SOCFRAME / THRONE Journal
All reports

Scenario 05 · Espionage · Iran-nexus

Harvesting credentials in the dark.
Lit up.

OilRig — Helix Kitten, APT34 — is an Iran-nexus espionage crew whose signature is patience, not force: don't crack passwords, read the ones already stored on the box and walk in wearing them. We ran a focused, non-destructive slice of that tradecraft on a live Windows victim, and THRONE lit up the credential grab the instant vaultcmd touched the vault — with the reconnaissance that framed it and the DNS-tunnel C2 pattern the group is known for caught alongside.

Adversary
OilRig · APT34
Attribution
Iran · MOIS (G0049)
Signature
Stored-credential harvest
Result
Detected
Executive summary

Iran's quietest espionage crew, caught reading the vault

OilRig (Helix Kitten / APT34, MITRE G0049) is an Iran-nexus espionage actor best known for low-noise credential theft and DNS-tunnelled command-and-control. In this scenario we hand-executed a focused, non-destructive slice of that tradecraft on a Windows victim and measured exactly what THRONE saw.

The run's hallmark step is deliberately quiet. Instead of dumping LSASS or cracking hashes, the operator reaches into Windows Credential Manager with the built-in vaultcmd.exe utility and reads the credentials a user has already saved. THRONE flagged that access directly and in real time as ALR-175454 — Windows Credential Manager Access Via Vaultcmd.EXE, mapped to T1555.004 — and scored it HIGH. The domain-account reconnaissance that framed the theft (T1087.002) and the outbound DNS beacon pattern OilRig is famous for (T1572) were picked up as corroborating, lower-severity signals.

1
Windows victim
3
Correlated detections
0
Passwords cracked
1
Credential vault read

The headline is the smallness of the thing THRONE had to catch. No exploit, no malware binary, no password spray — just one signed, built-in Windows utility doing exactly what it is designed to do, in a context that made it hostile. That is the whole OilRig game, and it is precisely the kind of signal that slips past controls tuned for noisier intrusions.

The adversary

OilRig — Helix Kitten, APT34

Tracked by MITRE as G0049 and by vendors as Helix Kitten, Cobalt Gypsy, Earth Simnavaz, Hazel Sandstorm, EUROPIUM and Crambus, OilRig is an Iran-nexus espionage group active since at least 2014 and widely assessed to operate on behalf of Iran's Ministry of Intelligence and Security (MOIS).

Who they target

OilRig's operations concentrate on the Middle East, with a long record against government ministries, financial services, energy and chemical firms, telecommunications and critical infrastructure. Their objective is classic state espionage — durable access, credential collection, and the quiet exfiltration of information over long dwell times, rather than destruction or extortion. They are an intelligence service with a keyboard, not a smash-and-grab crew.

What made them notorious

In 2019 a leak on Telegram under the banner "Lab Dookhtegan" dumped a slice of OilRig's toolkit and victim data in public — a rare exposure of a nation-state kit, web shells and DNS-tunnelling backdoors included. Over the years the group has fielded a deep custom arsenal: the Helminth first-stage backdoor delivered through macro-laden Office documents; the ALMA Communicator and BONDUPDATER DNS backdoors; QUADAGENT (PowerShell); ISMAgent; the TwoFace and RGDoor IIS web shells; RDAT, which smuggles data inside email using steganography; and more recently Saitama, Marlin and Menorah. Many of them share one family trait: they phone home over DNS.

Signature tradecraft

Three habits define OilRig on the ATT&CK matrix. First, DNS-tunnelled command-and-control (T1071.004 / T1572): encoding beacon traffic inside DNS queries and TXT answers so it rides out on a protocol almost nobody blocks. Second, credential access from stored secrets (T1555): rather than always cracking hashes, they harvest what is already saved — browser credentials, saved logons, and the Windows Credential Manager vault (T1555.004). Third, living off the land: signed, built-in utilities and LOLBins (certutil, bitsadmin, scheduled tasks, vaultcmd) so their footprint blends into normal administration. They are also fluent in trusted-relationship and internal spearphishing (T1199, T1534), pivoting from one compromised mailbox to phish the victim's trusted contacts.

Why this crew is worth emulating

OilRig is the archetype of the quiet intruder. Nothing in their playbook has to be loud: a macro, a signed binary, a DNS query. Detecting them is less about catching malware and more about catching ordinary tools used with hostile intent — exactly the discrimination THRONE is built to make.

Setup & methodology

A focused, non-destructive run — by hand

This scenario is deliberately narrow, and honest about it. Rather than an autonomous operation, we hand-executed a focused, non-destructive slice of OilRig's credential-harvesting tradecraft directly on the Windows victim — just enough real activity to throw genuine telemetry and test whether THRONE catches the one step that matters.

The victim is WIN-J50RP1JBGD4 (204.168.192.149 · internal 10.0.0.5), a Windows host instrumented with Sysmon and streaming its event log to the THRONE cloud tenant. We executed the steps directly at an interactive shell — no C2 framework, no implant, and no credential actually exfiltrated — so every signal THRONE raised is attributable to a known, bounded action. This is a lab environment and nothing is hidden: the real IPs, the real hostname and the real alert ID are shown exactly as captured.

From a process on the box to a scored incident

Once a process runs on the victim, the path to a triaged alert is automatic and takes seconds:

Operator action on WIN-J50RP1JBGD4 → Sysmon event (process-create, EID 1)
→ tenant-tagged syslog → THRONE :1514 → Kafka → ch_pump parse → ClickHouse
→ Sigma sweep (3,148 rules / 389 ATT&CK techniques) + behavioral engine → alert
→ ONYX auto-triage & grouping → incident → causality tree (parent/child process GUIDs)

Sysmon records each process creation with its full command line and the parent/child process GUIDs. The host tags every line with its tenant before shipping it to THRONE's syslog listener on :1514; Kafka buffers it; ch_pump parses and normalises it into ClickHouse; the Sigma corpus and the behavioral engine evaluate it; and ONYX, THRONE's AI SOC analyst, triages the resulting alert into a scored, grouped incident with a causality tree waiting — before any human looks at it.

Scope, stated plainly

This was a single-host, hand-run slice — not a full intrusion. We did not establish initial access, deploy a backdoor, or move laterally. The value here is narrow and specific: can THRONE tell a signed, built-in Windows utility reading the credential vault apart from the same utility used for legitimate administration? It can.

The kill chain

The slice we ran, phase by phase

Three tactics, executed in the order a real OilRig operator would: scope the environment, take the stored credentials, and signal home over DNS. Each step generated genuine Windows telemetry that THRONE evaluated.

Detected
Discoverynet · nltest
Detected
Credential accessvaultcmd /list
Detected
Command & controlDNS beacon

1 · Discovery — domain-account enumeration T1087.002

Before stealing anything, the operator maps who and what is reachable. Using built-in tools — net group /domain, net user /domain, nltest /dclist: — they enumerate domain accounts, privileged groups and domain controllers. What it does: queries Active Directory for the roster of users, admins and machines. Why OilRig uses it: espionage is targeted, so the group needs to know which identities are worth stealing and where the high-value mailboxes and servers live before it spends a single credential.

2 · Credential access — Windows Credential Manager via vaultcmd.exe T1555.004

The hallmark step. vaultcmd.exe is a signed, built-in Windows utility for managing Credential Manager. Run as vaultcmd /list and vaultcmd /listcreds:"Windows Credentials", it enumerates the credentials a user has already saved — RDP logons, mapped-drive passwords, IIS and service accounts, vaulted secrets. What it does: reads the local credential store without touching LSASS, without a dumper, and without cracking a single hash. Why OilRig uses it: it is quiet and it is signed. There is no malware on disk to catch and no memory-access alarm to trip; the operator simply collects the keys the user left in the drawer and reuses them as that user. This single step is the one that defines the group's tradecraft.

3 · Command & control — DNS-tunnelled beacon T1572

With credentials in hand, an OilRig implant phones home — and it does so over DNS. What it does: encodes beacon and tasking data inside DNS queries and TXT-record answers, so the traffic leaves on a protocol almost every network permits and few inspect (related application-layer technique T1071.004). Why OilRig uses it: DNS tunnelling is the group's enduring signature — ALMA Communicator, BONDUPDATER, Saitama and others all talk home this way — because it survives egress filtering that would strangle a raw outbound socket.

In a real intrusion these three sit inside a longer chain — macro-document initial access, a scheduled-task or web-shell foothold, lateral movement on the stolen credentials, and slow exfiltration over the same DNS channel. We ran only the credential-centric core, by hand, to isolate the detection question.

What THRONE detected

Every signal, and the one that matters

The run's hallmark step is the quiet one: reaching into Windows Credential Manager to read what is already stored. THRONE flagged it directly, with the reconnaissance around it and the DNS tradecraft OilRig is known for picked up as lower-severity corroboration.

AlertDetectionEngineSevATT&CK
ALR-175454Windows Credential Manager Access Via Vaultcmd.EXEsigma_engineHIGHT1555.004
—Domain-account enumerationsigma_engineMEDT1087.002
—Outbound DNS query / beacon patternbehavior_engineLOWT1572

The top row is the one that matters. vaultcmd.exe is the built-in utility for listing what Windows Credential Manager is holding — the hallmark OilRig credential-harvest step. THRONE matched it the moment the process ran (ALR-175454, T1555.004). The domain-account enumeration beneath it is the reconnaissance that frames the theft; the low-severity outbound DNS pattern is the tradecraft OilRig is best known for — DNS-tunnelled command-and-control (T1572). Below, the three detections in detail.

ALR-175454 — Windows Credential Manager Access Via Vaultcmd.EXE

This is the detection the scenario was built around. The Sigma rule keys on a process-creation event (Sysmon EID 1) where the image path ends in \vaultcmd.exe and the command line contains a credential-listing switch such as /list or /listcreds. Because vaultcmd.exe is a legitimate, signed Windows binary, the rule discriminates on how it is invoked, not whether it ran — mapped to T1555.004, Credentials from Password Stores: Windows Credential Manager. ONYX took the raw Sigma hit, correlated it with the parent shell and the domain recon that preceded it, recognised the sequence as the credential-access objective of an OilRig-style chain, raised it to HIGH, and surfaced it to the top of the queue as ALR-175454 — all before an analyst looked.

Domain-account enumeration

The Sigma logic here matches built-in discovery utilities enumerating domain objects — net group /domain, net user /domain, net1.exe, nltest /dclist — mapped to T1087.002, Account Discovery: Domain Account. On its own this is medium-severity, because administrators run these commands too. ONYX's contribution is context: it read the recon as the setup for the credential grab that followed and grouped the two into a single incident, rather than leaving two unrelated medium alerts for a human to connect.

Outbound DNS query / beacon pattern

This signal came from the behavioral engine rather than a single Sigma signature: a pattern of outbound DNS lookups with the regularity and structure of a tunnelled channel (T1572, with related application-layer technique T1071.004). A lone DNS query is near-zero signal, which is why it sits at LOW — but in the presence of a confirmed credential read it corroborates the OilRig hypothesis, and ONYX folded it into the same narrative instead of discarding it as noise.

The signature move

OilRig's craft is quiet. Rather than cracking passwords, it reads the credentials a user has already stored — Windows Credential Manager, saved logons, vaulted secrets — and walks straight in. That single vaultcmd access is the whole game, and THRONE caught it directly, the moment the process ran.

The evidence

Rebuilt as causality, not a log line

THRONE does not leave the analyst grepping logs. It reconstructs each incident's causality from Sysmon's process GUIDs — parent to child, start to end — and renders the lineage on a 2D canvas in the Incidents tab, so the whole story of a detection is one picture instead of a scroll of events.

For this run the lineage is short and damning: the interactive shell on WIN-J50RP1JBGD4 is the parent, the domain recon and the credential-manager read are its children, and Sysmon stamps every node with a ProcessGuid. THRONE stitches them into the tree behind ALR-175454:

Parent
Interactive shellcmd.exe / powershell.exe
Child · recon
net.exe · nltest.exeT1087.002
Flagged child
vaultcmd.exe /listALR-175454 · T1555.004

Each node carries its real command line, user context and process GUID; the edges are the parent/child relationships Sysmon recorded. That lineage is what lets ONYX group the recon and the credential read into one incident, and what lets an analyst confirm intent in seconds instead of reconstructing it by hand from a flat event log.

Why it matters

The hardest adversary to see is the quietest one

Everything in this run was legitimate on its face. No exploit fired, no binary was dropped, no hash was cracked. A signed Windows utility read a local store it is designed to read. That is what makes OilRig hard — and what THRONE is built to catch.

Credential theft from stored secrets defeats a whole class of defences. There is no malware signature to match, because the tool ships with Windows. There is no LSASS memory-access alarm, because the vault is read through the supported API. There is no brute-force pattern, because nothing is cracked. Controls tuned for loud intrusions — EDR memory alerts, anti-malware signatures, authentication-failure spikes — can watch this happen and stay silent.

What remains is behaviour: a signed utility invoked with a credential-listing switch, in a session that just finished enumerating the domain, on a host that then starts making structured DNS queries. No single one of those is damning. Together they are an OilRig fingerprint. THRONE's job — and ONYX's — is to hold those weak signals inside one hypothesis and score the whole, which is why the T1555.004 access landed as a HIGH incident and not three forgettable low alerts.

The finding

THRONE detected the credential-manager read directly, in real time, from first principles — the command line of a signed binary, not a malware signature. The quiet step that defines OilRig was the loudest thing in our queue.

Defensive takeaways

What to do about it

Four concrete moves that would have caught — or blunted — this run in a production environment.

1 · Alert on vaultcmd.exe with a listing switch

Interactive use of vaultcmd /list or /listcreds is rare on servers and endpoints. Treat command-line process creation for vaultcmd.exe — and its cousins cmdkey /list and rundll32 keymgr.dll — as a high-value signal rather than background noise, mapped to T1555.004.

2 · Correlate, don't isolate

The individual steps are weak; the sequence is strong. Group domain recon, credential-store access and anomalous DNS into a single incident so a reviewer sees the OilRig shape instead of three unrelated low alerts. That correlation is the work ONYX does automatically here.

3 · Inspect and baseline DNS egress

DNS tunnelling (T1572 / T1071.004) is OilRig's enduring channel. Baseline normal DNS, flag high-entropy or high-volume TXT lookups, and route DNS through a resolver that logs — so the beacon has somewhere to show up.

4 · Reduce what is in the vault to steal

Stored credentials are the target. Minimise saved RDP and service credentials on shared and internet-facing hosts, prefer short-lived and brokered access, and ensure a stolen saved logon cannot be replayed far — so that even a successful vaultcmd read yields little worth having.