Netskope Threat Labs

OilRig

ATP Sandbox Adv. Heuristics

OilRig is a detection family covering tooling used by the OilRig intrusion set, an Iranian actor known for continuous malware innovation and for unique backdoors built on AutoIt and PowerShell persistence techniques.

First seen
March 2022
Last seen
September 2026
Alert Name
ByteCode-MSIL.Trojan.OilRig
Script-BAT.Trojan.OilRig
Script-PowerShell.Downloader.OilRig
Win32.Trojan.OilRig