Analysis critical-infrastructurefinance
APT34 / OilRig / Hazel Sandstorm: Inside Iran's Premier Cyber Espionage Group
APT34 has operated persistently since at least 2014, targeting energy, government, financial, and telecoms sectors across the Middle East and beyond. Known for DNS-based command-and-control, a continuously evolving malware arsenal, and deep operational persistence, the group represents Iran's most capable and consistently active espionage platform. This deep-dive covers APT34's organisational profile, TTPs, malware families, and 2025-2026 activity.