Scenario 05 · Espionage · Iran-nexus
OilRig — Helix Kitten, APT34 — is an Iran-nexus espionage crew whose signature is patience, not force:
don't crack passwords, read the ones already stored on the box and walk in wearing them. We ran a focused, non-destructive
slice of that tradecraft on a live Windows victim, and THRONE lit up the credential grab the instant
vaultcmd touched the vault — with the reconnaissance that framed it and the DNS-tunnel C2 pattern the group is
known for caught alongside.
OilRig (Helix Kitten / APT34, MITRE G0049) is an Iran-nexus espionage actor best known for low-noise credential theft and DNS-tunnelled command-and-control. In this scenario we hand-executed a focused, non-destructive slice of that tradecraft on a Windows victim and measured exactly what THRONE saw.
The run's hallmark step is deliberately quiet. Instead of dumping LSASS or cracking hashes, the operator reaches into
Windows Credential Manager with the built-in vaultcmd.exe utility and reads the credentials a user has
already saved. THRONE flagged that access directly and in real time as ALR-175454 —
Windows Credential Manager Access Via Vaultcmd.EXE, mapped to T1555.004 — and scored it
HIGH. The domain-account reconnaissance that framed the theft
(T1087.002) and the outbound DNS beacon pattern OilRig is famous for
(T1572) were picked up as corroborating, lower-severity signals.
The headline is the smallness of the thing THRONE had to catch. No exploit, no malware binary, no password spray — just one signed, built-in Windows utility doing exactly what it is designed to do, in a context that made it hostile. That is the whole OilRig game, and it is precisely the kind of signal that slips past controls tuned for noisier intrusions.
Tracked by MITRE as G0049 and by vendors as Helix Kitten, Cobalt Gypsy, Earth Simnavaz, Hazel Sandstorm, EUROPIUM and Crambus, OilRig is an Iran-nexus espionage group active since at least 2014 and widely assessed to operate on behalf of Iran's Ministry of Intelligence and Security (MOIS).
OilRig's operations concentrate on the Middle East, with a long record against government ministries, financial services, energy and chemical firms, telecommunications and critical infrastructure. Their objective is classic state espionage — durable access, credential collection, and the quiet exfiltration of information over long dwell times, rather than destruction or extortion. They are an intelligence service with a keyboard, not a smash-and-grab crew.
In 2019 a leak on Telegram under the banner "Lab Dookhtegan" dumped a slice of OilRig's toolkit and victim data in public — a rare exposure of a nation-state kit, web shells and DNS-tunnelling backdoors included. Over the years the group has fielded a deep custom arsenal: the Helminth first-stage backdoor delivered through macro-laden Office documents; the ALMA Communicator and BONDUPDATER DNS backdoors; QUADAGENT (PowerShell); ISMAgent; the TwoFace and RGDoor IIS web shells; RDAT, which smuggles data inside email using steganography; and more recently Saitama, Marlin and Menorah. Many of them share one family trait: they phone home over DNS.
Three habits define OilRig on the ATT&CK matrix. First, DNS-tunnelled command-and-control
(T1071.004 / T1572): encoding beacon traffic inside DNS queries and TXT
answers so it rides out on a protocol almost nobody blocks. Second, credential access from stored secrets
(T1555): rather than always cracking hashes, they harvest what is already saved — browser
credentials, saved logons, and the Windows Credential Manager vault (T1555.004). Third,
living off the land: signed, built-in utilities and LOLBins (certutil, bitsadmin,
scheduled tasks, vaultcmd) so their footprint blends into normal administration. They are also fluent in
trusted-relationship and internal spearphishing (T1199, T1534),
pivoting from one compromised mailbox to phish the victim's trusted contacts.
OilRig is the archetype of the quiet intruder. Nothing in their playbook has to be loud: a macro, a signed binary, a DNS query. Detecting them is less about catching malware and more about catching ordinary tools used with hostile intent — exactly the discrimination THRONE is built to make.
This scenario is deliberately narrow, and honest about it. Rather than an autonomous operation, we hand-executed a focused, non-destructive slice of OilRig's credential-harvesting tradecraft directly on the Windows victim — just enough real activity to throw genuine telemetry and test whether THRONE catches the one step that matters.
The victim is WIN-J50RP1JBGD4 (204.168.192.149 · internal 10.0.0.5), a Windows host instrumented with Sysmon and streaming its event log to the THRONE cloud tenant. We executed the steps directly at an interactive shell — no C2 framework, no implant, and no credential actually exfiltrated — so every signal THRONE raised is attributable to a known, bounded action. This is a lab environment and nothing is hidden: the real IPs, the real hostname and the real alert ID are shown exactly as captured.
Once a process runs on the victim, the path to a triaged alert is automatic and takes seconds:
Sysmon records each process creation with its full command line and the parent/child process GUIDs. The host tags every
line with its tenant before shipping it to THRONE's syslog listener on :1514; Kafka buffers it;
ch_pump parses and normalises it into ClickHouse; the Sigma corpus and the behavioral engine evaluate it; and
ONYX, THRONE's AI SOC analyst, triages the resulting alert into a scored, grouped incident with a causality tree
waiting — before any human looks at it.
This was a single-host, hand-run slice — not a full intrusion. We did not establish initial access, deploy a backdoor, or move laterally. The value here is narrow and specific: can THRONE tell a signed, built-in Windows utility reading the credential vault apart from the same utility used for legitimate administration? It can.
Three tactics, executed in the order a real OilRig operator would: scope the environment, take the stored credentials, and signal home over DNS. Each step generated genuine Windows telemetry that THRONE evaluated.
Before stealing anything, the operator maps who and what is reachable. Using built-in tools — net group /domain,
net user /domain, nltest /dclist: — they enumerate domain accounts, privileged groups and domain
controllers. What it does: queries Active Directory for the roster of users, admins and machines.
Why OilRig uses it: espionage is targeted, so the group needs to know which identities are worth stealing and where
the high-value mailboxes and servers live before it spends a single credential.
vaultcmd.exe T1555.004The hallmark step. vaultcmd.exe is a signed, built-in Windows utility for managing Credential Manager. Run as
vaultcmd /list and vaultcmd /listcreds:"Windows Credentials", it enumerates the credentials a user
has already saved — RDP logons, mapped-drive passwords, IIS and service accounts, vaulted secrets. What it does: reads
the local credential store without touching LSASS, without a dumper, and without cracking a single hash.
Why OilRig uses it: it is quiet and it is signed. There is no malware on disk to catch and no memory-access alarm to
trip; the operator simply collects the keys the user left in the drawer and reuses them as that user. This single
step is the one that defines the group's tradecraft.
With credentials in hand, an OilRig implant phones home — and it does so over DNS. What it does: encodes beacon and tasking data inside DNS queries and TXT-record answers, so the traffic leaves on a protocol almost every network permits and few inspect (related application-layer technique T1071.004). Why OilRig uses it: DNS tunnelling is the group's enduring signature — ALMA Communicator, BONDUPDATER, Saitama and others all talk home this way — because it survives egress filtering that would strangle a raw outbound socket.
In a real intrusion these three sit inside a longer chain — macro-document initial access, a scheduled-task or web-shell foothold, lateral movement on the stolen credentials, and slow exfiltration over the same DNS channel. We ran only the credential-centric core, by hand, to isolate the detection question.
The run's hallmark step is the quiet one: reaching into Windows Credential Manager to read what is already stored. THRONE flagged it directly, with the reconnaissance around it and the DNS tradecraft OilRig is known for picked up as lower-severity corroboration.
| Alert | Detection | Engine | Sev | ATT&CK |
|---|---|---|---|---|
| ALR-175454 | Windows Credential Manager Access Via Vaultcmd.EXE | sigma_engine | HIGH | T1555.004 |
| — | Domain-account enumeration | sigma_engine | MED | T1087.002 |
| — | Outbound DNS query / beacon pattern | behavior_engine | LOW | T1572 |
The top row is the one that matters. vaultcmd.exe is the built-in utility for listing what Windows Credential
Manager is holding — the hallmark OilRig credential-harvest step. THRONE matched it the moment the process ran
(ALR-175454, T1555.004). The domain-account enumeration beneath it is the
reconnaissance that frames the theft; the low-severity outbound DNS pattern is the tradecraft OilRig is best known for —
DNS-tunnelled command-and-control (T1572). Below, the three detections in detail.
This is the detection the scenario was built around. The Sigma rule keys on a process-creation event (Sysmon EID 1) where
the image path ends in \vaultcmd.exe and the command line contains a credential-listing switch such as
/list or /listcreds. Because vaultcmd.exe is a legitimate, signed Windows binary, the
rule discriminates on how it is invoked, not whether it ran — mapped to
T1555.004, Credentials from Password Stores: Windows Credential Manager. ONYX took the raw Sigma hit,
correlated it with the parent shell and the domain recon that preceded it, recognised the sequence as the credential-access
objective of an OilRig-style chain, raised it to HIGH, and surfaced it to the top of the
queue as ALR-175454 — all before an analyst looked.
The Sigma logic here matches built-in discovery utilities enumerating domain objects — net group /domain,
net user /domain, net1.exe, nltest /dclist — mapped to
T1087.002, Account Discovery: Domain Account. On its own this is medium-severity, because
administrators run these commands too. ONYX's contribution is context: it read the recon as the setup for the credential
grab that followed and grouped the two into a single incident, rather than leaving two unrelated medium alerts for a human
to connect.
This signal came from the behavioral engine rather than a single Sigma signature: a pattern of outbound DNS lookups with the regularity and structure of a tunnelled channel (T1572, with related application-layer technique T1071.004). A lone DNS query is near-zero signal, which is why it sits at LOW — but in the presence of a confirmed credential read it corroborates the OilRig hypothesis, and ONYX folded it into the same narrative instead of discarding it as noise.
OilRig's craft is quiet. Rather than cracking passwords, it reads the credentials a user has already stored — Windows
Credential Manager, saved logons, vaulted secrets — and walks straight in. That single vaultcmd access is the
whole game, and THRONE caught it directly, the moment the process ran.
THRONE does not leave the analyst grepping logs. It reconstructs each incident's causality from Sysmon's process GUIDs — parent to child, start to end — and renders the lineage on a 2D canvas in the Incidents tab, so the whole story of a detection is one picture instead of a scroll of events.
For this run the lineage is short and damning: the interactive shell on WIN-J50RP1JBGD4 is the parent, the domain recon and the credential-manager read are its children, and Sysmon stamps every node with a ProcessGuid. THRONE stitches them into the tree behind ALR-175454:
Each node carries its real command line, user context and process GUID; the edges are the parent/child relationships Sysmon recorded. That lineage is what lets ONYX group the recon and the credential read into one incident, and what lets an analyst confirm intent in seconds instead of reconstructing it by hand from a flat event log.
Everything in this run was legitimate on its face. No exploit fired, no binary was dropped, no hash was cracked. A signed Windows utility read a local store it is designed to read. That is what makes OilRig hard — and what THRONE is built to catch.
Credential theft from stored secrets defeats a whole class of defences. There is no malware signature to match, because the tool ships with Windows. There is no LSASS memory-access alarm, because the vault is read through the supported API. There is no brute-force pattern, because nothing is cracked. Controls tuned for loud intrusions — EDR memory alerts, anti-malware signatures, authentication-failure spikes — can watch this happen and stay silent.
What remains is behaviour: a signed utility invoked with a credential-listing switch, in a session that just finished enumerating the domain, on a host that then starts making structured DNS queries. No single one of those is damning. Together they are an OilRig fingerprint. THRONE's job — and ONYX's — is to hold those weak signals inside one hypothesis and score the whole, which is why the T1555.004 access landed as a HIGH incident and not three forgettable low alerts.
THRONE detected the credential-manager read directly, in real time, from first principles — the command line of a signed binary, not a malware signature. The quiet step that defines OilRig was the loudest thing in our queue.
Four concrete moves that would have caught — or blunted — this run in a production environment.
vaultcmd.exe with a listing switchInteractive use of vaultcmd /list or /listcreds is rare on servers and endpoints. Treat
command-line process creation for vaultcmd.exe — and its cousins cmdkey /list and
rundll32 keymgr.dll — as a high-value signal rather than background noise, mapped to
T1555.004.
The individual steps are weak; the sequence is strong. Group domain recon, credential-store access and anomalous DNS into a single incident so a reviewer sees the OilRig shape instead of three unrelated low alerts. That correlation is the work ONYX does automatically here.
DNS tunnelling (T1572 / T1071.004) is OilRig's enduring channel. Baseline normal DNS, flag high-entropy or high-volume TXT lookups, and route DNS through a resolver that logs — so the beacon has somewhere to show up.
Stored credentials are the target. Minimise saved RDP and service credentials on shared and internet-facing hosts, prefer
short-lived and brokered access, and ensure a stolen saved logon cannot be replayed far — so that even a successful
vaultcmd read yields little worth having.