Refined Kitten
Named by CrowdStrikeSuspected state sponsor: Islamic Republic of IranRefined Kitten is CrowdStrike's designation for the Iranian state-sponsored threat actor known as APT33. The group has been active since at least 2013, focusing on cyber espionage against aerospace, energy, and defense organizations across the United States, Saudi Arabia, and South Korea. Operations attributed to this name share the same tradecraft as the broader APT33 cluster: spear phishing with recruitment-themed lures, password spraying, and custom backdoor deployment. The cluster is also tracked as Peach Sandstorm (Microsoft), Elfin (Symantec), and HOLMIUM (Microsoft legacy).
Targeted Regions
Saudi ArabiaSaudi Arabia
Jan 2013 ~ Dec 2019
Jan 2013 ~ Dec 2019
Jan 2013 ~ Dec 2019
Jan 2013 ~ Dec 2019
Jan 2013 ~ Dec 2019
Jan 2013 ~ Dec 2019
Jan 2013 ~ Dec 2019
Jan 2013 ~ Dec 2019
Jan 2013 ~ Dec 2019
Jan 2013 ~ Dec 2019
Jan 2013 ~ Dec 2019
Jan 2013 ~ Dec 2019
United Arab EmiratesUnited Arab Emirates
Jan 2013 ~ Dec 2019
Jan 2013 ~ Dec 2019
Jan 2013 ~ Dec 2019
Jan 2013 ~ Dec 2019
Jan 2013 ~ Dec 2019
Jan 2013 ~ Dec 2019
Jan 2013 ~ Dec 2019
Jan 2013 ~ Dec 2019
Jan 2013 ~ Dec 2019
Jan 2013 ~ Dec 2019
Jan 2013 ~ Dec 2019
Jan 2013 ~ Dec 2019
United StatesUnited States
Jan 2013 ~ Dec 2019
Jan 2013 ~ Dec 2019
Jan 2013 ~ Dec 2019
Jan 2013 ~ Dec 2019
Jan 2013 ~ Dec 2019
Jan 2013 ~ Dec 2019
Jan 2013 ~ Dec 2019
Jan 2013 ~ Dec 2019
Jan 2013 ~ Dec 2019
Jan 2013 ~ Dec 2019
Jan 2013 ~ Dec 2019
Jan 2013 ~ Dec 2019
Targeted Sectors
Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.