APT34

☆ pin
MITRE G0067Also known as TA402, OilRig, Hazel Sandstorm, Evasive Serpens
Reports
3
First seen
May 1, 2026
Last seen
Jul 21, 2026
Motivation
Espionage

Targeting

Top ATT&CK techniques

T1566 Phishing ×3T1005 Data from Local System ×2T1133 External Remote Services ×2T1110 Brute Force ×2T1570 Lateral Tool Transfer ×2T1041 Exfiltration Over C2 Channel ×2T1003 OS Credential Dumping ×2T1078 Valid Accounts ×2T1021.001 Remote Desktop Protocol ×1T1059.001 Command and Scripting Interpreter: PowerShell ×1T1087 Account Discovery ×1T1021.006 Remote Services: Windows Remote Management ×1

Indicators

domain ×2

Indicator values are available on Pro and via the API.

Associated CVEs

Recent reports

This page shows data on a 7-day delay. Free accounts get the full delayed feed; real-time reports, indicators, and the API start at $29/mo.