Security expert Marco Ramilli published the findings of a quick analysis of the webmask project standing behind the DNS attacks implemented by APT34 (aka OilRig and HelixKitten) The group conducts operations primarily in the Middle East, targeting financial, government, energy, chemical, telecommunications and other industries. The use of infrastructure tied to Iranian operations, timing and alignment with the national interests of Iran also lead FireEye to assess that APT 34 acts on behalf of the Iranian government. The leaked source code shows three main folders: webmask, poisonfrog and Webshells_and_Panel.”]
Source: https://securityaffairs.co/wordpress/84370/apt/iran-apt34-webmask-project.html

