APT33
Also known as: HOLMIUM · Elfin · Peach Sandstorm
Overview
APT33 is a suspected Iranian threat group that has carried out operations since at least 2013. The group has targeted organizations across multiple industries in the United States, Saudi Arabia, and South Korea, with a particular interest in the aviation and energy sectors.
Naming & attribution
APT33 is tracked under 4 names across the industry. It uses 31 documented ATT&CK techniques — more than 67% of the 174 groups tracked here. Activity attributed since at least 2013.
| Name | First reported by |
|---|---|
| HOLMIUM | Microsoft Threat Protection Intelligence Team |
| Elfin | Security Response attack Investigation Team |
| Peach Sandstorm | Microsoft |
| APT33 | O'Leary, J., et al |
Distinctive techniques
Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.
-
T1552.006Group Policy Preferences — used by 2 of 174 groups
Closest groups by technique overlap
Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.
- MuddyWater Iran — 22 shared techniques (29% overlap)
- FIN8 — 15 shared techniques (29% overlap)
- Confucius — 11 shared techniques (28% overlap)
- Molerats — 10 shared techniques (27% overlap)
- Inception Russia — 11 shared techniques (26% overlap)
- BRONZE BUTLER China — 14 shared techniques (25% overlap)
Malware families with current indicators
5 families attributed to APT33, carrying 628 indicators currently tracked from abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL. MITRE documents what a group does; this is what its tooling is doing now.
- NanoCore 256 indicators
- NetWire 251 indicators
- pupy 63 indicators
- PoshC2 56 indicators
- TURNEDUP 2 indicators
Browse or copy the indicators by hash, domain, IP or URL, filtered by age from 1 day to 3 years.
Targets
Private sector
Regions
Saudi Arabia · South Korea · United States
Capabilities
- Destructive / data-wiping operations — software: StoneDrill
- Exploitation of public-facing / client applications — ATT&CK T1203
- Custom malware/implant development — ATT&CK: 7 attributed custom malware families
- Documented tooling: STONEDRILL wiper, variants of TURNEDUP malware — MISP galaxy (meta.capabilities)
TTPs — 31 techniques across 10 tactics
Resource Development
-
T1588.002Tool
Initial Access
-
T1566.001Spearphishing Attachment -
T1566.002Spearphishing Link
Execution
-
T1053.005Scheduled Task -
T1059.001PowerShell -
T1059.005Visual Basic -
T1203Exploitation for Client Execution -
T1204.001Malicious Link -
T1204.002Malicious File
Persistence
-
T1547.001Registry Run Keys / Startup Folder
Privilege Escalation
Stealth
-
T1027.013Encrypted/Encoded File -
T1078Valid Accounts -
T1078.004Cloud Accounts
Credential Access
-
T1003.001LSASS Memory -
T1003.004LSA Secrets -
T1003.005Cached Domain Credentials -
T1040Network Sniffing -
T1110.003Password Spraying -
T1552.001Credentials In Files -
T1552.006Group Policy Preferences -
T1555Credentials from Password Stores -
T1555.003Credentials from Web Browsers
Collection
-
T1560.001Archive via Utility
Command and Control
-
T1071.001Web Protocols -
T1105Ingress Tool Transfer -
T1132.001Standard Encoding -
T1571Non-Standard Port -
T1573.001Symmetric Cryptography
Exfiltration
Tools & malware (16)
PowerSploit · AutoIt backdoor · PoshC2 · Ruler · Mimikatz · NanoCore · DEADWOOD · StoneDrill · POWERTON · LaZagne · TURNEDUP · NETWIRE · Net · Pupy · Empire · ftp
Reporting (3)
- How Microsoft names threat actors — Microsoft
- Inside Microsoft Threat Protection: Mapping attack chains from cloud to endpoint — Microsoft Threat Protection Intelligence Team
- Elfin: Relentless Espionage Group Targets Multiple Organizations in Saudi Arabia and U.S — Security Response attack Investigation Team