APT33 Expands its Cyberattack Scope Beyond the Middle East
- Actor Motivations: Espionage,Sabotage
- Attack Vectors: Vulnerability Exploitation,Malware,Spear Phishing
- Attack Complexity: Medium
- Threat Risk: High Impact/Low Probability
Threat Overview
HYAS Threat Intelligence identified a cluster of APT33 campaign infrastructure being actively built out ahead of imminent attacks on targets beyond the group's traditional Middle East focus. In mid-2019, APT33 — also tracked as Elfin, Holmium, Magnallium, and Refined Kitten — was observed targeting financial services and advanced technology companies in the United States and other countries, expanding beyond its historic emphasis on energy, aerospace, and defense. HYAS identified 11 high-confidence (95%+) and 9 moderate-confidence (75%+) domains linked to APT33 infrastructure, several of which were flagged before they were put into active use — including customermgmnt[.]net, later confirmed by US Cyber Command as a malware delivery point exploiting CVE-2017-11774 (a Microsoft Outlook vulnerability). The report reflects increased Iranian APT activity tied to escalating geopolitical tensions, with APT33 operating in parallel with APT34, APT35, and MuddyWater.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Sector | Defense | Verified |
| Sector | Financial | Verified |
| Sector | High-Tech | Verified |
| Sector | Aerospace | Verified |
| Sector | Energy | Verified |
| Region | United States | Verified |
| Region | Middle East Countries | Verified |
Exploited Vulnerabilities
Extracted IOCs
- admindirector[.]com
- backupaccount[.]net
- businessscards[.]com
- cardchsk[.]com
- cardkuys[.]com
- ceoadminoffice[.]com
- customermgmnt[.]net
- customermgmt[.]net
- diplomatsign[.]com
- groupchiefexecutive[.]com
- inboxsync[.]org
- mailsarchive[.]com
- managementdirector[.]com
- moreonlineshopping[.]com
- officemngt[.]com
- phpencryptssl[.]com
- service-search[.]info
- tokensetting[.]com
- truelogon[.]com
- urlmanage[.]com
- whiteelection[.]com
Tip: 21 related IOCs (0 IP, 21 domain, 0 URL, 0 email, 0 file hash) to this threat have been found.
Overlaps
Source: Hyas - July 2020
Detection (one case): customermgmt[.]net
Source: One Night in Norfolk - July 2019
Detection (one case): backupaccount[.]net
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
Frequently Asked Questions
In 2019, HYAS Threat Intelligence identified a wave of new infrastructure being built out by APT33, an Iranian state-aligned hacking group. The group was expanding its attack operations beyond its traditional Middle Eastern targets, actively preparing to hit financial services and technology companies in the United States and other countries. US Cyber Command later confirmed APT33 was exploiting a known Microsoft Outlook vulnerability to deliver malware from domains HYAS had already flagged months earlier.
APT33 is an Iranian state-aligned threat group, also tracked under the names Elfin, Holmium, Magnallium, and Refined Kitten. Multiple threat intelligence firms — including HYAS, ClearSky, Symantec, and FireEye — have independently attributed this infrastructure and campaign activity to APT33. US Cyber Command issued a public alert in July 2019 confirming APT33's use of the identified domains and the CVE-2017-11774 exploit.
The campaign combined two goals: espionage — gathering intelligence from financial and technology targets — and pre-positioning for potential sabotage consistent with APT33's history of destructive operations. The infrastructure buildup suggests the group was preparing sustained access to a broader set of targets, likely driven by escalating geopolitical tensions between Iran and Western nations in 2019.
HYAS identified 20 domains linked to APT33 with high or moderate confidence, several of which were pre-staged and not yet in active use at the time of discovery. US Cyber Command confirmed at least one active malware delivery domain (customermgmnt[.]net). The campaign extended across the United States and other unnamed countries, marking a clear expansion from APT33's previous focus on the Middle East.
Financial services companies and advanced technology firms were the newly added targets in this campaign — a departure from APT33's historical focus on energy, utilities, aerospace, and defense organizations in the Middle East. The expansion reflects the group's intent to pursue broader economic and geopolitical intelligence as Iran-West tensions intensified in 2019.
APT33 exploited CVE-2017-11774, a vulnerability in Microsoft Outlook, to execute malware on victim systems. The malware was delivered from attacker-controlled domains that mimicked legitimate business services — names like customermgmt[.]net, admindirector[.]com, and ceoadminoffice[.]com. HYAS identified these domains through passive DNS analysis and behavioral patterns consistent with known APT33 infrastructure, flagging them before they were used in live attacks.
Financial institutions hold sensitive economic data, transaction records, and access to capital markets — all valuable for state-sponsored intelligence gathering. Technology companies hold intellectual property, research, and access to downstream supply chains. For a nation-state actor like APT33, compromising these sectors offers both intelligence value and leverage for potential future disruptive operations.
Organizations should patch CVE-2017-11774 immediately if not already done, and monitor Outlook for unusual child process activity that could indicate exploitation. Block the 20 APT33-linked domains listed in this report at DNS and proxy layers. Financial and technology companies should treat APT33 as an active threat rather than a sector-specific concern for energy firms only. Investing in threat intelligence services that can identify attacker infrastructure before it goes live provides a meaningful head start on detection and blocking.