Shifting Domains: APT33's Evolving Network Infrastructure
- Actor Motivations: Espionage,Exfiltration
- Attack Vectors: Backdoor
- Attack Complexity: Low
- Threat Risk: High Impact/Low Probability
Threat Overview
ThreatConnect Research Team documents a brief infrastructure pivot observation: four APT33 C2 domains previously identified in Trend Micro's 2019 report on obfuscated APT33 botnets (zeverco[.]com, service-eset[.]com, simsoshop[.]com, qualitweb[.]com) began resolving to a new IP address, 109.230.199[.]157, starting in late July 2020. ThreatConnect explicitly notes that it is unknown whether this IP address is a sinkhole, a parking IP, or still under APT33's operational control, and whether the domains are still being used by APT33. Several additional domains not previously associated with APT33 also began resolving to the same IP during the same period: publicsecur[.]com, akadnsplugin[.]com (registrant: joshua.toon1978@mail[.]com), service-houston[.]com, support-newyork[.]com, and ocsp-support[.]com (registrant: warren.jones2626@mail[.]com). These additional domains were registered through THCservers, a suspicious reseller previously used by multiple state and criminal actors. ThreatConnect notes a possible further association between ocsp-support[.]com and two additional domains — prefmsedge[.]com and tracking-protection[.]net — based on reuse of the "Warren Jones" email address string in registrant data (registered through AminServe rather than THCservers). This is a brief infrastructure observation published as part of ThreatConnect's weekly Research Roundup; the same edition also covers unrelated RedDelta PlugX and Emotet activity. Attribution to APT33 for the newly identified domains remains unconfirmed.
Extracted IOCs
- akadnsplugin[.]com
- ocsp-support[.]com
- prefmsedge[.]com
- qualitweb[.]com
- service-eset[.]com
- simsoshop[.]com
- tracking-protection[.]net
- zeverco[.]com
- joshua.toon1978@mail[.]com
- oliverleftley@inbox[.]com
- tsuda2016@mail[.]com
- tsuyukisogawa@inbox[.]lv
- warren.jones2626@mail[.]com
- warrenjones39458@protonmail[.]com
- warren.jones6363@inbox[.]lv
- wata.nakatsu@mail[.]com
- 109[.]230.199.157
Tip: 17 related IOCs (1 IP, 8 domain, 0 URL, 8 email, 0 file hash) to this threat have been found.
Overlaps
Source: Trend Micro - November 2019
Detection (four cases): qualitweb[.]com, service-eset[.]com, simsoshop[.]com, zeverco[.]com
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
Frequently Asked Questions: APT33 Domain Infrastructure Shift — 2020 Update
ThreatConnect's Research Team noticed that four APT33 C2 domains previously identified by Trend Micro in their 2019 report — zeverco[.]com, service-eset[.]com, simsoshop[.]com, and qualitweb[.]com — started resolving to a new IP address (109.230.199[.]157) in late July 2020. The observation raises a question about whether APT33 is actively using this new IP, or whether the domains have been sinkholed by a security researcher or ISP.
The four domains shifting to the new IP were previously attributed to APT33 by Trend Micro. APT33, also known as Elfin or Refined Kitten, is an Iranian state-linked cyberespionage group known for targeting oil, gas, aviation, and national security organizations. ThreatConnect explicitly notes that attribution of the new IP and additional co-resolving domains to APT33 is unconfirmed — the IP may be a sinkhole operated by a third party.
ThreatConnect does not confirm whether 109.230.199[.]157 is still under APT33's control. It may be a sinkhole or parking IP operated by a security researcher or registrar. If it is a sinkhole, then connections to this IP from endpoints in your environment would still be significant — they would indicate machines with APT33 malware installed that are still beaconing to old C2 domains, giving you an opportunity to detect and remediate previously missed infections.
ThreatConnect identified five additional domains also resolving to the same IP: publicsecur[.]com, akadnsplugin[.]com, service-houston[.]com, support-newyork[.]com, and ocsp-support[.]com. Some were registered through THCservers, a domain registrar with a known history of use by state and criminal actors. Their connection to APT33 is unconfirmed. A further two domains — prefmsedge[.]com and tracking-protection[.]net — are linked to ocsp-support[.]com through shared registrant email strings using the name "Warren Jones," though registered through a different registrar (AminServe).
The same four APT33 domains that shifted to this IP were previously tracked in Trend Micro's 2019 report on APT33's obfuscated C2 infrastructure, which documented a multi-layer botnet model with cloud-hosted proxies, shared webserver backends, and private VPN exit nodes used for extremely narrow targeting. The domain shift in 2020 may reflect either continued operations under new infrastructure or the domains being taken over or sinkholed after public disclosure.
Monitor your network logs for any outbound connections to 109.230.199[.]157 and to all domains in the IOC bundle. Even if the IP is a sinkhole, live connections would reveal active APT33 infections. Block the four known APT33 domains as a minimum. Treat the additional co-resolving domains with caution and add them to watchlists. Cross-reference your logs against the broader APT33 IOC set documented in the related Trend Micro report — the 21 VPN exit node IPs and original 11 C2 domains are the higher-confidence indicators to prioritize.
This is a brief infrastructure pivot observation — a single paragraph published as part of ThreatConnect's weekly Research Roundup newsletter alongside unrelated Emotet and RedDelta items. It documents a DNS change and raises attribution questions without resolving them. Its value is as an indicator update: organizations already monitoring APT33 IOCs should add 109.230.199[.]157 to their watchlists and note the co-resolving domains for further investigation.
APT33 is a persistent Iranian state-aligned threat group with a long documented history of targeting oil, gas, aerospace, and national security organizations. Tracking their infrastructure shifts is valuable even when attribution of a specific IP is uncertain — the pattern of domain movement, registrar use, and co-resolving infrastructure helps analysts maintain an up-to-date picture of APT33's operational footprint and identify early indicators of renewed activity. Infrastructure tracking reports like this one are a standard part of continuous threat intelligence for organizations in APT33's target sectors.