logo

The OilRig Campaign: Attacks on Saudi Arabian Organizations Deliver Helminth Backdoor - Palo Alto Networks BlogPalo Alto Networks Blog

ID: 2e4ec7e8-7dd5-4ce8-97d5-35c9d926d22a

STIX ID: report--2e4ec7e8-7dd5-4ce8-97d5-35c9d926d22a

Threat Score

78/100

Uploaded: 2026-08-21

Published Date: 2016-05-27

Last Modified Date: 2016-05-27

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
OilRig targeted Saudi Arabian financial and technology organizations, delivering the HelmINTH backdoor via two variants—a macro-delivered VBScript/PowerShell via Excel spreadsheets (ClaySlide) and a standalone Windows executable (HerHer dropper). The campaigns used social engineering, decoy content, and both HTTP and DNS C2 channels to control and exfiltrate data, including a keystroke-logging module in the executable variant, with shared infrastructure across variants and potential Iranian-linked artifacts.