APT33
MITRE ATT&CK: G0064 View on attack.mitre.org
Aliases: HOLMIUM, Elfin, Peach Sandstorm, APT 33, MAGNALLIUM, Refined Kitten, COBALT TRINITY, ATK35, TA451, APT33
- First seen
- 2013-01-01 00:00:00
- Origin
- IR
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- Espionage
- Related IoCs
- 29 (10 malicious)
- Last IoC activity
- 2026-09-02 00:39:47
- Profile updated
- 2026-07-07 12:33:46
Targeted industries: defense-and-aerospace energy-and-utilities transportation-and-logistics
Targeted regions: country_code:us country_code:sa country_code:kr
Context
APT33 is a suspected Iranian threat group that has carried out operations since at least 2013. The group has targeted organizations across multiple industries in the United States, Saudi Arabia, and South Korea, with a particular interest in the aviation and energy sectors.
Recent IoC activity
10 malicious indicators in Maltiverse are attributed to APT33 (G0064). The 10 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | mynetwork.ddns.net | 2026-09-03 | 3 |
| hostname | mypsh.ddns.net | 2026-09-02 | 2 |
| hostname | mywinnetwork.ddns.net | 2026-09-02 | 4 |
| hostname | manage-shope.com | 2026-04-15 | 2 |
| hostname | microsoftupdated.com | 2026-03-04 | 3 |
| hostname | saharapcc.ga | 2026-01-22 | 1 |
| hostname | aramcojobs.ga | 2026-01-22 | 2 |
| hostname | dyn-corp.ga | 2026-01-22 | 1 |
| hostname | btcgenerate.cf | 2026-01-22 | 1 |
| hostname | mynetwork.cf | 2026-01-22 | 2 |
Detection coverage
- 20 YARA rules
- 739 Sigma rules
Malware & tools used
- Credentials In Files (attack-pattern)
- Cached Domain Credentials (attack-pattern)
- Archive via Utility (attack-pattern)
- Credentials from Web Browsers (attack-pattern)
- Group Policy Preferences (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- LSASS Memory (attack-pattern)
- Spearphishing Link (attack-pattern)
- Password Spraying (attack-pattern)
- LSA Secrets (attack-pattern)
- Scheduled Task (attack-pattern)
- Credentials from Password Stores (attack-pattern)
- Windows Management Instrumentation Event Subscription (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Exfiltration Over Unencrypted Non-C2 Protocol (attack-pattern)
- Tool (attack-pattern)
- Network Sniffing (attack-pattern)
- Web Protocols (attack-pattern)
- PowerShell (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Valid Accounts (attack-pattern)
- Symmetric Cryptography (attack-pattern)
- Visual Basic (attack-pattern)
- Standard Encoding (attack-pattern)
Reports & references
- cloud.google.com — Updated Cyber Threat Actor Naming System (report)
- Mandiant — Apt33 Insights Into Iranian Cyber Espionage (report)
- Trend Micro — More Than A Dozen Obfuscated Apt33 Botnets Used For Extreme Narrow Targeting (report)
- brighttalk.com — 275683 (report)
- Broadcom/Symantec — Elfin Apt33 Espionage (report)
- secureworks.com — Cobalt Trinity (report)
- MITRE ATT&CK — G0064 (report)
- threatconnect.com — Research Roundup Activity On Previously Identified Apt33 Domains (report)
- cfr.org — Apt 33 (report)
- dragos.com — 2017 Review Industrial Control System Threats (report)
- dragos.com — Adversaries (report)
- Microsoft — Peach Sandstorm Password Spray Campaigns Enable Intelligence Collection At High Value Targets (report)
- raw.githubusercontent.com — Microsoftmapping (report)
- Microsoft — Microsoft Threat Actor Naming (report)
- Microsoft — Inside Microsoft Threat Protection Mapping Attack Chains From Cloud To Endpoint (report)
- Broadcom/Symantec — Elfin Apt33 Espionage (report)
External references
- mitre-attack — G0064
- APT33
- HOLMIUM
- Peach Sandstorm
- Elfin
- FireEye APT33 Webinar Sept 2017
- Microsoft Threat Actor Naming July 2023
- Microsoft Holmium June 2020
- FireEye APT33 Sept 2017
- Symantec Elfin Mar 2019
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy