Latest Update27/08/2026

Threats Feed

  1. Public

    Iran's Cyber Operations Target 2024 US Presidential Election

    It has been established that Iranian threat actors have initiated cyber-enabled influence operations targeting the 2024 US presidential election. Groups such as Sefid Flood are impersonating social and political activist groups with the intention of undermining trust in authorities and sowing discord. Iran's Islamic Revolutionary Guard Corps (IRGC)-linked Mint Sandstorm has been observed conducting spear-phishing campaigns against US presidential campaigns, while Peach Sandstorm has been engaged in password spray attacks on local government accounts. Additionally, the Iranian network Storm-2035 has been identified as operating covert news websites with the objective of polarising US voters. These operations represent part of a broader effort by Iran to interfere with elections in the US and other countries like Bahrain and Israel, often targeting political and government sectors.

    read more about Iran's Cyber Operations Target 2024 US Presidential Election
  2. Public

    Iranian APT33 Intensifies Attacks on Multiple Sectors Worldwide

    Booz Allen Hamilton's Adversary Pursuit cell published a comprehensive technical hunt report on APT33 (Elfin/NewsBeef/Holmium), an Iranian state-attributed threat group active since 2013. The report synthesizes multi-year campaign activity across five distinct phases: (1) 2016–2017 aerospace and petrochemical spearphishing with job-lure malicious Office macros deploying TURNEDUP and DROPSHOT; (2) a parallel Saudi Arabian government campaign combining spearphishing and watering hole attacks against compromised web servers; (3) late 2017 to mid-2018 engineering sector intrusions using stolen credentials and RULER (CVE-2017-11774) to deploy POWERTON via Outlook client homepage persistence; (4) February 2019 spearphishing of a Saudi chemical company exploiting CVE-2018-20250 (WinRAR ACE path traversal); and (5) mid-2019 password spray campaigns against cloud-hosted ICS vendors and service providers, alongside June 2019 spearphishing of US federal agencies and Middle Eastern financial institutions, and August 2019 spoofed US defense contractor domains distributing malware. The report documents APT33's full malware arsenal — custom implants (TURNEDUP, SHAPESHIFT/STONEDRILL, DROPSHOT, POWERTON) and commodity tools (PoshC2, Remcos, DarkComet, Quasar RAT, Pupy RAT) — alongside targeted CVEs (CVE-2017-11774, CVE-2018-20250, CVE-2017-0213), MITRE ATT&CK technique mappings, specific detection analytics with Sysmon/Splunk queries, and targeted country and sector tables covering 11 countries and 16 sectors. The report notes Booz Allen could not independently verify claims linking APT33 to Shamoon wiper attacks but includes Shamoon detection logic given the potential overlap.

    read more about Iranian APT33 Intensifies Attacks on Multiple Sectors Worldwide
  3. Public

    Iranian APT33 Intensifies Attacks on Multiple Sectors Worldwide

    Booz Allen Hamilton's Adversary Pursuit cell published a comprehensive technical hunt report on APT33 (Elfin/NewsBeef/Holmium), an Iranian state-attributed threat group active since 2013. The report synthesizes multi-year campaign activity across five distinct phases: (1) 2016–2017 aerospace and petrochemical spearphishing with job-lure malicious Office macros deploying TURNEDUP and DROPSHOT; (2) a parallel Saudi Arabian government campaign combining spearphishing and watering hole attacks against compromised web servers; (3) late 2017 to mid-2018 engineering sector intrusions using stolen credentials and RULER (CVE-2017-11774) to deploy POWERTON via Outlook client homepage persistence; (4) February 2019 spearphishing of a Saudi chemical company exploiting CVE-2018-20250 (WinRAR ACE path traversal); and (5) mid-2019 password spray campaigns against cloud-hosted ICS vendors and service providers, alongside June 2019 spearphishing of US federal agencies and Middle Eastern financial institutions, and August 2019 spoofed US defense contractor domains distributing malware. The report documents APT33's full malware arsenal — custom implants (TURNEDUP, SHAPESHIFT/STONEDRILL, DROPSHOT, POWERTON) and commodity tools (PoshC2, Remcos, DarkComet, Quasar RAT, Pupy RAT) — alongside targeted CVEs (CVE-2017-11774, CVE-2018-20250, CVE-2017-0213), MITRE ATT&CK technique mappings, specific detection analytics with Sysmon/Splunk queries, and targeted country and sector tables covering 11 countries and 16 sectors. The report notes Booz Allen could not independently verify claims linking APT33 to Shamoon wiper attacks but includes Shamoon detection logic given the potential overlap.

    read more about Iranian APT33 Intensifies Attacks on Multiple Sectors Worldwide
  4. Public

    Iranian APT33 Intensifies Attacks on Multiple Sectors Worldwide

    Booz Allen Hamilton's Adversary Pursuit cell published a comprehensive technical hunt report on APT33 (Elfin/NewsBeef/Holmium), an Iranian state-attributed threat group active since 2013. The report synthesizes multi-year campaign activity across five distinct phases: (1) 2016–2017 aerospace and petrochemical spearphishing with job-lure malicious Office macros deploying TURNEDUP and DROPSHOT; (2) a parallel Saudi Arabian government campaign combining spearphishing and watering hole attacks against compromised web servers; (3) late 2017 to mid-2018 engineering sector intrusions using stolen credentials and RULER (CVE-2017-11774) to deploy POWERTON via Outlook client homepage persistence; (4) February 2019 spearphishing of a Saudi chemical company exploiting CVE-2018-20250 (WinRAR ACE path traversal); and (5) mid-2019 password spray campaigns against cloud-hosted ICS vendors and service providers, alongside June 2019 spearphishing of US federal agencies and Middle Eastern financial institutions, and August 2019 spoofed US defense contractor domains distributing malware. The report documents APT33's full malware arsenal — custom implants (TURNEDUP, SHAPESHIFT/STONEDRILL, DROPSHOT, POWERTON) and commodity tools (PoshC2, Remcos, DarkComet, Quasar RAT, Pupy RAT) — alongside targeted CVEs (CVE-2017-11774, CVE-2018-20250, CVE-2017-0213), MITRE ATT&CK technique mappings, specific detection analytics with Sysmon/Splunk queries, and targeted country and sector tables covering 11 countries and 16 sectors. The report notes Booz Allen could not independently verify claims linking APT33 to Shamoon wiper attacks but includes Shamoon detection logic given the potential overlap.

    read more about Iranian APT33 Intensifies Attacks on Multiple Sectors Worldwide
  5. Public

    Cyber Threats on the Rise: APT33 Targets Aerospace, Shipping, and Manufacturing via OneNote

    Loginsoft's March 2023 report examines the broader OneNote malware delivery campaign, within which APT33 is identified as one of several threat actors exploiting Microsoft OneNote files to deliver malware payloads. The campaign emerged after Microsoft disabled malicious macro execution in Office documents, prompting attackers to pivot to OneNote notebooks as a new delivery vehicle. APT33 used this method to target organizations in the aerospace, shipping, and manufacturing sectors, embedding malicious files or URLs within OneNote pages hidden behind counterfeit clickable buttons — tricking victims into triggering payload execution. The malware families associated with the broader campaign include commodity RATs and stealers such as NETWIRE, Quasar RAT, AsyncRAT, XWorm, Formbook, Agent Tesla, RedLine Stealer, IcedID, QakBot, Emotet, and the APT33-linked DOUBLEBACK backdoor. The technique chain involved spearphishing attachment delivery, obfuscated embedded payloads, process injection, and proxy execution via Windows LOLBins including mshta.exe, rundll32.exe, and regsvcs/regasm to evade defenses. Note: the original source URL is no longer accessible; content is reconstructed from the archived feed description and threat record.

    read more about Cyber Threats on the Rise: APT33 Targets Aerospace, Shipping, and Manufacturing via OneNote
  6. Public

    Iran-Linked TA451 Targets US Defense Contractor with COVID-19 Phishing

    In early January 2021, Proofpoint researchers identified the Iran-aligned APT actor TA451 (also known as APT33) running a spearphishing campaign against a US defense contractor using COVID-19-themed lures. The actor masqueraded as the World Health Organization, delivering emails with a link to a malicious executable named COVID19tracker[.]exe. Once a user executed the file, it reached out to download a batch script (iehchecker[.]bat), which in turn retrieved a PowerShell script (Update-KB4524147[.]ps1) with reverse shell capabilities, giving the attacker remote access to the compromised host. The campaign is documented as a case study in TA451's social engineering tradecraft within Proofpoint's broader 2022 Social Engineering Report, which covers threat actor tactics observed throughout 2021 — including multi-stage infection chains, impersonation of trusted organizations, and exploitation of topical events to lower victim defenses.

    read more about Iran-Linked TA451 Targets US Defense Contractor with COVID-19 Phishing
  7. Public

    Shifting Domains: APT33's Evolving Network Infrastructure

    ThreatConnect Research Team documents a brief infrastructure pivot observation: four APT33 C2 domains previously identified in Trend Micro's 2019 report on obfuscated APT33 botnets (zeverco[.]com, service-eset[.]com, simsoshop[.]com, qualitweb[.]com) began resolving to a new IP address, 109.230.199[.]157, starting in late July 2020. ThreatConnect explicitly notes that it is unknown whether this IP address is a sinkhole, a parking IP, or still under APT33's operational control, and whether the domains are still being used by APT33. Several additional domains not previously associated with APT33 also began resolving to the same IP during the same period: publicsecur[.]com, akadnsplugin[.]com (registrant: joshua.toon1978@mail[.]com), service-houston[.]com, support-newyork[.]com, and ocsp-support[.]com (registrant: warren.jones2626@mail[.]com). These additional domains were registered through THCservers, a suspicious reseller previously used by multiple state and criminal actors. ThreatConnect notes a possible further association between ocsp-support[.]com and two additional domains — prefmsedge[.]com and tracking-protection[.]net — based on reuse of the "Warren Jones" email address string in registrant data (registered through AminServe rather than THCservers). This is a brief infrastructure observation published as part of ThreatConnect's weekly Research Roundup; the same edition also covers unrelated RedDelta PlugX and Emotet activity. Attribution to APT33 for the newly identified domains remains unconfirmed.

    read more about Shifting Domains: APT33's Evolving Network Infrastructure
  8. Public

    APT33: Leveraging Known Vulnerabilities in U.S. Industry Attacks

    HYAS provides a July 2020 update on APT33 activity during the COVID-19 pandemic, a period during which public attention to Iranian threat groups had diminished despite continued operations. APT33 — also known as Refined Kitten, Magnallium, and Holmium — maintained its infrastructure-building tempo throughout the pandemic, with HYAS identifying new suspicious domain registrations consistent with prior APT33 TTPs over a 90-day monitoring window. The group continued targeting US organizations in the aviation, petrochemical, and defense contractor sectors using multi-stage attacks: weaponized documents, exploitation of the Microsoft Outlook vulnerability CVE-2017-11774, and PowerShell backdoors delivered from domains mimicking legitimate business services. A key example — customermgmt[.]net — was publicly confirmed by US Cyber Command in July 2019 as an active APT33 malware delivery point. The report contextualizes this activity against escalating Iran-West tensions: the collapse of the Iran nuclear deal, the January 2020 assassination of Qasem Soleimani, and the subsequent downing of a civilian aircraft near Tehran.

    read more about APT33: Leveraging Known Vulnerabilities in U.S. Industry Attacks
  9. Public

    Suspected APT33 Cyber Infrastructure Identified in Recent Domain Registrations

    The report uncovers suspicious network infrastructure possibly linked to APT33, highlighting the registration of the domain taskreminder[.]net and its association with the ns1.realhosters.com name server and OVH hosting. It draws parallels with previously identified APT33 infrastructure, emphasizing the pattern of using specific name servers and hosting services. Additionally, the report identifies domains spoofing Poste Italiane and “msupdate” themed domains, suggesting potential credential harvesting and malicious software distribution activities.

    read more about Suspected APT33 Cyber Infrastructure Identified in Recent Domain Registrations
  10. Public

    Fox Kitten Campaign: Iranian APTs Target Global Infrastructure via VPN Exploits

    Iranian APT groups APT34 and APT33 jointly operated the Fox Kitten campaign from 2017 to 2019, exploiting VPN vulnerabilities (e.g., Pulse Secure CVE-2019-11510, Fortinet CVE-2018-13379) to breach networks across Israel, the US, Gulf states, and Europe. Targeted sectors included IT, telecommunications, oil and gas, aviation, government, and security. The attackers established persistence using custom and open-source tools, including SSH tunnels, RDP proxies, webshells, and credential dumping via Mimikatz and ProcDump. Tools like Ngrok and Serveo enabled data exfiltration. The infrastructure supported both espionage and potential destructive operations tied to malware such as ZeroCleare and Dustman.

    read more about Fox Kitten Campaign: Iranian APTs Target Global Infrastructure via VPN Exploits
  11. Public

    Deciphering APT33's POWERBAND: A Step Towards Critical Infrastructure Attacks

    Telsy's February 2020 report documents POWERBAND, a new .NET-based Remote Administration Tool attributed to APT33 with medium-to-high confidence. The implant is a heavily obfuscated .NET executable and represents a TTP evolution for APT33 — the first time the group was observed using the .NET runtime environment for a late-stage implant. Telsy named it POWERBAND after the structured URL paths used in its HTTPS C2 communications. The malware closely mirrors APT33's previously known POWERTON backdoor, sharing the same architecture, encryption logic, command parsing methodology, and C2 interaction patterns. On execution, POWERBAND generates a unique victim identifier called BKey, derived from an MD5 hash of the machine name, user domain name, and username (first 24 characters, uppercase). This BKey is used to encrypt all victim fingerprint data — machine name, username, and the BKey itself — and to encrypt and decrypt all C2 traffic. C2 communications use HTTPS POST requests to dailystudy[.]org with three distinct path structures: /album/PBKey/ for command output, /track/BKey/ for file downloads and screenshot exfiltration, and /music/Bkey/band for file uploads. Persistence is achieved via the HKCU SOFTWARE\Microsoft\Windows\CurrentVersion\Run registry key. The report notes APT33's observed shift toward targeting critical infrastructure, raising concern about potential disruptive or destructive follow-on operations.

    read more about Deciphering APT33's POWERBAND: A Step Towards Critical Infrastructure Attacks
  12. Public

    Persistent Exploits in Microsoft Outlook: Iranian Hackers Bypass Security Patches

    Iranian APT groups, notably APT34 and APT33, have exploited the CVE-2017-11774 vulnerability in Microsoft Outlook, using it for espionage and destructive attacks. This exploit involves modifying Outlook's homepage settings via the registry to achieve persistence and remote code execution, bypassing Microsoft's patch. The attacks have targeted sectors globally, leveraging custom phishing documents and Azure-hosted payloads to bypass security measures and maintain control over compromised systems.

    read more about Persistent Exploits in Microsoft Outlook: Iranian Hackers Bypass Security Patches
  13. Public

    Credential and Information Theft: APT33's Job Scam Campaign

    Iranian APT33 has been detected running a phishing campaign that employs fake job scams to lure victims. The campaign aims for credential theft, information theft, and unauthorized remote access. While the targeted sectors and countries are not specified, the indicators of compromise involve domain names like "www[.]global-careers[.]org" and filenames such as "JobDescription.zip" and "JobDescription.vbe".

    read more about Credential and Information Theft: APT33's Job Scam Campaign
  14. Public

    Cyber Espionage by APT33 Targets Education, National Security, and Oil Industries

    Trend Micro documents APT33's use of more than a dozen obfuscated C2 servers for extremely narrow targeting, with each botnet comprising only about 12 infected machines. The group runs a multi-layer C2 obfuscation chain: infected bots connect to cloud-hosted proxy domains, which relay traffic to shared webserver backends, which report to dedicated bot data aggregators and controllers — all administered by APT33 operators through a private VPN network with exit nodes rotated frequently. Trend Micro tracked 10 live bot aggregators in fall 2019 and 21 private VPN exit node IPs across late 2018 to late 2019, confirming sustained operations. Confirmed active victims in 2019 include two separate US national security services company locations, two US university victims, a US military-related victim, and multiple Middle East and Asia victims. Oil supply chain compromises confirmed in fall 2018 include a UK-based oil company with servers in the UK and India communicating with an APT33 C2, and a European oil company with an infected server in India for at least three weeks in November–December 2018. APT33 also used a high-ranking European politician's private website for at least two years to send spear phishing emails — with job-lure subjects spoofing aviation and oil companies including al-Salam Aircraft Company, NGAAKSA, DynCorp International, SIPCHEM, Saudi Aramco, and SAMREF — targeting oil supply chain companies including a US military water supply facility. The malware deployed (MsdUpdate.exe, DysonPart.exe — detected as NYMERIA/SCAR variants) is functionally basic: it establishes persistence and downloads additional payloads. All 11 C2 domains listed were registered in 2016–2017 and remained live at time of publication. The VPN exit nodes were also used for reconnaissance against oil exploration companies and military hospitals in the Middle East and a US oil company.

    read more about Cyber Espionage by APT33 Targets Education, National Security, and Oil Industries
  15. Public

    APT33 Expands its Cyberattack Scope Beyond the Middle East

    HYAS Threat Intelligence identified a cluster of APT33 campaign infrastructure being actively built out ahead of imminent attacks on targets beyond the group's traditional Middle East focus. In mid-2019, APT33 — also tracked as Elfin, Holmium, Magnallium, and Refined Kitten — was observed targeting financial services and advanced technology companies in the United States and other countries, expanding beyond its historic emphasis on energy, aerospace, and defense. HYAS identified 11 high-confidence (95%+) and 9 moderate-confidence (75%+) domains linked to APT33 infrastructure, several of which were flagged before they were put into active use — including customermgmnt[.]net, later confirmed by US Cyber Command as a malware delivery point exploiting CVE-2017-11774 (a Microsoft Outlook vulnerability). The report reflects increased Iranian APT activity tied to escalating geopolitical tensions, with APT33 operating in parallel with APT34, APT35, and MuddyWater.

    read more about APT33 Expands its Cyberattack Scope Beyond the Middle East
  16. Public

    APT33 Elevates C2 Capabilities with New PowerShell Malware

    Norfolk InfoSec analyzed a custom PowerShell backdoor linked to APT33's mid-2019 campaign, identified through infrastructure pivots on the confirmed C2 domain backupaccount[.]net — a domain publicly flagged by US Cyber Command, ClearSky, and FireEye. The malware defines 14 functions and implements a full-featured C2 framework: it communicates with its control server via JSON-masked HTTP requests, supports active and silent operating modes with dynamically adjusted polling intervals (5–10 seconds active, 45–70 minutes silent), and implements two separate persistence mechanisms — WMI event filters and HKCU registry Run keys (smrsservice.exe). Core capabilities include file upload and download (with recursive directory traversal), screenshot capture, privilege checking, credential-related commands (SAM hive, LDAP, and an external invoke-pass module), arbitrary PowerShell command execution via invoke-expression, and encrypted C2 communications. The malware's modular command structure — with operator-controlled mode switching and clean-up via a paired "left" command — reflects a mature, operationally disciplined C2 design consistent with APT33's known capability level.

    read more about APT33 Elevates C2 Capabilities with New PowerShell Malware
  17. Public

    APT33 Targets Engineering Sector: A Blend of Public Tools and Custom Malware

    Mandiant's Managed Defense documented a series of contained intrusions against engineering sector organizations from November 2017 through December 2018, assessed with low-to-medium confidence as APT33 activity. The actor consistently exploited Microsoft Exchange and Outlook using stolen credentials and SensePost's RULER tool — first via malicious client-side mail rules delivering an AutoIT downloader over WebDAV (November 2017), then via CVE-2017-11774 (RULER.HOMEPAGE) to modify Outlook client homepages for persistent code execution (July–August 2018). The initial AutoIT downloader retrieved PowerSploit and reflectively loaded PUPYRAT. In later stages the actor transitioned to PoshC2 .NET stagers — configured with kill dates and AES-encrypted Base64 C2 traffic — then further escalated to POWERTON, a custom multi-layer obfuscated PowerShell backdoor supporting WMI and registry Run key persistence, HTTP(S) C2 over AES, and (in v2) credential dumping. Privilege escalation used CVE-2017-0213; credential theft used Procdump against LSASS and Mimikatz. After Managed Defense contained one intrusion, the actor reestablished access via password spraying within three weeks. Mandiant noted strong circumstantial overlap with confirmed APT33 tooling timelines and assessed the activity posed a heightened risk to critical infrastructure, particularly the energy sector. A July 2019 update confirmed full attribution to APT33 operating on behalf of the Iranian government.

    read more about APT33 Targets Engineering Sector: A Blend of Public Tools and Custom Malware
  18. Public

    APT33 Suspected in Latest Shamoon Attacks Targeting Middle East and European Energy Sector

    McAfee Advanced Threat Research analysts attribute a late-2018 wave of Shamoon destructive attacks to APT33, or a group impersonating them. The campaign used a modular .NET toolkit — comprising OCLC.exe, spreader.exe, SpreaderPsexec.exe, and a new file-erasure wiper called Filerase — alongside Shamoon Version 3. Initial access was gained through spear-phishing websites that mimicked legitimate energy-sector job portals, harvesting corporate credentials from targeted organizations in the Middle East and Europe as early as August 2018. Attackers then used those credentials to move laterally and deploy wipers across victim networks in a supply-chain-style operation, with the wiper execution stage reached in December 2018.

    read more about APT33 Suspected in Latest Shamoon Attacks Targeting Middle East and European Energy Sector
  19. Public

    Unveiling APT33’s Dropshot: Decrypting the Sophisticated Wiper Malware

    APT33’s Dropshot, also known as StoneDrill, is a sophisticated wiper malware targeting organizations primarily in Saudi Arabia. Dropshot uses advanced anti-emulation techniques and obfuscation to evade detection. The malware decrypts its payload from an encrypted resource and employs anti-emulation strategies, including invalid Windows API calls. It also leverages zlib for decompression. This analysis focuses on decrypting Dropshot's encrypted resource to understand its functionality. The malware's association with APT33 and similarities to the Shamoon malware underscore its threat to targeted sectors.

    read more about Unveiling APT33’s Dropshot: Decrypting the Sophisticated Wiper Malware
  20. Public

    APT33's Dropshot Malware: Advanced Evasion Techniques Unveiled

    APT33's Dropshot malware, also known as StoneDrill, targeted organizations primarily in Saudi Arabia. Dropshot, a sophisticated wiper malware, employs advanced anti-emulation techniques and string encryption to evade detection and analysis. The malware's high entropy suggests packed or compressed data, particularly in the .rsrc section, indicating hidden malicious content. This analysis focuses on decrypting the strings within Dropshot.

    read more about APT33's Dropshot Malware: Advanced Evasion Techniques Unveiled
  21. Public

    Cyber Espionage on Aviation: APT33 Targets US, Saudi Arabia, and South Korea

    Mandiant's September 2017 report provides the foundational profile of APT33, an Iranian state-sponsored espionage group active since at least 2013. The group targeted organizations in the United States, Saudi Arabia, and South Korea, with a strong focus on the aerospace and energy sectors — particularly companies with military aviation ties and petrochemical production. Between mid-2016 and early 2017, APT33 compromised a U.S. aerospace organization and targeted Saudi and South Korean conglomerates with aviation and oil refining operations. Intrusions began with spearphishing emails carrying malicious HTML Application (.hta) files disguised as aviation job postings, sent via the publicly available ALFA TEaM Shell. APT33 registered lookalike domains impersonating Boeing, Alsalam Aircraft Company, Northrop Grumman Aviation Arabia, and Vinnell Arabia to lend credibility to phishing lures. The group's primary backdoor, TURNEDUP, was deployed via the DROPSHOT dropper; commodity RATs including NANOCORE and NETWIRE were also used. Mandiant also identified links between DROPSHOT and the SHAPESHIFT disk-wiping malware, raising concerns about APT33's potential for destructive operations. Attacker activity aligned with Iranian working hours (UTC+4:30) and the Iranian Saturday-to-Wednesday workweek, supporting attribution to Iran.

    read more about Cyber Espionage on Aviation: APT33 Targets US, Saudi Arabia, and South Korea