Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Also known as: HOLMIUM, Elfin, Peach Sandstorm, APT 33, MAGNALLIUM, Refined Kitten, COBALT TRINITY, G0064, ATK35, TA451, BLEAK ION, tracked as, the United States, ALFASHELL

Description

APT33 is a suspected Iranian threat group that has carried out operations since at least 2013. The group has targeted organizations across multiple industries in the United States, Saudi Arabia, and South Korea, with a particular interest in the aviation and energy sectors.(Citation: FireEye APT33 Sept 2017)(Citation: FireEye APT33 Webinar Sept 2017)

Goals & Targeting

Targeted Sectors

Energy
Aerospace
Defense
Government
Aviation
Financial services
Telecommunications
Oil gas
Transportation
Non profit
Healthcare
Education
Manufacturing
Media

Targeted Countries / Regions

SA
IR
US
KR
IL
CN
AE

AI Analysis

· 1 week ago

Executive Summary

APT33 (HOLMIUM, Elfin, Peach Sandstorm) is a suspected Iranian state-sponsored cyber-espionage group targeting sectors like aviation and energy in countries such as the U.S., Saudi Arabia, and South Korea since at least 2013. The group employs various TTPs including spear-phishing, tools like NanoCore and POWERTON, and techniques such as web protocol exploitation.

Goals & Targeting

APT33 targets critical infrastructure sectors such as aviation and energy for intelligence gathering likely linked to geopolitical interests. Their focus includes the U.S., Saudi Arabia, and South Korea, suggesting strategic alignment with potential state-level objectives

Enhanced Description

APT33 is a high-sophistication cyber threat group believed to be linked to Iran. Their primary campaign activities have focused on stealing sensitive information from critical infrastructure sectors. The grpup has demonstrated adaptability through the use of a variety of tools and techniques, including custom malware development and persistent lateral movement within networks. They operate with a clear targeting strategy, focusing on specific industries and geographies that align with strategic espionage goals.

Key Capabilities

  • Spear-phishing campaigns
  • Custom malware development (NanoCore, POWERTON)
  • Lateral movement within networks
  • Persistence mechanisms

MITRE ATT&CK Tactics

Initial Access
Execution
Credential Access
Defense Evasion

ATT&CK Techniques

T1053.005
T1560.001
T1132.001
T1003.004
T1573.001
T1204.002
T1588.002
T1566.002

Software / Tooling

StoneDrill
POWERTON
DEADWOOD
Netwire
NanoCore

Campaigns & Victims

APT33 has conducted multiple campaigns since at least 2013, focusing on stealing sensitive information from critical sectors. Campaigns have involved spear-phishing with malicious links and attachments targeting employees in the aviation and energy industries.

IOC Patterns

  • Spear-phishing emails with malicious attachments
  • Scheduled task creation for persistence
  • Use of custom malware families like POWERTON

Recommended Actions

  • Implement network monitoring for known APT33 TTPs
  • Conduct regular user training on spear-phishing attacks
  • Enhance segmentation and micro-segmentation in critical systems

Suggested Tags

APT
espionage
critical-infrastructure

Confidence Assessment

High confidence in APT33's operational tactics and targeted sectors based on multiple reports. Limited specifics on exact campaigns or toolsets used beyond known TTPs and tools.

ATT&CK Techniques

Credential Access
12 techniques
Execution
9 techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

MD5 Hash 15 Domain 5

References

  1. FireEye APT33 Webinar Sept 2017 — Davis, S. and Carr, N. (2017, September 21). APT33: New Insights into Iranian Cyber Espionage Group. Retrieved February 15, 2018.
  2. Microsoft Threat Actor Naming July 2023 — Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.
  3. Microsoft Holmium June 2020 — Microsoft Threat Protection Intelligence Team. (2020, June 18). Inside Microsoft Threat Protection: Mapping attack chains from cloud to endpoint. Retrieved June 22, 2020.
  4. FireEye APT33 Sept 2017 — O'Leary, J., et al. (2017, September 20). Insights into Iranian Cyber Espionage: APT33 Targets Aerospace and Energy Sectors and has Ties to Destructive Malware. Retrieved February 15, 2018.
  5. Symantec Elfin Mar 2019 — Security Response attack Investigation Team. (2019, March 27). Elfin: Relentless Espionage Group Targets Multiple Organizations in Saudi Arabia and U.S.. Retrieved April 10, 2019.
  6. apt.etda.or.th — Cited by web research for: the United States
  7. attack.mitre.org — Cited by web research for: T1547
  8. attack.mitre.org — Cited by web research for: T1055
  9. www.huntress.com — Cited by web research for: DROPSHOT
  10. cloud.google.com — Cited by web research for: ALFA TEaM Shell
  11. www.crowdstrike.com — Cited by web research for: GlassWorm

Intel Summary

53

Techniques

52

Tools

0

Campaigns

40

IOCs

0

Observed Data

12

Tactics

Tags

APT
espionage
critical-infrastructure

Details

MITRE ID
G0064
Type
Unknown
Primary Motivation
Espionage
Country of Origin
I
Confidence
90%
Added
Jul 22, 2026
STIX ID
intrusion-set--fbd29c89-18ba-4c2d-b792-51c0adee049f
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.