Iranian APT33 Intensifies Attacks on Multiple Sectors Worldwide
- Actor Motivations: Espionage,Exfiltration,Sabotage
- Attack Vectors: Compromised Credentials,Vulnerability Exploitation,Backdoor,Dropper,Malicious Macro,RAT,Wiper,Spear Phishing
- Attack Complexity: High
- Threat Risk: High Impact/High Probability
Threat Overview
Booz Allen Hamilton's Adversary Pursuit cell published a comprehensive technical hunt report on APT33 (Elfin/NewsBeef/Holmium), an Iranian state-attributed threat group active since 2013. The report synthesizes multi-year campaign activity across five distinct phases: (1) 2016–2017 aerospace and petrochemical spearphishing with job-lure malicious Office macros deploying TURNEDUP and DROPSHOT; (2) a parallel Saudi Arabian government campaign combining spearphishing and watering hole attacks against compromised web servers; (3) late 2017 to mid-2018 engineering sector intrusions using stolen credentials and RULER (CVE-2017-11774) to deploy POWERTON via Outlook client homepage persistence; (4) February 2019 spearphishing of a Saudi chemical company exploiting CVE-2018-20250 (WinRAR ACE path traversal); and (5) mid-2019 password spray campaigns against cloud-hosted ICS vendors and service providers, alongside June 2019 spearphishing of US federal agencies and Middle Eastern financial institutions, and August 2019 spoofed US defense contractor domains distributing malware. The report documents APT33's full malware arsenal — custom implants (TURNEDUP, SHAPESHIFT/STONEDRILL, DROPSHOT, POWERTON) and commodity tools (PoshC2, Remcos, DarkComet, Quasar RAT, Pupy RAT) — alongside targeted CVEs (CVE-2017-11774, CVE-2018-20250, CVE-2017-0213), MITRE ATT&CK technique mappings, specific detection analytics with Sysmon/Splunk queries, and targeted country and sector tables covering 11 countries and 16 sectors. The report notes Booz Allen could not independently verify claims linking APT33 to Shamoon wiper attacks but includes Shamoon detection logic given the potential overlap.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Sector | Consulting | Medium |
| Sector | Defense | Verified |
| Sector | Financial | Verified |
| Sector | Government Agencies and Services | Verified |
| Sector | High-Tech | Verified |
| Sector | Information Technology | Verified |
| Sector | Logistics | Verified |
| Sector | Manufacturing | Verified |
| Sector | Retail | Verified |
| Sector | Aerospace Source Table 5 explicitly lists Aerospace as a targeted sector. APT33 targeted aerospace and aviation organizations from 2016-2017 to enhance Iran's aviation capabilities. | Verified |
| Sector | Education Source Table 5 explicitly lists Education as a targeted sector. | Verified |
| Sector | Healthcare Source Table 5 explicitly lists Healthcare as a targeted sector. | Verified |
| Sector | Researchers Source Table 5 explicitly lists Research institutions as a targeted sector. | Verified |
| Sector | Telecommunication | Verified |
| Region | Belgium | Verified |
| Region | China | Verified |
| Region | Czech Republic | Verified |
| Region | Jordan | Verified |
| Region | Morocco | Verified |
| Region | Saudi Arabia | Verified |
| Region | South Korea | Verified |
| Region | Thailand | Verified |
| Region | United Arab Emirates | Verified |
| Region | United Kingdom | Verified |
| Region | United States | Verified |
Exploited Vulnerabilities
FAQs
Understanding APT33’s Threat Activities
APT33, an Iran-linked cyber threat group, has been carrying out sophisticated cyberattacks since at least 2013, targeting a wide range of industries in the Middle East, the U.S., and beyond.
The group, known by several names including Elfin and Holmium, is attributed to Iran and is believed to operate with state sponsorship.
APT33’s objectives appear to include espionage, competitive advantage in sectors like aviation and petrochemicals, and potentially disruptive operations such as deploying wiper malware.
While their main focus is on Saudi Arabia and the United States, APT33 has also targeted organizations in Europe and Asia, indicating a broad geographic reach.
Victims span across aerospace, chemical, government, financial, engineering, and telecom sectors, often including high-profile firms and critical infrastructure.
APT33 primarily uses spear phishing emails with infected attachments, stolen credentials, and software vulnerabilities to infiltrate networks and deploy malware.
The likely motive is to support Iran’s strategic interests in defense, economic development, and regional influence by stealing data or disrupting rivals.
Defensive actions include improving email defenses, enforcing strong password and authentication policies, applying security patches promptly, and monitoring for known malware behaviors.
These are highly targeted attacks aimed at specific organizations rather than the general public, but the tactics used can have broader cybersecurity implications.