The Elfin Threat: Customized Malware Attacks Across Diverse Sectors
- Actor Motivations: Espionage,Exfiltration
- Attack Vectors: Vulnerability Exploitation,Backdoor,RAT,Spear Phishing
- Attack Complexity: High
- Threat Risk: High Impact/Low Probability
Threat Overview
Symantec's March 2019 report documents the sustained espionage operations of Elfin (also tracked as APT33), an Iranian-linked group active since late 2015. Over three years, Elfin compromised at least 50 organizations across Saudi Arabia, the United States, and multiple other countries, targeting sectors including research, chemical, engineering, manufacturing, finance, telecommunications, energy, IT, and healthcare. The group routinely scans for vulnerable public-facing websites to identify targets and build command-and-control infrastructure. Its arsenal spans custom malware (TURNEDUP/Notestuk, StoneDrill, AutoIt backdoor), commodity RATs (Remcos, DarkComet, Quasar, Pupy, NanoCore, NetWeird), and open-source post-exploitation tools (Mimikatz, LaZagne, PoshC2, Empire). A documented February 2019 intrusion into a U.S. organization shows the full attack chain: a spearphishing link delivered via email, PowerShell-based staging, scheduled task persistence, credential dumping, and data exfiltration over FTP using a custom tool called FastUploader. The report also notes a February 2019 attempted exploitation of CVE-2018-20250 (WinRAR) against a Saudi chemical-sector target.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Sector | Consulting | Verified |
| Sector | Financial | Verified |
| Sector | High-Tech | Verified |
| Sector | Information Technology | Verified |
| Sector | Manufacturing | Verified |
| Sector | Medical | Verified |
| Sector | Scientific Research | Verified |
| Sector | Telecommunication | Verified |
| Sector | Utilities | Verified |
| Region | Belgium | Verified |
| Region | China | Verified |
| Region | Czech Republic | Verified |
| Region | Jordan | Verified |
| Region | Morocco | Verified |
| Region | Saudi Arabia | Verified |
| Region | Thailand | Verified |
| Region | United Arab Emirates | Verified |
| Region | United Kingdom | Verified |
| Region | United States | Verified |
Exploited Vulnerabilities
Extracted IOCs
- ddns[.]net
- microsoftupdated[.]com
- myftp[.]biz
- myftp[.]org
- mynetwork[.]cf
- redirectme[.]net
- securityupdated[.]com
- servehttp[.]com
- service-avant[.]com
- svcexplores[.]com
- sytes[.]net
- update-sec[.]com
- backupnet.ddns[.]net
- hyperservice.ddns[.]net
- mynetwork.ddns[.]net
- mypsh.ddns[.]net
- mywinnetwork.ddns[.]net
- remote-server.ddns[.]net
- remserver.ddns[.]net
- servhost.hopto[.]org
- srvhost.servehttp[.]com
- 018360b869d8080cf5bcca1a09eb8251558378eb6479d8d89b8c80a8e2fa328c
- 0b3610524ff6f67c59281dbf4a24a6e8753b965c15742c8a98c11ad9171e783d
- 367e78852134ef488ecf6862e71f70a3b10653e642bda3df00dd012c4e130330
- 5798aefb07e12a942672a60c2be101dc26b01485616713e8be1f68b321747f2f
- 6401abe9b6e90411dc48ffc863c40c9d9b073590a8014fe1b0e6c2ecab2f7e18
- 709df1bbd0a5b15e8f205b2854204e8caf63f78203e3b595e0e66c918ec23951
- 87e2cf4aa266212aa8cf1b1c98ae905c7bac40a6fc21b8e821ffe88cf9234586
- 94526e2d1aca581121bd79a699a3bf5e4d91a4f285c8ef5ab2ab6e9e44783997
- 99c1228d15e9a7693d67c4cb173eaec61bdb3e3efdd41ee38b941e733c7104f8
- a23c182349f17398076360b2cb72e81e5e23589351d3a6af59a27e1d552e1ec0
- a67461a0c14fc1528ad83b9bd874f53b7616cfed99656442fb4d9cdd7d09e449
- ae1d75a5f87421953372e79c081e4b0a929f65841ed5ea0d380b6289e4a6b565
- af41e9e058e0a5656f457ad4425a299481916b6cf5e443091c7a6b15ea5b3db3
- bf9c589de55f7496ff14187b1b5e068bd104396c23418a18954db61450d21bab
- c7a2559f0e134cafbfc27781acc51217127a7739c67c40135be44f23b3f9d77b
- d5262f1bc42d7d5d0ebedadd8ab90a88d562c7a90ff9b0aed1b3992ec073e2b0
- dedfbc8acf1c7b49fb30af35eda5e23d3f7a202585a5efe82ea7c2a785a95f40
- e999fdd6a0f5f8d1ca08cf2aef47f5ddc0ee75879c6f2c1ee23bc31fb0f26c70
- ea5295868a6aef6aac9e117ef128e9de107817cc69e75f0b20648940724880f3
- f2943f5e45befa52fb12748ca7171d30096e1d4fc3c365561497c618341299d5
- 162[.]250.145.204
- 162[.]250.145.222
- 162[.]250.145.234
- 188[.]165.4.81
- 192[.]119.15.35
- 192[.]119.15.36
- 192[.]119.15.37
- 192[.]119.15.38
- 192[.]119.15.39
- 192[.]119.15.40
- 192[.]119.15.41
- 192[.]119.15.42
- 195[.]20.52.172
- 213[.]252.244.14
- 217[.]13.103.46
- 217[.]147.168.44
- 37[.]48.105.178
- 5[.]187.21.70
- 5[.]187.21.71
- 5[.]79.127.177
- 64[.]251.19.214
- 64[.]251.19.215
- 64[.]251.19.216
- 64[.]251.19.217
- 64[.]251.19.231
- 64[.]251.19.232
- 8[.]26.21.117
- 8[.]26.21.119
- 8[.]26.21.120
- 8[.]26.21.220
- 8[.]26.21.221
- 8[.]26.21.222
- 8[.]26.21.223
- 89[.]34.237.118
- 91[.]230.121.143
- 91[.]230.121.144
- 91[.]235.142.124
- 91[.]235.142.76
- 95[.]211.191.117
Tip: 80 related IOCs (39 IP, 21 domain, 0 URL, 0 email, 20 file hash) to this threat have been found.
Overlaps
Source: Trend Micro - November 2019
Detection (one case): a67461a0c14fc1528ad83b9bd874f53b7616cfed99656442fb4d9cdd7d09e449
Source: Mandiant - September 2017
Detection (two cases): microsoftupdated[.]com, mywinnetwork.ddns[.]net
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
Frequently Asked Questions About the Elfin (APT33) Espionage Campaign
Elfin, an Iranian-linked espionage group also known as APT33, conducted a sustained campaign targeting at least 50 organizations across Saudi Arabia, the United States, and other countries between late 2015 and early 2019. The group used spearphishing emails, custom malware, and commodity hacking tools to break into target networks, steal credentials, and exfiltrate data. A notable February 2019 incident involved an attempted exploitation of a vulnerability in the WinRAR file archiver against a Saudi chemical company.
The campaign is attributed to Elfin, a threat group that security researchers also track as APT33 and link to Iran. The group has been active since at least late 2015 and specializes in cyber espionage operations against organizations in the Middle East, the United States, and other regions. Symantec, which published this analysis in March 2019, describes the group as "one of the most active groups currently operating in the Middle East."
The primary goal was intelligence collection and data theft. Elfin broke into target networks to harvest credentials, access sensitive files, and exfiltrate data to attacker-controlled servers. The group used a range of backdoors and remote access tools to maintain long-term access, and in one documented case remained active inside a compromised U.S. organization for nearly two months. Researchers also noted a possible connection to Shamoon wiper attacks, though no conclusive link was established.
The campaign was broad in both geography and scale. At least 50 organizations were compromised or targeted across multiple countries including Saudi Arabia, the United States, Belgium, the United Kingdom, the United Arab Emirates, Jordan, Morocco, Czech Republic, China, and Thailand. Saudi Arabia accounted for roughly 42 percent of observed attacks, while 18 U.S. organizations were targeted over a three-year period — including several Fortune 500 companies.
Elfin cast a wide net across industries. Targeted sectors included research, chemical, engineering, manufacturing, consulting, finance, telecommunications, energy, information technology, and healthcare. Some U.S. targets appeared to be selected as entry points for potential supply chain attacks — in at least one case, a large U.S. company was attacked the same month its Middle Eastern co-owned subsidiary was also compromised.
Elfin typically started with a spearphishing email, often disguised as a job vacancy notice, containing a malicious link. Clicking the link downloaded a malicious HTML file that executed PowerShell commands in the background, establishing a backdoor connection to the attackers' servers. From there, the group installed additional tools for credential theft, set up scheduled tasks to maintain persistence, and ultimately exfiltrated data over FTP using a custom-built tool called FastUploader. The full intrusion in one documented case unfolded over roughly seven weeks.
Saudi Arabia and the United States hold strategic interest for Iran-linked actors because of their roles in regional geopolitics, energy markets, and defense industries. Organizations in chemical, engineering, and energy sectors likely hold proprietary technical data of value to state-sponsored intelligence collection. U.S. Fortune 500 companies in these sectors also provide potential access to global supply chains — giving attackers the ability to reach additional targets through trusted relationships.
Organizations should patch CVE-2018-20250 (WinRAR) and keep all software up to date to reduce the risk of exploitation via malicious archive files. Train employees to recognize spearphishing emails, especially job-related lures. Restrict and monitor PowerShell execution, and enable Windows script block logging. Block outbound FTP traffic where not operationally required, and flag connections to DDNS services. Deploy endpoint detection tools to alert on credential dumping activity, scheduled task creation, and unusual startup entries.