Also known as: HOLMIUM, Elfin, Peach Sandstorm, APT 33, MAGNALLIUM, Refined Kitten, COBALT TRINITY, G0064, ATK35, TA451, BLEAK ION, tracked as, the United States, ALFASHELL
APT33 is a suspected Iranian threat group that has carried out operations since at least 2013. The group has targeted organizations across multiple industries in the United States, Saudi Arabia, and South Korea, with a particular interest in the aviation and energy sectors.(Citation: FireEye APT33 Sept 2017)(Citation: FireEye APT33 Webinar Sept 2017)
Targeted Sectors
Targeted Countries / Regions
Executive Summary
APT33 (HOLMIUM, Elfin, Peach Sandstorm) is a suspected Iranian state-sponsored cyber-espionage group targeting sectors like aviation and energy in countries such as the U.S., Saudi Arabia, and South Korea since at least 2013. The group employs various TTPs including spear-phishing, tools like NanoCore and POWERTON, and techniques such as web protocol exploitation.
Goals & Targeting
APT33 targets critical infrastructure sectors such as aviation and energy for intelligence gathering likely linked to geopolitical interests. Their focus includes the U.S., Saudi Arabia, and South Korea, suggesting strategic alignment with potential state-level objectives
Enhanced Description
APT33 is a high-sophistication cyber threat group believed to be linked to Iran. Their primary campaign activities have focused on stealing sensitive information from critical infrastructure sectors. The grpup has demonstrated adaptability through the use of a variety of tools and techniques, including custom malware development and persistent lateral movement within networks. They operate with a clear targeting strategy, focusing on specific industries and geographies that align with strategic espionage goals.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
APT33 has conducted multiple campaigns since at least 2013, focusing on stealing sensitive information from critical sectors. Campaigns have involved spear-phishing with malicious links and attachments targeting employees in the aviation and energy industries.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in APT33's operational tactics and targeted sectors based on multiple reports. Limited specifics on exact campaigns or toolsets used beyond known TTPs and tools.
No campaigns linked yet.
No observed data linked yet.
53
Techniques
52
Tools
0
Campaigns
40
IOCs
0
Observed Data
12
Tactics