Threats Feed|Elfin|Last Updated 30/04/2026|AuthorCertfa Radar|Publish Date27/03/2019

The Elfin Threat: Customized Malware Attacks Across Diverse Sectors

  • Actor Motivations: Espionage,Exfiltration
  • Attack Vectors: Vulnerability Exploitation,Backdoor,RAT,Spear Phishing
  • Attack Complexity: High
  • Threat Risk: High Impact/Low Probability

Threat Overview

Symantec's March 2019 report documents the sustained espionage operations of Elfin (also tracked as APT33), an Iranian-linked group active since late 2015. Over three years, Elfin compromised at least 50 organizations across Saudi Arabia, the United States, and multiple other countries, targeting sectors including research, chemical, engineering, manufacturing, finance, telecommunications, energy, IT, and healthcare. The group routinely scans for vulnerable public-facing websites to identify targets and build command-and-control infrastructure. Its arsenal spans custom malware (TURNEDUP/Notestuk, StoneDrill, AutoIt backdoor), commodity RATs (Remcos, DarkComet, Quasar, Pupy, NanoCore, NetWeird), and open-source post-exploitation tools (Mimikatz, LaZagne, PoshC2, Empire). A documented February 2019 intrusion into a U.S. organization shows the full attack chain: a spearphishing link delivered via email, PowerShell-based staging, scheduled task persistence, credential dumping, and data exfiltration over FTP using a custom tool called FastUploader. The report also notes a February 2019 attempted exploitation of CVE-2018-20250 (WinRAR) against a Saudi chemical-sector target.

Detected Targets

TypeDescriptionConfidence
SectorConsulting
Verified
SectorFinancial
Verified
SectorHigh-Tech
Verified
SectorInformation Technology
Verified
SectorManufacturing
Verified
SectorMedical
Verified
SectorScientific Research
Verified
SectorTelecommunication
Verified
SectorUtilities
Verified
RegionBelgium
Verified
RegionChina
Verified
RegionCzech Republic
Verified
RegionJordan
Verified
RegionMorocco
Verified
RegionSaudi Arabia
Verified
RegionThailand
Verified
RegionUnited Arab Emirates
Verified
RegionUnited Kingdom
Verified
RegionUnited States
Verified

Exploited Vulnerabilities

Extracted IOCs

  • ddns[.]net
  • microsoftupdated[.]com
  • myftp[.]biz
  • myftp[.]org
  • mynetwork[.]cf
  • redirectme[.]net
  • securityupdated[.]com
  • servehttp[.]com
  • service-avant[.]com
  • svcexplores[.]com
  • sytes[.]net
  • update-sec[.]com
  • backupnet.ddns[.]net
  • hyperservice.ddns[.]net
  • mynetwork.ddns[.]net
  • mypsh.ddns[.]net
  • mywinnetwork.ddns[.]net
  • remote-server.ddns[.]net
  • remserver.ddns[.]net
  • servhost.hopto[.]org
  • srvhost.servehttp[.]com
  • 018360b869d8080cf5bcca1a09eb8251558378eb6479d8d89b8c80a8e2fa328c
  • 0b3610524ff6f67c59281dbf4a24a6e8753b965c15742c8a98c11ad9171e783d
  • 367e78852134ef488ecf6862e71f70a3b10653e642bda3df00dd012c4e130330
  • 5798aefb07e12a942672a60c2be101dc26b01485616713e8be1f68b321747f2f
  • 6401abe9b6e90411dc48ffc863c40c9d9b073590a8014fe1b0e6c2ecab2f7e18
  • 709df1bbd0a5b15e8f205b2854204e8caf63f78203e3b595e0e66c918ec23951
  • 87e2cf4aa266212aa8cf1b1c98ae905c7bac40a6fc21b8e821ffe88cf9234586
  • 94526e2d1aca581121bd79a699a3bf5e4d91a4f285c8ef5ab2ab6e9e44783997
  • 99c1228d15e9a7693d67c4cb173eaec61bdb3e3efdd41ee38b941e733c7104f8
  • a23c182349f17398076360b2cb72e81e5e23589351d3a6af59a27e1d552e1ec0
  • a67461a0c14fc1528ad83b9bd874f53b7616cfed99656442fb4d9cdd7d09e449
  • ae1d75a5f87421953372e79c081e4b0a929f65841ed5ea0d380b6289e4a6b565
  • af41e9e058e0a5656f457ad4425a299481916b6cf5e443091c7a6b15ea5b3db3
  • bf9c589de55f7496ff14187b1b5e068bd104396c23418a18954db61450d21bab
  • c7a2559f0e134cafbfc27781acc51217127a7739c67c40135be44f23b3f9d77b
  • d5262f1bc42d7d5d0ebedadd8ab90a88d562c7a90ff9b0aed1b3992ec073e2b0
  • dedfbc8acf1c7b49fb30af35eda5e23d3f7a202585a5efe82ea7c2a785a95f40
  • e999fdd6a0f5f8d1ca08cf2aef47f5ddc0ee75879c6f2c1ee23bc31fb0f26c70
  • ea5295868a6aef6aac9e117ef128e9de107817cc69e75f0b20648940724880f3
  • f2943f5e45befa52fb12748ca7171d30096e1d4fc3c365561497c618341299d5
  • 162[.]250.145.204
  • 162[.]250.145.222
  • 162[.]250.145.234
  • 188[.]165.4.81
  • 192[.]119.15.35
  • 192[.]119.15.36
  • 192[.]119.15.37
  • 192[.]119.15.38
  • 192[.]119.15.39
  • 192[.]119.15.40
  • 192[.]119.15.41
  • 192[.]119.15.42
  • 195[.]20.52.172
  • 213[.]252.244.14
  • 217[.]13.103.46
  • 217[.]147.168.44
  • 37[.]48.105.178
  • 5[.]187.21.70
  • 5[.]187.21.71
  • 5[.]79.127.177
  • 64[.]251.19.214
  • 64[.]251.19.215
  • 64[.]251.19.216
  • 64[.]251.19.217
  • 64[.]251.19.231
  • 64[.]251.19.232
  • 8[.]26.21.117
  • 8[.]26.21.119
  • 8[.]26.21.120
  • 8[.]26.21.220
  • 8[.]26.21.221
  • 8[.]26.21.222
  • 8[.]26.21.223
  • 89[.]34.237.118
  • 91[.]230.121.143
  • 91[.]230.121.144
  • 91[.]235.142.124
  • 91[.]235.142.76
  • 95[.]211.191.117
download

Tip: 80 related IOCs (39 IP, 21 domain, 0 URL, 0 email, 20 file hash) to this threat have been found.

Overlaps

APT33Cyber Espionage by APT33 Targets Education, National Security, and Oil Industries

Source: Trend Micro - November 2019

Detection (one case): a67461a0c14fc1528ad83b9bd874f53b7616cfed99656442fb4d9cdd7d09e449

APT33Cyber Espionage on Aviation: APT33 Targets US, Saudi Arabia, and South Korea

Source: Mandiant - September 2017

Detection (two cases): microsoftupdated[.]com, mywinnetwork.ddns[.]net

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

Frequently Asked Questions About the Elfin (APT33) Espionage Campaign

Elfin, an Iranian-linked espionage group also known as APT33, conducted a sustained campaign targeting at least 50 organizations across Saudi Arabia, the United States, and other countries between late 2015 and early 2019. The group used spearphishing emails, custom malware, and commodity hacking tools to break into target networks, steal credentials, and exfiltrate data. A notable February 2019 incident involved an attempted exploitation of a vulnerability in the WinRAR file archiver against a Saudi chemical company.

The campaign is attributed to Elfin, a threat group that security researchers also track as APT33 and link to Iran. The group has been active since at least late 2015 and specializes in cyber espionage operations against organizations in the Middle East, the United States, and other regions. Symantec, which published this analysis in March 2019, describes the group as "one of the most active groups currently operating in the Middle East."

The primary goal was intelligence collection and data theft. Elfin broke into target networks to harvest credentials, access sensitive files, and exfiltrate data to attacker-controlled servers. The group used a range of backdoors and remote access tools to maintain long-term access, and in one documented case remained active inside a compromised U.S. organization for nearly two months. Researchers also noted a possible connection to Shamoon wiper attacks, though no conclusive link was established.

The campaign was broad in both geography and scale. At least 50 organizations were compromised or targeted across multiple countries including Saudi Arabia, the United States, Belgium, the United Kingdom, the United Arab Emirates, Jordan, Morocco, Czech Republic, China, and Thailand. Saudi Arabia accounted for roughly 42 percent of observed attacks, while 18 U.S. organizations were targeted over a three-year period — including several Fortune 500 companies.

Elfin cast a wide net across industries. Targeted sectors included research, chemical, engineering, manufacturing, consulting, finance, telecommunications, energy, information technology, and healthcare. Some U.S. targets appeared to be selected as entry points for potential supply chain attacks — in at least one case, a large U.S. company was attacked the same month its Middle Eastern co-owned subsidiary was also compromised.

Elfin typically started with a spearphishing email, often disguised as a job vacancy notice, containing a malicious link. Clicking the link downloaded a malicious HTML file that executed PowerShell commands in the background, establishing a backdoor connection to the attackers' servers. From there, the group installed additional tools for credential theft, set up scheduled tasks to maintain persistence, and ultimately exfiltrated data over FTP using a custom-built tool called FastUploader. The full intrusion in one documented case unfolded over roughly seven weeks.

Saudi Arabia and the United States hold strategic interest for Iran-linked actors because of their roles in regional geopolitics, energy markets, and defense industries. Organizations in chemical, engineering, and energy sectors likely hold proprietary technical data of value to state-sponsored intelligence collection. U.S. Fortune 500 companies in these sectors also provide potential access to global supply chains — giving attackers the ability to reach additional targets through trusted relationships.

Organizations should patch CVE-2018-20250 (WinRAR) and keep all software up to date to reduce the risk of exploitation via malicious archive files. Train employees to recognize spearphishing emails, especially job-related lures. Restrict and monitor PowerShell execution, and enable Windows script block logging. Block outbound FTP traffic where not operationally required, and flag connections to DDNS services. Deploy endpoint detection tools to alert on credential dumping activity, scheduled task creation, and unusual startup entries.

About Affiliation
Elfin
Elfin is the name assigned by Symantec to the Iranian state-sponsored threat actor widely known as APT33. The group has been active since at least 2013 and focuses on cyber espionage against organizations in the aerospace, energy, defense, and aviation sectors across the United States, Saudi Arabia, South Korea, and Europe. Elfin operations are characterized by spear phishing campaigns using recruitment-themed lures, exploitation of known vulnerabilities for initial access, and deployment of custom backdoors for persistent intelligence collection. The cluster is also tracked as Peach Sandstorm and HOLMIUM by Microsoft.
View Elfin's Insights