Helminth is a Windows backdoor associated with OilRig, also known as APT34 and Helix Kitten, an Iranian-linked cyberespionage group. It provides an initial foothold on compromised systems, allowing operators to execute commands, collect information, and exfiltrate data. Documented deployments include attacks against Saudi Arabian financial and technology organizations and phishing campaigns targeting government personnel. Helminth exists in two principal forms: a script-based implementation using VBScript and PowerShell, and a standalone Windows executable. The executable variant additionally captures keystrokes and clipboard contents for exfiltration.
Helminth is delivered through malicious Excel macros in Clayslide documents and through executable installers, including the HerHer dropper. Distribution campaigns have used spear-phishing emails, technical-support and job-offer lures, and fake university-themed websites offering downloadable documents. Its command-and-control channels use HTTP and DNS tunneling to receive tasking and return collected data. The script implementation can download and execute batch scripts and upload their output; its DNS component reconstructs scripts from DNS responses. HTTP communications can carry Base64-encoded data in the Cookie header, and some variants encrypt HTTP traffic with RC4. DNS communications encode outbound data as hexadecimal without encryption. Helminth performs process discovery using the Windows Tasklist utility and maintains persistence through scheduled tasks or startup shortcuts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The fileless attack was delivered via Microsoft Word documents that exploited a former zero-day vulnerability in Word, CVE-2017-0199, to install a fileless attack variant of the Helminth Trojan agent. Microsoft released the patch for the vulnerability on April 11, but many organizations have not yet deployed the update. | The fileless attack was delivered via Microsoft Word documents that exploited a former zero-day vulnerability in Word, CVE-2017-0199, to install a fileless attack variant of the Helminth Trojan agent.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The primary tool used in these attacks was the Helminth backdoor, delivered through Excel macros or as standalone executables.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
The content repeatedly describes threat actors and malware using PowerShell to execute payloads, run commands, download additional malware, perform lateral movement, evade defenses, and execute scripts in memory. | Examples include: 'APT28 downloads and executes PowerShell scripts and performs PowerShell commands'; 'APT3 has used PowerShell on victim systems to download and run payloads after exploitation'; 'TA505 has used PowerShell to download and execute malware and reconnaissance scripts.'
Numerous entries state malware can create a remote shell or reverse shell, for example 4H RAT, BLACKCOFFEE, DarkComet, PlugX, QuasarRAT, and others. | The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
We speculate that the executable variant involves threat actors socially engineering the victim into running the payload, rather than installing the payload as the result of successful exploitation of a vulnerability. | This is an attempt to trick the user into running the embedded macro to install the Trojan, which does not require any vulnerability exploitation.
The content repeatedly describes malware and threat actors that can "download files from C2," "download additional payloads," "upload and download files," "retrieve payloads from the C2 server," and "copy files to remote machines."
41 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
55 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom backdoor used in cyberespionage operations; part of OilRig’s modular tooling for persistence and remote access.
Backdoor malware used by OilRig for persistence and remote access.
Backdoor used in OilRig's targeted phishing operations. Delivered through malicious Excel macros or standalone executables and subsequently modified to improve antivirus evasion.
A fileless Trojan/backdoor used in the OilRig-linked campaign against Israeli organizations. It is installed via malicious Word documents exploiting CVE-2017-0199, uses PowerShell and VBS components, establishes persistence via scheduled tasks, communicates with C2 over HTTP and DNS, downloads batch scripts for execution, uploads results, and clears traces.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.