Threats Feed|APT33|Last Updated 30/04/2026|AuthorCertfa Radar|Publish Date30/03/2023

Cyber Threats on the Rise: APT33 Targets Aerospace, Shipping, and Manufacturing via OneNote

  • Actor Motivations: Espionage,Exfiltration
  • Attack Vectors: Backdoor,Malware,RAT,Spear Phishing
  • Attack Complexity: Medium
  • Threat Risk: High Impact/Low Probability

Threat Overview

Loginsoft's March 2023 report examines the broader OneNote malware delivery campaign, within which APT33 is identified as one of several threat actors exploiting Microsoft OneNote files to deliver malware payloads. The campaign emerged after Microsoft disabled malicious macro execution in Office documents, prompting attackers to pivot to OneNote notebooks as a new delivery vehicle. APT33 used this method to target organizations in the aerospace, shipping, and manufacturing sectors, embedding malicious files or URLs within OneNote pages hidden behind counterfeit clickable buttons — tricking victims into triggering payload execution. The malware families associated with the broader campaign include commodity RATs and stealers such as NETWIRE, Quasar RAT, AsyncRAT, XWorm, Formbook, Agent Tesla, RedLine Stealer, IcedID, QakBot, Emotet, and the APT33-linked DOUBLEBACK backdoor. The technique chain involved spearphishing attachment delivery, obfuscated embedded payloads, process injection, and proxy execution via Windows LOLBins including mshta.exe, rundll32.exe, and regsvcs/regasm to evade defenses. Note: the original source URL is no longer accessible; content is reconstructed from the archived feed description and threat record.

Detected Targets

TypeDescriptionConfidence
SectorDefense
Verified
SectorManufacturing
Verified
SectorTransportation
Verified

Extracted IOCs

  • 4283f36c5dd58523ead73e5c89f3b8d2
  • 72062a06e73f3c2d931c27d677c0334b7c962e26
  • 8bfd499350dc36e9ad85f70e01249bb917dfe4002d07c8fca7a780a1a4b2c6c7
download

Tip: 3 related IOCs (0 IP, 0 domain, 0 URL, 0 email, 3 file hash) to this threat have been found.

FAQs

Frequently Asked Questions About APT33's OneNote Malware Campaign

APT33 exploited Microsoft OneNote files as a malware delivery mechanism to target organizations in the aerospace, shipping, and manufacturing sectors. The group embedded malicious payloads inside OneNote notebooks disguised with fake buttons, tricking users into executing malware. This campaign emerged in late 2022 and early 2023 after Microsoft disabled Office macro execution by default, forcing threat actors to find new delivery methods.

The campaign is attributed to APT33, an Iranian state-sponsored threat group with a documented history of targeting aerospace, energy, and manufacturing organizations. APT33 is one of several threat actors — including both criminal and state-linked groups — observed adopting the OneNote delivery technique in this period. The group's use of the DOUBLEBACK backdoor, previously linked to APT33, is among the indicators supporting this attribution.

The primary goals were intelligence gathering and data theft from strategic sectors. APT33 targeted aerospace, shipping, and manufacturing companies — industries aligned with Iran's national interests in military aviation and logistics. Malware deployed in the campaign gave attackers remote access to victim systems, enabling credential theft, file exfiltration, and persistent surveillance.

The OneNote campaign was widespread, with multiple threat actors targeting organizations globally. APT33's specific targeting focused on aerospace, shipping, and manufacturing sectors. The technique itself was adopted broadly across the threat landscape in late 2022 and early 2023, making it a risk for any organization whose employees receive external email with file attachments.

APT33 specifically targeted the aerospace, shipping (transportation), and manufacturing sectors. These industries are of consistent interest to Iran-linked actors seeking intelligence on military aviation capabilities, supply chain logistics, and industrial production. Employees in these sectors receiving unsolicited OneNote files via email were the primary targets.

Attackers sent phishing emails with malicious OneNote (.one) file attachments. Inside the notebook, a fake button or image was displayed, prompting the victim to click it. Clicking the element triggered a hidden embedded file or script — often a VBScript, JavaScript, or PowerShell payload — that downloaded and executed the actual malware. The attack then used Windows system tools like mshta.exe and rundll32.exe to run the payload while evading security controls, and injected malicious code into legitimate processes to maintain stealth.

Aerospace and manufacturing companies hold proprietary data on aviation technology, production processes, and supply chains — all of direct intelligence value to Iran. Shipping and transportation companies provide insight into logistics networks that may support military or economic planning. The shift to OneNote as a delivery method also reflects a tactical advantage: many organizations had trained employees to be wary of Office macro documents, but OneNote files were a newer and less-recognized threat at the time.

Block OneNote (.one) files from being delivered via external email, or quarantine them for review — most organizations have no legitimate need to receive them from outside senders. Enable Microsoft Defender attack surface reduction rules to prevent Office applications from launching child processes or running executable content. Restrict mshta.exe, rundll32.exe, and script interpreters from being launched by document applications. Train employees to be suspicious of any file that asks them to "click here" or interact with buttons to unlock content. Keep endpoint protection updated with signatures for commodity RATs such as AsyncRAT, XWorm, NETWIRE, and Quasar.

About Affiliation
APT33
APT33 is an Iranian state-sponsored threat actor active since at least 2013, assessed by Mandiant to work at the behest of the Iranian government. The group focuses primarily on cyber espionage against organizations in the aerospace, aviation, energy, and defense sectors across the United States, Saudi Arabia, South Korea, and other countries. APT33 is known for spear phishing campaigns using job-recruitment lures and malicious .hta files, large-scale password spray operations, and the use of destructive malware. Microsoft tracks this cluster as Peach Sandstorm and previously as HOLMIUM.
View APT33's Insights