Threats Feed|APT33|Last Updated 30/04/2026|AuthorCertfa Radar|Publish Date20/09/2017

Cyber Espionage on Aviation: APT33 Targets US, Saudi Arabia, and South Korea

  • Actor Motivations: Espionage,Exfiltration
  • Attack Vectors: Vulnerability Exploitation,Backdoor,RAT,Spear Phishing
  • Attack Complexity: High
  • Threat Risk: High Impact/Low Probability

Threat Overview

Mandiant's September 2017 report provides the foundational profile of APT33, an Iranian state-sponsored espionage group active since at least 2013. The group targeted organizations in the United States, Saudi Arabia, and South Korea, with a strong focus on the aerospace and energy sectors — particularly companies with military aviation ties and petrochemical production. Between mid-2016 and early 2017, APT33 compromised a U.S. aerospace organization and targeted Saudi and South Korean conglomerates with aviation and oil refining operations. Intrusions began with spearphishing emails carrying malicious HTML Application (.hta) files disguised as aviation job postings, sent via the publicly available ALFA TEaM Shell. APT33 registered lookalike domains impersonating Boeing, Alsalam Aircraft Company, Northrop Grumman Aviation Arabia, and Vinnell Arabia to lend credibility to phishing lures. The group's primary backdoor, TURNEDUP, was deployed via the DROPSHOT dropper; commodity RATs including NANOCORE and NETWIRE were also used. Mandiant also identified links between DROPSHOT and the SHAPESHIFT disk-wiping malware, raising concerns about APT33's potential for destructive operations. Attacker activity aligned with Iranian working hours (UTC+4:30) and the Iranian Saturday-to-Wednesday workweek, supporting attribution to Iran.

Detected Targets

TypeDescriptionConfidence
CaseAlsalam Aerospace Industries
Alsalam Aerospace Industries is a company based in Riyadh, Saudi Arabia, that provides aircraft maintenance, repair, and overhaul (MRO) services. Alsalam Aerospace Industries has been targeted by APT33 with abusive purposes.
Verified
CaseBoeing
The Boeing Company is an American multinational corporation that designs, manufactures, and sells airplanes, rotorcraft, rockets, satellites, telecommunications equipment, and missiles worldwide. The company also provides leasing and product support services. Boeing has been targeted by APT33 with abusive purposes.
Verified
CaseNorthrop Grumman
Northrop Grumman Corporation is an American multinational aerospace and defense technology company. Northrop Grumman has been targeted by APT33 with abusive purposes.
Verified
CaseVinnell Arabia
Vinnell Arabia LLC is a knowledge-transfer company, wholly-owned by Northrop Grumman Corporation (NGC), that delivers a broad range of military and non-military services to the government and private sectors within the Kingdom of Saudi Arabia. Vinnell Arabia has been targeted by APT33 with abusive purposes.
Verified
SectorDefense
Verified
SectorMilitary
Verified
SectorUtilities
Verified
RegionSaudi Arabia
Verified
RegionSouth Korea
Verified
RegionUnited States
Verified

Extracted IOCs

  • googlmail[.]net
  • managehelpdesk[.]com
  • microsoftupdated[.]com
  • microsoftupdated[.]net
  • osupd[.]com
  • alsalam.ddns[.]net
  • boeing.servehttp[.]com
  • mywinnetwork.ddns[.]net
  • ngaaksa.ddns[.]net
  • ngaaksa.sytes[.]net
  • syn.broadcaster[.]rocks
  • vinnellarabia.myftp[.]org
  • www.chromup[.]com
  • www.googlmail[.]net
  • www.securityupdated[.]com
  • solevisible@gmail[.]com
  • 0753857710dcf96b950e07df9cdf7911
  • 0ccc9ec82f1d44c243329014b82d3125
  • 10f58774cd52f71cd4438547c39b1aa7
  • 1381148d543c0de493b13ba8ca17c14f
  • 32a9a9aa9a81be6186937b99e04ad4be
  • 3e8a4d654d5baa99f8913d8e2bd8a184
  • 3f5329cf2a829f8840ba6a903f17a1bf
  • 59d0d27360c9534d55596891049eb3ef
  • 663c18cfcedd90a3c91a09478f1e91bc
  • 6a0f07e322d3b7bc88e2468f9e4b861b
  • 6b41980aa6966dda6c3f68aeeb9ae2e0
  • 6f1d5c57b3b415edc3767b079999dd50
  • 797bc06d3e0f5891591b68885d99b4e1
  • 8e67f4c98754a2373a49eaf53425d79a
  • 8e6d5ef3f6912a7c49f8eb6a71e18ee2
  • a272326cb5f0b73eb9a42c9e629a0fd8
  • a2af2e6bbb6551ddf09f0a7204b5952e
  • a80c7ce33769ada7b4d56733d02afbe5
  • a813dd6b81db331f10efaf1173f1da5d
  • aa63b16b6bf326dd3b4e82ffad4c1338
  • ae47d53fe8ced620e9969cea58e87d9a
  • ae870c46f3b8f44e576ffa1528c3ea37
  • b12faab84e2140dfa5852411c91a3474
  • b189b21aafd206625e6c4e4a42c8ba76
  • b3d73364995815d78f6d66101e718837
  • b5f69841bf4e0e96a99aa811b52d0e90
  • b681aa600be5e3ca550d4ff4c884dc3d
  • bbdd6bb2e8827e64cd1a440e05c0d537
  • c02689449a4ce73ec79a52595ab590f6
  • c2d472bdb8b98ed83cc8ded68a79c425
  • c2fbb3ac76b0839e0a744ad8bdddba0e
  • c55b002ae9db4dbb2992f7ef0fbc86cb
  • c57c5529d91cffef3ec8dadf61c5ffb2
  • c66422d3a9ebe5f323d29a7be76bc57a
  • c6f2f502ad268248d6c0087a2538cad0
  • d01781f1246fd1b64e09170bd6600fe1
  • de7a44518d67b13cda535474ffedf36b
  • de9e3b4124292b4fba0c5284155fa317
  • fb21f3cea1aa051ba2a45e75d46b98b8
download

Tip: 55 related IOCs (0 IP, 15 domain, 0 URL, 1 email, 39 file hash) to this threat have been found.

Overlaps

GreenbugDecoding Greenbug Group's Command and Control Communications via DNS Tunneling

Source: DomainTools - December 2019

Detection (two cases): microsoftupdated[.]net, osupd[.]com

ElfinThe Elfin Threat: Customized Malware Attacks Across Diverse Sectors

Source: Symantec - March 2019

Detection (two cases): microsoftupdated[.]com, mywinnetwork.ddns[.]net

APT33APT33's Dropshot Malware: Advanced Evasion Techniques Unveiled

Source: Megabeets - May 2018

Detection (one case): 0ccc9ec82f1d44c243329014b82d3125

NewsBeefShamoon 2.0 and StoneDrill Revive Wiper Threats Across Saudi and European Targets

Source: Kaspersky - March 2017

Detection (five cases): 0ccc9ec82f1d44c243329014b82d3125, 8e67f4c98754a2373a49eaf53425d79a, fb21f3cea1aa051ba2a45e75d46b98b8, www.chromup[.]com, www.securityupdated[.]com

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

Frequently Asked Questions About the APT33 Aerospace and Energy Espionage Campaign

APT33, an Iranian state-sponsored hacking group, conducted a sustained cyber espionage campaign targeting organizations in the United States, Saudi Arabia, and South Korea. The group focused on the aerospace and energy sectors, breaking into networks via job-lure spearphishing emails to steal intelligence on military aviation capabilities and petrochemical operations. Mandiant researchers documented the campaign in September 2017, identifying compromises dating back to at least 2016.

APT33, an Iranian state-sponsored hacking group, conducted a sustained cyber espionage campaign targeting organizations in the United States, Saudi Arabia, and South Korea. The group focused on the aerospace and energy sectors, breaking into networks via job-lure spearphishing emails to steal intelligence on military aviation capabilities and petrochemical operations. Mandiant researchers documented the campaign in September 2017, identifying compromises dating back to at least 2016.

The attacks are attributed to APT33, a threat group Mandiant assesses to work on behalf of the Iranian government. Evidence supporting this includes the group's use of tools and DNS servers associated with Iranian hacker communities, attacker activity hours consistent with Iran's UTC+4:30 time zone, and a Saturday-to-Wednesday workweek matching Iran's government schedule. A developer handle found in TURNEDUP malware samples was also linked to Iran's "Nasr Institute," reportedly tied to Iran's cyber operations infrastructure.

The primary goal was intelligence collection — gaining insight into Saudi Arabia's military aviation capabilities, Iran's regional rivals, and the petrochemical industry. APT33 also had potential destructive capability: the DROPSHOT dropper it used has been linked to SHAPESHIFT, a disk-wiping malware that can destroy data on infected systems. While destructive use was not directly observed in this campaign, the connection raises concern about the group's broader intent.

The campaign targeted organizations across three countries — the United States, Saudi Arabia, and South Korea. Known victims include a U.S. aerospace company, a Saudi business conglomerate with aviation holdings, and a South Korean oil refining and petrochemicals company. APT33 registered spoofed domains impersonating four major defense and aviation firms — Boeing, Alsalam Aircraft Company, Northrop Grumman Aviation Arabia, and Vinnell Arabia — and sent hundreds of spearphishing emails to aviation-sector employees.

APT33 focused specifically on the aerospace and energy sectors. Within aerospace, the group targeted both military and commercial aviation organizations, including firms involved in aircraft maintenance, training, and Saudi Arabia's rotorcraft fleet. In energy, it focused on petrochemical companies — particularly those with ties to Saudi Arabia — likely to benefit Iran's own ambitions to expand petrochemical production and compete regionally. Employees in aviation-related roles were the primary recipients of spearphishing emails.

APT33 sent targeted emails to aviation employees that appeared to be legitimate job postings — complete with specific salary details, links to spoofed company websites, and equal opportunity hiring statements. Each email contained a link to a malicious .hta (HTML Application) file. When opened, the file displayed plausible job content while silently downloading the TURNEDUP backdoor in the background. The DROPSHOT dropper staged and launched the backdoor, giving attackers persistent remote access to compromised machines.

Saudi Arabia is Iran's primary regional rival, and its military aviation capabilities and petrochemical industry are of direct strategic interest to Iran. The U.S. organizations targeted had defense and aviation partnerships with Saudi Arabia, making them valuable intelligence targets. South Korean companies were likely targeted due to their partnerships with both Iran's and Saudi Arabia's petrochemical sectors. Mandiant assesses APT33 may be trying to enhance Iran's aviation capabilities and support military decision-making against regional adversaries.

Block or flag .hta file execution across endpoints — it is rarely needed for legitimate use and is a known APT33 delivery mechanism. Train staff to recognize aviation job-lure phishing, even when emails appear highly professional and reference real companies. Block DDNS domains (ddns.net, sytes.net, myftp.org, servehttp.com) at the network level and monitor for connections to lookalike domains impersonating Boeing, Northrop Grumman, or similar defense brands. Maintain offline backups of critical systems given APT33's links to disk-wiping malware, and deploy EDR tools capable of detecting TURNEDUP and DROPSHOT behavioral patterns.

About Affiliation
APT33
APT33 is an Iranian state-sponsored threat actor active since at least 2013, assessed by Mandiant to work at the behest of the Iranian government. The group focuses primarily on cyber espionage against organizations in the aerospace, aviation, energy, and defense sectors across the United States, Saudi Arabia, South Korea, and other countries. APT33 is known for spear phishing campaigns using job-recruitment lures and malicious .hta files, large-scale password spray operations, and the use of destructive malware. Microsoft tracks this cluster as Peach Sandstorm and previously as HOLMIUM.
View APT33's Insights