HOLMIUM
Named by MicrosoftSuspected state sponsor: Islamic Republic of IranHOLMIUM is Microsoft's legacy tracking designation for the Iranian threat actor now formally named Peach Sandstorm, which is widely known across the industry as APT33. The group has been active since at least 2013 and conducts espionage operations primarily targeting the aerospace, defense, satellite, energy, and pharmaceutical sectors. Microsoft retired the HOLMIUM name as part of an updated threat actor naming taxonomy. Under both names, the same cluster is responsible for large-scale password spray campaigns, spear phishing with malicious .hta files, and post-compromise use of tools such as AzureHound and the TICKLER backdoor.
Targeted Regions
AustraliaAustralia
Nov 2021 ~ Aug 2024
Nov 2021 ~ Aug 2024
Nov 2021 ~ Aug 2024
Nov 2021 ~ Aug 2024
Nov 2021 ~ Aug 2024
Nov 2021 ~ Aug 2024
Nov 2021 ~ Aug 2024
Nov 2021 ~ Aug 2024
Nov 2021 ~ Aug 2024
Nov 2021 ~ Aug 2024
Nov 2021 ~ Aug 2024
Nov 2021 ~ Aug 2024
United Arab EmiratesUnited Arab Emirates
Nov 2021 ~ Aug 2024
Nov 2021 ~ Aug 2024
Nov 2021 ~ Aug 2024
Nov 2021 ~ Aug 2024
Nov 2021 ~ Aug 2024
Nov 2021 ~ Aug 2024
Nov 2021 ~ Aug 2024
Nov 2021 ~ Aug 2024
Nov 2021 ~ Aug 2024
Nov 2021 ~ Aug 2024
Nov 2021 ~ Aug 2024
Nov 2021 ~ Aug 2024
United StatesUnited States
Nov 2021 ~ Aug 2024
Nov 2021 ~ Aug 2024
Nov 2021 ~ Aug 2024
Nov 2021 ~ Aug 2024
Nov 2021 ~ Aug 2024
Nov 2021 ~ Aug 2024
Nov 2021 ~ Aug 2024
Nov 2021 ~ Aug 2024
Nov 2021 ~ Aug 2024 Dec 2023 ~ Jan 2024
Nov 2021 ~ Aug 2024 Dec 2023 ~ Jan 2024
Nov 2021 ~ Aug 2024
Nov 2021 ~ Aug 2024
Targeted Sectors
Recent Indexed Reports
Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.