APT33

๐Ÿ”ด High
Also known as: APT 33, APT33, ATK35, COBALT TRINITY, Elfin, G0064, HOLMIUM, MAGNALLIUM, Peach Sandstorm, Refined Kitten, TA451

APT33 is a suspected Iranian threat group that has carried out operations since at least 2013. The group has targeted organizations across multiple industries in the United States, Saudi Arabia, and South Korea, with a particular interest in the aviation and energy sectors. FireEye APT33 Sept 2017 FireEye APT33 Webinar Sept 2017

๐ŸŒ Country Iran
โšก Risk Level High
๐ŸŽฏ Incident Type Espionage
๐Ÿงญ ATT&CK G0064
Private sector

Introduction

APT33 is a suspected Iranian threat group that has carried out operations since at least 2013. The group has targeted organizations across multiple industries in the United States, Saudi Arabia, and South Korea, with a particular interest in the aviation and energy sectors. FireEye APT33 Sept 2017 FireEye APT33 Webinar Sept 2017

Activities and Tactics

Targeted Sectors: Private sector

Country of Origin: ๐Ÿ‡ฎ๐Ÿ‡ท Iran

Risk Level: High

Incident Type: Espionage

Suspected Victims: United States, Saudi Arabia, South Korea

Notable Campaigns

Information pending cataloguing.

Tactics, Techniques, and Procedures (TTPs)

ATT&CK technique IDs (denormalized)

Notable Indicators of Compromise (IOCs)

No curated IOCs are currently published for this actor. This section will be updated when stable, attributable indicators are available.

Malware and Tools

  • CyberGate
  • Cyber Eye RAT

MITRE ATT&CK Software

Attribution and Evidence

Country of Origin: Iran Additional attribution information pending cataloguing.

References

[1] mitre-attack [6] FireEye APT33 Webinar Sept 2017 Davis, S. and Carr, N. (2017, September 21). APT33: New Insights into Iranian Cyber Espionage Group. Retrieved February 15, 2018. [7] Microsoft Threat Actor Naming July 2023 Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023. [8] Microsoft Holmium June 2020 Microsoft Threat Protection Intelligence Team. (2020, June 18). Inside Microsoft Threat Protection: Mapping attack chains from cloud to endpoint. Retrieved June 22, 2020. [9] FireEye APT33 Sept 2017 Oโ€™Leary, J., et al. (2017, September 20). Insights into Iranian Cyber Espionage: APT33 Targets Aerospace and Energy Sectors and has Ties to Destructive Malware. Retrieved February 15, 2018. [10] Symantec Elfin Mar 2019 Security Response attack Investigation Team. (2019, March 27). Elfin: Relentless Espionage Group Targets Multiple Organizations in Saudi Arabia and U.S.. Retrieved April 10, 2019.