TA451
Named by ProofpointSuspected state sponsor: Islamic Republic of IranTA451 is Proofpoint's tracking designation for the Iranian state-sponsored threat cluster widely known as APT33 and Elfin, linked to the IRGC and active since at least 2013. The group conducts cyber espionage primarily against aviation, energy, defense, government, and healthcare organizations in Saudi Arabia, South Korea, and the United States, using spear phishing with job-recruitment lures and malicious HTA files for initial access. In documented campaigns, TA451 has targeted US defense contractor personnel and aerospace-sector employees in the UAE using HTA files delivered via targeted business-to-business sales approaches. Proofpoint documented TA451 as active through at least December 2019 in public reporting, though APT33 campaign activity has continued under other vendor designations. The group is separately tracked as Peach Sandstorm (Microsoft), Refined Kitten (CrowdStrike), and Magnallium (Dragos), and is widely suspected in connection with the Shamoon wiper attacks against Saudi Aramco.
Targeted Regions
United StatesUnited States
Jan 2021 ~ Mar 2021
Recent Indexed Reports
Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.