APT33 — APT Profile
APT33 is a suspected Iranian threat group that has carried out operations since at least 2013. The group has targeted organizations across multiple industries in the United States, Saudi Arabia, and South Korea, with a particular interest in the aviation and energy sectors.Also tracked as
HOLMIUM, Elfin, Peach Sandstorm
Tools & malware
- AutoIt backdoor Backdoor
- DEADWOOD Wiper
- Empire Post-Exploitation Framework
- ftp Exfiltration
- LaZagne Credential Harvesting
- Mimikatz Credential Harvesting
- NanoCore Remote Access Trojan
- Net Network Reconnaissance
- NETWIRE Remote Access Trojan
- PoshC2 Post-Exploitation Framework
- PowerSploit Post-Exploitation Framework
- POWERTON Backdoor
- ps1.powerton Backdoor
- Pupy Remote Access Trojan
- Ruler Phishing Framework
- StoneDrill Wiper
- TURNEDUP Backdoor
- win.darkcomet Backdoor
- win.dropshot Backdoor
- win.filerase Backdoor
- win.nanocore Backdoor
- win.netwire Backdoor
- win.poshc2 POS Malware
- win.powerband Backdoor
- win.pupy Backdoor
- win.quasar_rat Remote Access Trojan
- win.remcos Backdoor
- win.shapeshift Backdoor
- win.turnedup Backdoor
Vendor research
- How Microsoft names threat actors Microsoft
- APT33: New Insights into Iranian Cyber Espionage Group FireEye
- Inside Microsoft Threat Protection: Mapping attack chains from cloud to endpoint Microsoft
- Insights into Iranian Cyber Espionage: APT33 Targets Aerospace and Energy Sectors and has Ties to Destructive Malware FireEye
- Elfin: Relentless Espionage Group Targets Multiple Organizations in Saudi Arabia and U.S Symantec