APT33

MITRE ATT&CK: G0064 View on attack.mitre.org

Aliases: HOLMIUM, Elfin, Peach Sandstorm, APT 33, MAGNALLIUM, Refined Kitten, COBALT TRINITY, ATK35, TA451, APT33

First seen
2013-01-01 00:00:00
Origin
IR
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
Espionage
Related IoCs
29 (10 malicious)
Last IoC activity
2026-09-02 00:39:47
Profile updated
2026-07-07 12:33:46

Targeted industries: defense-and-aerospace energy-and-utilities transportation-and-logistics

Targeted regions: country_code:us country_code:sa country_code:kr

Context

APT33 is a suspected Iranian threat group that has carried out operations since at least 2013. The group has targeted organizations across multiple industries in the United States, Saudi Arabia, and South Korea, with a particular interest in the aviation and energy sectors.

Recent IoC activity

10 malicious indicators in Maltiverse are attributed to APT33 (G0064). The 10 most recently updated:

TypeIndicatorUpdatedSources
hostname mynetwork.ddns.net 2026-09-03 3
hostname mypsh.ddns.net 2026-09-02 2
hostname mywinnetwork.ddns.net 2026-09-02 4
hostname manage-shope.com 2026-04-15 2
hostname microsoftupdated.com 2026-03-04 3
hostname saharapcc.ga 2026-01-22 1
hostname aramcojobs.ga 2026-01-22 2
hostname dyn-corp.ga 2026-01-22 1
hostname btcgenerate.cf 2026-01-22 1
hostname mynetwork.cf 2026-01-22 2

Detection coverage

  • 20 YARA rules
  • 739 Sigma rules

Malware & tools used

  • Credentials In Files (attack-pattern)
  • Cached Domain Credentials (attack-pattern)
  • Archive via Utility (attack-pattern)
  • Credentials from Web Browsers (attack-pattern)
  • Group Policy Preferences (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • LSASS Memory (attack-pattern)
  • Spearphishing Link (attack-pattern)
  • Password Spraying (attack-pattern)
  • LSA Secrets (attack-pattern)
  • Scheduled Task (attack-pattern)
  • Credentials from Password Stores (attack-pattern)
  • Windows Management Instrumentation Event Subscription (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Exfiltration Over Unencrypted Non-C2 Protocol (attack-pattern)
  • Tool (attack-pattern)
  • Network Sniffing (attack-pattern)
  • Web Protocols (attack-pattern)
  • PowerShell (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Valid Accounts (attack-pattern)
  • Symmetric Cryptography (attack-pattern)
  • Visual Basic (attack-pattern)
  • Standard Encoding (attack-pattern)

Reports & references

  • cloud.google.com — Updated Cyber Threat Actor Naming System (report)
  • Mandiant — Apt33 Insights Into Iranian Cyber Espionage (report)
  • Trend Micro — More Than A Dozen Obfuscated Apt33 Botnets Used For Extreme Narrow Targeting (report)
  • brighttalk.com — 275683 (report)
  • Broadcom/Symantec — Elfin Apt33 Espionage (report)
  • secureworks.com — Cobalt Trinity (report)
  • MITRE ATT&CK — G0064 (report)
  • threatconnect.com — Research Roundup Activity On Previously Identified Apt33 Domains (report)
  • cfr.org — Apt 33 (report)
  • dragos.com — 2017 Review Industrial Control System Threats (report)
  • dragos.com — Adversaries (report)
  • Microsoft — Peach Sandstorm Password Spray Campaigns Enable Intelligence Collection At High Value Targets (report)
  • raw.githubusercontent.com — Microsoftmapping (report)
  • Microsoft — Microsoft Threat Actor Naming (report)
  • Microsoft — Inside Microsoft Threat Protection Mapping Attack Chains From Cloud To Endpoint (report)
  • Broadcom/Symantec — Elfin Apt33 Espionage (report)

External references