OilRig Cyber Attack: Exposing a Pervasive Threat Actor and the PowerExchange Backdoor

– The OilRig threat actor, known to have links with Iran, targeted an undisclosed Middle Eastern government in a campaign that lasted from February to September 2023.
– The campaign saw the theft of files and passwords, with one incident even deploying a PowerShell Backdoor aptly named ‘PowerExchange’.
– Symantec Threat Hunter Team, a part of Broadcom, detailed the attack in a report shared with The Hacker News.

