Threats Feed|APT33|Last Updated 01/05/2026|AuthorCertfa Radar|Publish Date20/09/2019

APT33 Expands its Cyberattack Scope Beyond the Middle East

  • Actor Motivations: Espionage,Sabotage
  • Attack Vectors: Vulnerability Exploitation,Malware,Spear Phishing
  • Attack Complexity: Medium
  • Threat Risk: High Impact/Low Probability

Threat Overview

HYAS Threat Intelligence identified a cluster of APT33 campaign infrastructure being actively built out ahead of imminent attacks on targets beyond the group's traditional Middle East focus. In mid-2019, APT33 — also tracked as Elfin, Holmium, Magnallium, and Refined Kitten — was observed targeting financial services and advanced technology companies in the United States and other countries, expanding beyond its historic emphasis on energy, aerospace, and defense. HYAS identified 11 high-confidence (95%+) and 9 moderate-confidence (75%+) domains linked to APT33 infrastructure, several of which were flagged before they were put into active use — including customermgmnt[.]net, later confirmed by US Cyber Command as a malware delivery point exploiting CVE-2017-11774 (a Microsoft Outlook vulnerability). The report reflects increased Iranian APT activity tied to escalating geopolitical tensions, with APT33 operating in parallel with APT34, APT35, and MuddyWater.

Detected Targets

TypeDescriptionConfidence
SectorDefense
Verified
SectorFinancial
Verified
SectorHigh-Tech
Verified
SectorAerospace
Verified
SectorEnergy
Verified
RegionUnited States
Verified
RegionMiddle East Countries
Verified

Exploited Vulnerabilities

Extracted IOCs

  • admindirector[.]com
  • backupaccount[.]net
  • businessscards[.]com
  • cardchsk[.]com
  • cardkuys[.]com
  • ceoadminoffice[.]com
  • customermgmnt[.]net
  • customermgmt[.]net
  • diplomatsign[.]com
  • groupchiefexecutive[.]com
  • inboxsync[.]org
  • mailsarchive[.]com
  • managementdirector[.]com
  • moreonlineshopping[.]com
  • officemngt[.]com
  • phpencryptssl[.]com
  • service-search[.]info
  • tokensetting[.]com
  • truelogon[.]com
  • urlmanage[.]com
  • whiteelection[.]com
download

Tip: 21 related IOCs (0 IP, 21 domain, 0 URL, 0 email, 0 file hash) to this threat have been found.

Overlaps

APT33APT33: Leveraging Known Vulnerabilities in U.S. Industry Attacks

Source: Hyas - July 2020

Detection (one case): customermgmt[.]net

APT33APT33 Elevates C2 Capabilities with New PowerShell Malware

Source: One Night in Norfolk - July 2019

Detection (one case): backupaccount[.]net

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

Frequently Asked Questions

In 2019, HYAS Threat Intelligence identified a wave of new infrastructure being built out by APT33, an Iranian state-aligned hacking group. The group was expanding its attack operations beyond its traditional Middle Eastern targets, actively preparing to hit financial services and technology companies in the United States and other countries. US Cyber Command later confirmed APT33 was exploiting a known Microsoft Outlook vulnerability to deliver malware from domains HYAS had already flagged months earlier.

APT33 is an Iranian state-aligned threat group, also tracked under the names Elfin, Holmium, Magnallium, and Refined Kitten. Multiple threat intelligence firms — including HYAS, ClearSky, Symantec, and FireEye — have independently attributed this infrastructure and campaign activity to APT33. US Cyber Command issued a public alert in July 2019 confirming APT33's use of the identified domains and the CVE-2017-11774 exploit.

The campaign combined two goals: espionage — gathering intelligence from financial and technology targets — and pre-positioning for potential sabotage consistent with APT33's history of destructive operations. The infrastructure buildup suggests the group was preparing sustained access to a broader set of targets, likely driven by escalating geopolitical tensions between Iran and Western nations in 2019.

HYAS identified 20 domains linked to APT33 with high or moderate confidence, several of which were pre-staged and not yet in active use at the time of discovery. US Cyber Command confirmed at least one active malware delivery domain (customermgmnt[.]net). The campaign extended across the United States and other unnamed countries, marking a clear expansion from APT33's previous focus on the Middle East.

Financial services companies and advanced technology firms were the newly added targets in this campaign — a departure from APT33's historical focus on energy, utilities, aerospace, and defense organizations in the Middle East. The expansion reflects the group's intent to pursue broader economic and geopolitical intelligence as Iran-West tensions intensified in 2019.

APT33 exploited CVE-2017-11774, a vulnerability in Microsoft Outlook, to execute malware on victim systems. The malware was delivered from attacker-controlled domains that mimicked legitimate business services — names like customermgmt[.]net, admindirector[.]com, and ceoadminoffice[.]com. HYAS identified these domains through passive DNS analysis and behavioral patterns consistent with known APT33 infrastructure, flagging them before they were used in live attacks.

Financial institutions hold sensitive economic data, transaction records, and access to capital markets — all valuable for state-sponsored intelligence gathering. Technology companies hold intellectual property, research, and access to downstream supply chains. For a nation-state actor like APT33, compromising these sectors offers both intelligence value and leverage for potential future disruptive operations.

Organizations should patch CVE-2017-11774 immediately if not already done, and monitor Outlook for unusual child process activity that could indicate exploitation. Block the 20 APT33-linked domains listed in this report at DNS and proxy layers. Financial and technology companies should treat APT33 as an active threat rather than a sector-specific concern for energy firms only. Investing in threat intelligence services that can identify attacker infrastructure before it goes live provides a meaningful head start on detection and blocking.

About Affiliation
APT33
APT33 is an Iranian state-sponsored threat actor active since at least 2013, assessed by Mandiant to work at the behest of the Iranian government. The group focuses primarily on cyber espionage against organizations in the aerospace, aviation, energy, and defense sectors across the United States, Saudi Arabia, South Korea, and other countries. APT33 is known for spear phishing campaigns using job-recruitment lures and malicious .hta files, large-scale password spray operations, and the use of destructive malware. Microsoft tracks this cluster as Peach Sandstorm and previously as HOLMIUM.
View APT33's Insights