilRig targeted Saudi Arabian financial and technology organizations, delivering the HelmINTH backdoor via two variants—a macro-delivered VBScript/PowerShell via Excel spreadsheets (ClaySlide) and a standalone Windows executable (HerHer dropper). The campaigns used social engineering, decoy content, and both HTTP and DNS C2 channels to control and exfiltrate data, including a keystroke-logging module in the executable variant, with shared infrastructure across variants and potential Iranian-linked artifacts.
