Threats Feed|APT33|Last Updated 01/05/2026|AuthorCertfa Radar|Publish Date21/12/2018

APT33 Targets Engineering Sector: A Blend of Public Tools and Custom Malware

  • Actor Motivations: Espionage,Exfiltration
  • Attack Vectors: Backdoor,Spear Phishing
  • Attack Complexity: Medium
  • Threat Risk: High Impact/Low Probability

Threat Overview

Mandiant's Managed Defense documented a series of contained intrusions against engineering sector organizations from November 2017 through December 2018, assessed with low-to-medium confidence as APT33 activity. The actor consistently exploited Microsoft Exchange and Outlook using stolen credentials and SensePost's RULER tool — first via malicious client-side mail rules delivering an AutoIT downloader over WebDAV (November 2017), then via CVE-2017-11774 (RULER.HOMEPAGE) to modify Outlook client homepages for persistent code execution (July–August 2018). The initial AutoIT downloader retrieved PowerSploit and reflectively loaded PUPYRAT. In later stages the actor transitioned to PoshC2 .NET stagers — configured with kill dates and AES-encrypted Base64 C2 traffic — then further escalated to POWERTON, a custom multi-layer obfuscated PowerShell backdoor supporting WMI and registry Run key persistence, HTTP(S) C2 over AES, and (in v2) credential dumping. Privilege escalation used CVE-2017-0213; credential theft used Procdump against LSASS and Mimikatz. After Managed Defense contained one intrusion, the actor reestablished access via password spraying within three weeks. Mandiant noted strong circumstantial overlap with confirmed APT33 tooling timelines and assessed the activity posed a heightened risk to critical infrastructure, particularly the energy sector. A July 2019 update confirmed full attribution to APT33 operating on behalf of the Iranian government.

Detected Targets

TypeDescriptionConfidence
SectorCivil Engineering
Mandiant source repeatedly and explicitly identifies the engineering industry as the primary target of all documented intrusions in this campaign.
Verified
SectorFinancial
Verified
SectorGovernment Agencies and Services
Verified
SectorRetail
Verified
SectorEducation
Education sector explicitly named as a target in APT33's June 2019 intrusion campaign referenced in the Mandiant source update.
Verified
SectorEnergy
Mandiant source states the energy sector faces heightened risk from APT33, consistent with Iranian national priorities around petrochemical production. Infrastructure overlap with SHAMOON (energy sector wiper) was noted.
High
SectorMedia
Mandiant source explicitly names media sector targeting in APT33's June 2019 campaign, consistent with this activity cluster.
Verified
RegionUnited States
Verified
RegionUnited States
All documented Managed Defense intrusions were at US-based engineering firms. June 2019 APT33 campaign explicitly targeted US federal government agencies and financial, retail, media and education sectors.
Verified

Extracted IOCs

  • staffmusic[.]org
  • 129c296c363b6d9da0102aa03878ca7f
  • 17587668ac577fce0b278420b8eb72ac
  • 2cd286711151efb61a15e2e11736d7d2
  • 3871aac486ba79215f2155f32d581dc2
  • 4047e238bbcec147f8b97d849ef40ce5
  • 46038aa5b21b940099b0db413fa62687
  • 48d1ed9870ed40c224e50a11bf3523f8
  • 4aca006b9afe85b1f11314b39ee270f7
  • 4b19bccc25750f49c2c1bb462509f84e
  • 53ae59ed03fa5df3bf738bc0775a91d9
  • 56f5891f065494fdbb2693cfc9bce9ae
  • 5832f708fd860c88cbdc088acecec4ea
  • 5a66480e100d4f14e12fceb60e91371d
  • 75e680d5fddbdb989812c7ba83e7c425
  • 7f4f7e307a11f121d8659ca98bc8ba56
  • 8a99624d224ab3378598b9895660c890
  • 8be06571e915ae3f76901d52068e3498
  • 8d3fe1973183e1d3b0dbec31be8ee9dd
  • 95f3bea43338addc1ad951cd2d42eb6f
  • 974b999186ff434bee3ab6d61411731f
  • 99649d58c0d502b2dfada02124b1504c
  • bd80fcf5e70a0677ba94b3f7c011440e
  • c38069d0bc79acdc28af3820c1123e53
  • e2d60bb6e3e67591e13b6a8178d89736
  • f5ac89d406e698e169ba34fea59a780e
  • fa7790abe9ee40556fb3c5524388de0b
  • fca0ad319bf8e63431eb468603d50eff
  • 103[.]236.149.100
  • 103[.]236.149.124
  • 185[.]161.209.172
  • 51[.]254.71.223
  • 5[.]79.66.241
  • 85[.]206.161.214
  • 85[.]206.161.216
  • 89[.]45.35.235
  • 91[.]235.116.212
  • hxxps://staffmusic[.]org
download

Tip: 38 related IOCs (9 IP, 1 domain, 1 URL, 0 email, 27 file hash) to this threat have been found.

FAQs

APT33 Engineering Sector Campaign (OVERRULED) — Frequently Asked Questions

Between November 2017 and December 2018, FireEye's Managed Defense team detected and contained multiple targeted intrusions against US engineering companies, attributed to APT33 — an Iranian state-sponsored hacking group. The attackers abused Microsoft Exchange and Outlook to gain initial access using stolen credentials, then deployed a progression of tools from publicly available frameworks to a custom-built backdoor called POWERTON, designed to give them persistent, covert access to victim networks.

The attacks were carried out by APT33, also known as Elfin or Refined Kitten — an Iranian state-sponsored group confirmed in July 2019 by FireEye to be operating at the behest of the Iranian government. APT33 has been active since at least 2013 and is known for targeting energy, aerospace, and engineering organizations, particularly in the United States and the Middle East. FireEye initially assessed attribution at low-to-medium confidence based on tool and timeline overlap with confirmed APT33 activity; full attribution was confirmed after the group's June 2019 campaign against US federal agencies.

The primary goal was to gain and maintain persistent access to engineering sector networks for espionage and data collection. The attackers showed remarkable persistence — each time Managed Defense contained an intrusion, the actor reestablished access within weeks using a different method or new infrastructure. Mandiant also noted that APT33 has documented ties to destructive malware, including SHAMOON (a disk-wiping tool), suggesting the group is capable of transitioning from espionage to destructive attacks against critical infrastructure if directed to do so.

The documented intrusions were contained to a small number of US engineering firms, but the scope of APT33's broader activity is significantly wider. The group's June 2019 campaign targeted US federal government agencies, financial institutions, retail companies, media organizations, and educational institutions. APT33 also consistently targets the energy sector, which Mandiant assessed as facing a heightened risk from the group — consistent with Iran's strategic interest in understanding and potentially disrupting petrochemical and energy infrastructure.

The primary targets in this campaign were organizations in the engineering industry in the United States. APT33 more broadly targets the energy and aerospace sectors — specifically petrochemical companies, defense contractors, and government entities in the US, Saudi Arabia, South Korea, and across the Middle East. Mandiant specifically flagged the energy sector as the highest-risk industry due to APT33's consistent focus and its documented links to SHAMOON, which has been used to destroy data and disrupt operations at energy companies.

The attackers first obtained or guessed valid email credentials, then used a public tool called RULER to exploit Microsoft Exchange features — either creating malicious email rules that automatically downloaded and ran malware, or modifying a victim's Outlook homepage to silently execute code every time Outlook opened. This gave the attackers a persistent foothold that survived reboots. From there they installed a series of backdoors, starting with publicly available tools like PUPYRAT and PoshC2, and eventually deploying POWERTON — their own custom PowerShell backdoor — which communicated with attacker servers using AES encryption to avoid detection. When defenders blocked them, they regained access through password spraying, testing common passwords against many accounts until one worked.

Engineering companies hold sensitive technical data — design schematics, operational processes, and proprietary systems — that has both intelligence value and potential use in preparing for destructive attacks against industrial infrastructure. The energy sector is particularly attractive because it aligns with Iran's strategic objectives around understanding and potentially influencing petrochemical production capacity in rival states. US federal agencies are high-priority targets for state-level intelligence collection. The breadth of APT33's targeting across government, finance, media, and education also suggests a broad intelligence collection mandate beyond any single sector.

Enforce multi-factor authentication on all Exchange and OWA access — this single control would have significantly disrupted this actor's repeated reentry via stolen credentials and password spraying. Patch CVE-2017-11774 and lock down Outlook homepage settings via Group Policy. Monitor for RULER activity: alert on Outlook processes making unexpected network connections, especially to WebDAV endpoints. Implement detection for PowerShell launched with encoding or execution bypass flags, and for WMIC remote process creation. Block the disclosed C2 IPs and domains, and apply hash-based endpoint detections for all 27 file hashes. Set up alerts for distributed low-frequency authentication failures against Exchange from external IPs, which are a strong indicator of password spraying.

About Affiliation
APT33
APT33 is an Iranian state-sponsored threat actor active since at least 2013, assessed by Mandiant to work at the behest of the Iranian government. The group focuses primarily on cyber espionage against organizations in the aerospace, aviation, energy, and defense sectors across the United States, Saudi Arabia, South Korea, and other countries. APT33 is known for spear phishing campaigns using job-recruitment lures and malicious .hta files, large-scale password spray operations, and the use of destructive malware. Microsoft tracks this cluster as Peach Sandstorm and previously as HOLMIUM.
View APT33's Insights