Cyber Espionage on Aviation: APT33 Targets US, Saudi Arabia, and South Korea
- Actor Motivations: Espionage,Exfiltration
- Attack Vectors: Vulnerability Exploitation,Backdoor,RAT,Spear Phishing
- Attack Complexity: High
- Threat Risk: High Impact/Low Probability
Threat Overview
Mandiant's September 2017 report provides the foundational profile of APT33, an Iranian state-sponsored espionage group active since at least 2013. The group targeted organizations in the United States, Saudi Arabia, and South Korea, with a strong focus on the aerospace and energy sectors — particularly companies with military aviation ties and petrochemical production. Between mid-2016 and early 2017, APT33 compromised a U.S. aerospace organization and targeted Saudi and South Korean conglomerates with aviation and oil refining operations. Intrusions began with spearphishing emails carrying malicious HTML Application (.hta) files disguised as aviation job postings, sent via the publicly available ALFA TEaM Shell. APT33 registered lookalike domains impersonating Boeing, Alsalam Aircraft Company, Northrop Grumman Aviation Arabia, and Vinnell Arabia to lend credibility to phishing lures. The group's primary backdoor, TURNEDUP, was deployed via the DROPSHOT dropper; commodity RATs including NANOCORE and NETWIRE were also used. Mandiant also identified links between DROPSHOT and the SHAPESHIFT disk-wiping malware, raising concerns about APT33's potential for destructive operations. Attacker activity aligned with Iranian working hours (UTC+4:30) and the Iranian Saturday-to-Wednesday workweek, supporting attribution to Iran.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Case | Alsalam Aerospace Industries Alsalam Aerospace Industries is a company based in Riyadh, Saudi Arabia, that provides aircraft maintenance, repair, and overhaul (MRO) services. Alsalam Aerospace Industries has been targeted by APT33 with abusive purposes. | Verified |
| Case | Boeing The Boeing Company is an American multinational corporation that designs, manufactures, and sells airplanes, rotorcraft, rockets, satellites, telecommunications equipment, and missiles worldwide. The company also provides leasing and product support services. Boeing has been targeted by APT33 with abusive purposes. | Verified |
| Case | Northrop Grumman Northrop Grumman Corporation is an American multinational aerospace and defense technology company. Northrop Grumman has been targeted by APT33 with abusive purposes. | Verified |
| Case | Vinnell Arabia Vinnell Arabia LLC is a knowledge-transfer company, wholly-owned by Northrop Grumman Corporation (NGC), that delivers a broad range of military and non-military services to the government and private sectors within the Kingdom of Saudi Arabia. Vinnell Arabia has been targeted by APT33 with abusive purposes. | Verified |
| Sector | Defense | Verified |
| Sector | Military | Verified |
| Sector | Utilities | Verified |
| Region | Saudi Arabia | Verified |
| Region | South Korea | Verified |
| Region | United States | Verified |
Extracted IOCs
- googlmail[.]net
- managehelpdesk[.]com
- microsoftupdated[.]com
- microsoftupdated[.]net
- osupd[.]com
- alsalam.ddns[.]net
- boeing.servehttp[.]com
- mywinnetwork.ddns[.]net
- ngaaksa.ddns[.]net
- ngaaksa.sytes[.]net
- syn.broadcaster[.]rocks
- vinnellarabia.myftp[.]org
- www.chromup[.]com
- www.googlmail[.]net
- www.securityupdated[.]com
- solevisible@gmail[.]com
- 0753857710dcf96b950e07df9cdf7911
- 0ccc9ec82f1d44c243329014b82d3125
- 10f58774cd52f71cd4438547c39b1aa7
- 1381148d543c0de493b13ba8ca17c14f
- 32a9a9aa9a81be6186937b99e04ad4be
- 3e8a4d654d5baa99f8913d8e2bd8a184
- 3f5329cf2a829f8840ba6a903f17a1bf
- 59d0d27360c9534d55596891049eb3ef
- 663c18cfcedd90a3c91a09478f1e91bc
- 6a0f07e322d3b7bc88e2468f9e4b861b
- 6b41980aa6966dda6c3f68aeeb9ae2e0
- 6f1d5c57b3b415edc3767b079999dd50
- 797bc06d3e0f5891591b68885d99b4e1
- 8e67f4c98754a2373a49eaf53425d79a
- 8e6d5ef3f6912a7c49f8eb6a71e18ee2
- a272326cb5f0b73eb9a42c9e629a0fd8
- a2af2e6bbb6551ddf09f0a7204b5952e
- a80c7ce33769ada7b4d56733d02afbe5
- a813dd6b81db331f10efaf1173f1da5d
- aa63b16b6bf326dd3b4e82ffad4c1338
- ae47d53fe8ced620e9969cea58e87d9a
- ae870c46f3b8f44e576ffa1528c3ea37
- b12faab84e2140dfa5852411c91a3474
- b189b21aafd206625e6c4e4a42c8ba76
- b3d73364995815d78f6d66101e718837
- b5f69841bf4e0e96a99aa811b52d0e90
- b681aa600be5e3ca550d4ff4c884dc3d
- bbdd6bb2e8827e64cd1a440e05c0d537
- c02689449a4ce73ec79a52595ab590f6
- c2d472bdb8b98ed83cc8ded68a79c425
- c2fbb3ac76b0839e0a744ad8bdddba0e
- c55b002ae9db4dbb2992f7ef0fbc86cb
- c57c5529d91cffef3ec8dadf61c5ffb2
- c66422d3a9ebe5f323d29a7be76bc57a
- c6f2f502ad268248d6c0087a2538cad0
- d01781f1246fd1b64e09170bd6600fe1
- de7a44518d67b13cda535474ffedf36b
- de9e3b4124292b4fba0c5284155fa317
- fb21f3cea1aa051ba2a45e75d46b98b8
Tip: 55 related IOCs (0 IP, 15 domain, 0 URL, 1 email, 39 file hash) to this threat have been found.
Overlaps
Source: DomainTools - December 2019
Detection (two cases): microsoftupdated[.]net, osupd[.]com
Source: Symantec - March 2019
Detection (two cases): microsoftupdated[.]com, mywinnetwork.ddns[.]net
Source: Megabeets - May 2018
Detection (one case): 0ccc9ec82f1d44c243329014b82d3125
Source: Kaspersky - March 2017
Detection (five cases): 0ccc9ec82f1d44c243329014b82d3125, 8e67f4c98754a2373a49eaf53425d79a, fb21f3cea1aa051ba2a45e75d46b98b8, www.chromup[.]com, www.securityupdated[.]com
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
Frequently Asked Questions About the APT33 Aerospace and Energy Espionage Campaign
APT33, an Iranian state-sponsored hacking group, conducted a sustained cyber espionage campaign targeting organizations in the United States, Saudi Arabia, and South Korea. The group focused on the aerospace and energy sectors, breaking into networks via job-lure spearphishing emails to steal intelligence on military aviation capabilities and petrochemical operations. Mandiant researchers documented the campaign in September 2017, identifying compromises dating back to at least 2016.
APT33, an Iranian state-sponsored hacking group, conducted a sustained cyber espionage campaign targeting organizations in the United States, Saudi Arabia, and South Korea. The group focused on the aerospace and energy sectors, breaking into networks via job-lure spearphishing emails to steal intelligence on military aviation capabilities and petrochemical operations. Mandiant researchers documented the campaign in September 2017, identifying compromises dating back to at least 2016.
The attacks are attributed to APT33, a threat group Mandiant assesses to work on behalf of the Iranian government. Evidence supporting this includes the group's use of tools and DNS servers associated with Iranian hacker communities, attacker activity hours consistent with Iran's UTC+4:30 time zone, and a Saturday-to-Wednesday workweek matching Iran's government schedule. A developer handle found in TURNEDUP malware samples was also linked to Iran's "Nasr Institute," reportedly tied to Iran's cyber operations infrastructure.
The primary goal was intelligence collection — gaining insight into Saudi Arabia's military aviation capabilities, Iran's regional rivals, and the petrochemical industry. APT33 also had potential destructive capability: the DROPSHOT dropper it used has been linked to SHAPESHIFT, a disk-wiping malware that can destroy data on infected systems. While destructive use was not directly observed in this campaign, the connection raises concern about the group's broader intent.
The campaign targeted organizations across three countries — the United States, Saudi Arabia, and South Korea. Known victims include a U.S. aerospace company, a Saudi business conglomerate with aviation holdings, and a South Korean oil refining and petrochemicals company. APT33 registered spoofed domains impersonating four major defense and aviation firms — Boeing, Alsalam Aircraft Company, Northrop Grumman Aviation Arabia, and Vinnell Arabia — and sent hundreds of spearphishing emails to aviation-sector employees.
APT33 focused specifically on the aerospace and energy sectors. Within aerospace, the group targeted both military and commercial aviation organizations, including firms involved in aircraft maintenance, training, and Saudi Arabia's rotorcraft fleet. In energy, it focused on petrochemical companies — particularly those with ties to Saudi Arabia — likely to benefit Iran's own ambitions to expand petrochemical production and compete regionally. Employees in aviation-related roles were the primary recipients of spearphishing emails.
APT33 sent targeted emails to aviation employees that appeared to be legitimate job postings — complete with specific salary details, links to spoofed company websites, and equal opportunity hiring statements. Each email contained a link to a malicious .hta (HTML Application) file. When opened, the file displayed plausible job content while silently downloading the TURNEDUP backdoor in the background. The DROPSHOT dropper staged and launched the backdoor, giving attackers persistent remote access to compromised machines.
Saudi Arabia is Iran's primary regional rival, and its military aviation capabilities and petrochemical industry are of direct strategic interest to Iran. The U.S. organizations targeted had defense and aviation partnerships with Saudi Arabia, making them valuable intelligence targets. South Korean companies were likely targeted due to their partnerships with both Iran's and Saudi Arabia's petrochemical sectors. Mandiant assesses APT33 may be trying to enhance Iran's aviation capabilities and support military decision-making against regional adversaries.
Block or flag .hta file execution across endpoints — it is rarely needed for legitimate use and is a known APT33 delivery mechanism. Train staff to recognize aviation job-lure phishing, even when emails appear highly professional and reference real companies. Block DDNS domains (ddns.net, sytes.net, myftp.org, servehttp.com) at the network level and monitor for connections to lookalike domains impersonating Boeing, Northrop Grumman, or similar defense brands. Maintain offline backups of critical systems given APT33's links to disk-wiping malware, and deploy EDR tools capable of detecting TURNEDUP and DROPSHOT behavioral patterns.