Threats Feed|APT33|Last Updated 01/05/2026|AuthorCertfa Radar|Publish Date14/09/2023

Iranian APT33 Intensifies Attacks on Multiple Sectors Worldwide

  • Actor Motivations: Espionage,Exfiltration,Sabotage
  • Attack Vectors: Compromised Credentials,Vulnerability Exploitation,Backdoor,Dropper,Malicious Macro,RAT,Wiper,Spear Phishing
  • Attack Complexity: High
  • Threat Risk: High Impact/High Probability

Threat Overview

Booz Allen Hamilton's Adversary Pursuit cell published a comprehensive technical hunt report on APT33 (Elfin/NewsBeef/Holmium), an Iranian state-attributed threat group active since 2013. The report synthesizes multi-year campaign activity across five distinct phases: (1) 2016–2017 aerospace and petrochemical spearphishing with job-lure malicious Office macros deploying TURNEDUP and DROPSHOT; (2) a parallel Saudi Arabian government campaign combining spearphishing and watering hole attacks against compromised web servers; (3) late 2017 to mid-2018 engineering sector intrusions using stolen credentials and RULER (CVE-2017-11774) to deploy POWERTON via Outlook client homepage persistence; (4) February 2019 spearphishing of a Saudi chemical company exploiting CVE-2018-20250 (WinRAR ACE path traversal); and (5) mid-2019 password spray campaigns against cloud-hosted ICS vendors and service providers, alongside June 2019 spearphishing of US federal agencies and Middle Eastern financial institutions, and August 2019 spoofed US defense contractor domains distributing malware. The report documents APT33's full malware arsenal — custom implants (TURNEDUP, SHAPESHIFT/STONEDRILL, DROPSHOT, POWERTON) and commodity tools (PoshC2, Remcos, DarkComet, Quasar RAT, Pupy RAT) — alongside targeted CVEs (CVE-2017-11774, CVE-2018-20250, CVE-2017-0213), MITRE ATT&CK technique mappings, specific detection analytics with Sysmon/Splunk queries, and targeted country and sector tables covering 11 countries and 16 sectors. The report notes Booz Allen could not independently verify claims linking APT33 to Shamoon wiper attacks but includes Shamoon detection logic given the potential overlap.

Detected Targets

TypeDescriptionConfidence
SectorConsulting
Medium
SectorDefense
Verified
SectorFinancial
Verified
SectorGovernment Agencies and Services
Verified
SectorHigh-Tech
Verified
SectorInformation Technology
Verified
SectorLogistics
Verified
SectorManufacturing
Verified
SectorRetail
Verified
SectorAerospace
Source Table 5 explicitly lists Aerospace as a targeted sector. APT33 targeted aerospace and aviation organizations from 2016-2017 to enhance Iran's aviation capabilities.
Verified
SectorEducation
Source Table 5 explicitly lists Education as a targeted sector.
Verified
SectorHealthcare
Source Table 5 explicitly lists Healthcare as a targeted sector.
Verified
SectorResearchers
Source Table 5 explicitly lists Research institutions as a targeted sector.
Verified
SectorTelecommunication
Verified
RegionBelgium
Verified
RegionChina
Verified
RegionCzech Republic
Verified
RegionJordan
Verified
RegionMorocco
Verified
RegionSaudi Arabia
Verified
RegionSouth Korea
Verified
RegionThailand
Verified
RegionUnited Arab Emirates
Verified
RegionUnited Kingdom
Verified
RegionUnited States
Verified

FAQs

Understanding APT33’s Threat Activities

APT33, an Iran-linked cyber threat group, has been carrying out sophisticated cyberattacks since at least 2013, targeting a wide range of industries in the Middle East, the U.S., and beyond.

The group, known by several names including Elfin and Holmium, is attributed to Iran and is believed to operate with state sponsorship.

APT33’s objectives appear to include espionage, competitive advantage in sectors like aviation and petrochemicals, and potentially disruptive operations such as deploying wiper malware.

While their main focus is on Saudi Arabia and the United States, APT33 has also targeted organizations in Europe and Asia, indicating a broad geographic reach.

Victims span across aerospace, chemical, government, financial, engineering, and telecom sectors, often including high-profile firms and critical infrastructure.

APT33 primarily uses spear phishing emails with infected attachments, stolen credentials, and software vulnerabilities to infiltrate networks and deploy malware.

The likely motive is to support Iran’s strategic interests in defense, economic development, and regional influence by stealing data or disrupting rivals.

Defensive actions include improving email defenses, enforcing strong password and authentication policies, applying security patches promptly, and monitoring for known malware behaviors.

These are highly targeted attacks aimed at specific organizations rather than the general public, but the tactics used can have broader cybersecurity implications.

About Affiliation
APT33
APT33 is an Iranian state-sponsored threat actor active since at least 2013, assessed by Mandiant to work at the behest of the Iranian government. The group focuses primarily on cyber espionage against organizations in the aerospace, aviation, energy, and defense sectors across the United States, Saudi Arabia, South Korea, and other countries. APT33 is known for spear phishing campaigns using job-recruitment lures and malicious .hta files, large-scale password spray operations, and the use of destructive malware. Microsoft tracks this cluster as Peach Sandstorm and previously as HOLMIUM.
View APT33's Insights