OilRig Exploits Windows Kernel Flaw in Espionage Campaign Targeting UAE and Gulf
As part of a cyber espionage campaign aimed at the United Arab Emirates and the wider Gulf area, the Iranian threat actor known as OilRig has been seen taking use of a privilege escalation vulnerability affecting the Windows Kernel that has since been patched.
Researchers Mohamed Fahmy, Bahaa Yamany, Ahmed Kamal, and Nick Dai of Trend Micro said in an analysis released on Friday that the group uses sophisticated tactics, such as the deployment of a backdoor that uses Microsoft Exchange servers to steal credentials and the exploitation of vulnerabilities like CVE-2024-30088 for privilege escalation.
Under the alias Earth Simnavaz—also known as APT34, Crambus, Cobalt Gypsy, GreenBug, Hazel Sandstorm (formerly EUROPIUM), and Helix Kitten—the cybersecurity firm is keeping tabs on the th...

