APT33: Iran's IRGC-Linked Cyber Espionage Group Targets Aviation, Energy, and Defense Across Three Continents
A comprehensive threat profile published by Brandefense sheds light on APT33 — the Iran-nexus espionage group also tracked as Elfin, Holmium, Magnallium, and Refined Kitten — documenting over a decade of targeted intrusions across the United States, Saudi Arabia, and a dozen other countries, with a particular focus on aerospace, petrochemical, and defense sectors.
IRGC Alignment and Strategic Objectives
APT33 has conducted espionage-focused operations since at least 2013, with activities assessed to align with the objectives of Iran's Islamic Revolutionary Guard Corps (IRGC). While intelligence collection remains the group's primary mandate, APT33 has also been linked to destructive operations involving the Shamoon wiper malware — a capability that distinguishes it from purely collection-oriented threat actors. The group's targeting spans fifteen industry sectors and eleven countries, with Saudi Arabia and the United States representing the most consistently targeted nations.
Campaign History: A Decade of Targeted Operations
APT33's operational record reveals a methodical, sector-by-sector approach across distinct campaign phases. Between 2016 and 2017, the group focused on aerospace and petrochemical organizations, distributing spear-phishing emails with malicious attachments — an approach analysts assess was intended to advance Iran's aviation and energy sector intelligence capabilities. During the same period, Saudi Arabian government agencies were targeted through a dual-vector campaign combining phishing with waterhole attacks.
In 2017–2018, APT33 pivoted toward engineering sector targets, exploiting compromised credentials to manipulate victims' email clients and leveraging an open-source tool that abused CVE-2017-11774 to download and execute malware. Credential material was sourced through third-party breaches, credential harvesting scams, and weak password exploitation.
A February 2019 campaign targeted a Saudi Arabian chemical company via a compressed spear-phishing attachment exploiting CVE-2018-20250 — triggering execution of a remote malware download upon opening. From mid-June through October 2019, the group conducted a sustained password-spraying campaign against cloud-hosted infrastructure across multiple industries, with industrial control system vendors among the most heavily targeted. Concurrent phishing campaigns in June 2019 struck U.S. federal government entities and Middle Eastern financial institutions using documents carrying malicious macros. By August 2019, APT33 was manipulating domain names associated with U.S. defense contractors to deliver malware via phishing.
Malware Arsenal
APT33 maintains a layered toolkit combining custom-developed implants with widely available open-source remote access tools:
- TURNEDUP: A custom backdoor supporting file upload/download, system reconnaissance, and reverse shell creation.
- DROPSHOT: A dropper responsible for deploying TURNEDUP and SHAPESHIFT on targeted systems.
- SHAPESHIFT (STONEDRILL): A destructive backdoor capable of downloading additional files and wiping disks, volumes, and files based on configuration.
- POWERTON: A PowerShell-based backdoor first observed in 2018, reflecting the group's investment in living-off-the-land techniques.
Alongside these proprietary tools, APT33 regularly deploys commodity RATs sourced from underground platforms, including Remcos, Quasar, DarkComet, Pupy, NetWeird, PoshC2, and PowerShell Empire — providing operational flexibility and complicating attribution.
Tactics, Techniques, and Procedures
Spear-phishing remains APT33's dominant initial access vector, with emails delivering malicious attachments or links to attacker-controlled infrastructure. In more recent operations, the group has shifted toward credential-based intrusion methods — using stolen or sprayed credentials to access cloud services and email platforms directly, reducing reliance on malware delivery at the perimeter. This evolution toward identity-based access techniques reflects a broader maturation in the group's tradecraft and an awareness of improved endpoint detection capabilities among high-value targets.