Threats Feed|APT33|Last Updated 01/05/2026|AuthorCertfa Radar|Publish Date01/07/2020

APT33: Leveraging Known Vulnerabilities in U.S. Industry Attacks

  • Actor Motivations: Espionage,Sabotage
  • Attack Vectors: Vulnerability Exploitation,Malware,Spear Phishing
  • Attack Complexity: Medium
  • Threat Risk: High Impact/Low Probability

Threat Overview

HYAS provides a July 2020 update on APT33 activity during the COVID-19 pandemic, a period during which public attention to Iranian threat groups had diminished despite continued operations. APT33 — also known as Refined Kitten, Magnallium, and Holmium — maintained its infrastructure-building tempo throughout the pandemic, with HYAS identifying new suspicious domain registrations consistent with prior APT33 TTPs over a 90-day monitoring window. The group continued targeting US organizations in the aviation, petrochemical, and defense contractor sectors using multi-stage attacks: weaponized documents, exploitation of the Microsoft Outlook vulnerability CVE-2017-11774, and PowerShell backdoors delivered from domains mimicking legitimate business services. A key example — customermgmt[.]net — was publicly confirmed by US Cyber Command in July 2019 as an active APT33 malware delivery point. The report contextualizes this activity against escalating Iran-West tensions: the collapse of the Iran nuclear deal, the January 2020 assassination of Qasem Soleimani, and the subsequent downing of a civilian aircraft near Tehran.

Detected Targets

TypeDescriptionConfidence
SectorDefense
None
Verified
SectorAerospace
None
Verified
SectorOil and Gas
None
Verified
RegionUnited States
Verified

Exploited Vulnerabilities

Extracted IOCs

  • adminprofessional[.]net
  • customermgmt[.]net
  • mgntdesk[.]com
  • signin-accounts[.]com
  • systemsupports[.]net
download

Tip: 5 related IOCs (0 IP, 5 domain, 0 URL, 0 email, 0 file hash) to this threat have been found.

Overlaps

APT42APT42: Iranian Cyber Espionage Campaign Targets Global NGO and Media Sectors

Source: Google Cloud - May 2024

Detection (one case): signin-accounts[.]com

APT33APT33 Expands its Cyberattack Scope Beyond the Middle East

Source: Hyas - September 2019

Detection (one case): customermgmt[.]net

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

Frequently Asked Questions

During the COVID-19 pandemic in 2020, APT33 — an Iranian state-aligned hacking group — continued actively targeting US organizations in the aviation, petrochemical, and defense contractor sectors. While public attention had shifted to the pandemic, HYAS Threat Intelligence tracked a 90-day window of new APT33 infrastructure registrations, confirming the group maintained its operational tempo. Attacks used weaponized documents, a known Microsoft Outlook vulnerability, and PowerShell backdoors.

APT33 is an Iranian state-aligned threat group, also tracked as Refined Kitten, Magnallium, and Holmium. The group has been operating since at least 2013 and is linked to the Iranian government. Multiple intelligence firms — including HYAS and ThreatConnect — attributed this infrastructure activity to APT33, consistent with US Cyber Command's July 2019 public confirmation of the group's use of the same domains and vulnerability.

The campaign serves dual purposes: intelligence gathering from strategically important US industries, and pre-positioning for potential sabotage — consistent with APT33's documented history of destructive operations including the Shamoon wiper campaigns. The sustained activity during a period of heightened Iran-US tensions suggests the group was maintaining readiness for escalation if geopolitical conditions warranted it.

The campaign focused on US organizations, with the aviation, petrochemical, and defense contractor sectors as the primary targets. This reflects APT33's consistent strategic interest in industries tied to Iran's economic and military rivalries with the United States. HYAS identified five domains linked to this activity, with overlap confirmed against prior APT33 infrastructure tracking reports.

US companies in aviation, petrochemical (oil and gas), and defense contracting were the named targets. These sectors have been consistent APT33 priorities across multiple campaign cycles dating back to at least 2013, reflecting Iran's strategic interest in disrupting or monitoring US capabilities in energy and defense supply chains.

APT33 used multi-stage attacks: victims first received spear-phishing emails containing weaponized documents or links that exploited CVE-2017-11774, a vulnerability in Microsoft Outlook, to execute malicious code. Once inside the network, PowerShell backdoors were deployed to maintain access and enable follow-on activity. All attack infrastructure — including delivery and command-and-control domains — was registered to look like legitimate business services, making them harder to flag without dedicated threat intelligence.

Aviation and defense companies hold sensitive technology, supply chain data, and military contract information that is directly valuable to Iranian intelligence. Petrochemical and oil and gas firms are critical to global energy markets, and disrupting or monitoring them aligns with Iran's economic and geopolitical leverage goals. APT33's consistent focus on these sectors over many years reflects deliberate strategic prioritization by the Iranian state.

Patch CVE-2017-11774 immediately if not already done — APT33 exploited this 2017 vulnerability for years against organizations that had not applied Microsoft's fix. Block the known APT33 domains at DNS and proxy layers. Monitor Microsoft Outlook for unusual child process activity as an indicator of exploitation. Alert on PowerShell being launched by Office applications, especially with obfuscated arguments. Organizations in aviation, oil and gas, and defense should conduct APT33-specific threat hunting and not assume reduced pandemic-era news coverage translates to reduced threat activity.

About Affiliation
APT33
APT33 is an Iranian state-sponsored threat actor active since at least 2013, assessed by Mandiant to work at the behest of the Iranian government. The group focuses primarily on cyber espionage against organizations in the aerospace, aviation, energy, and defense sectors across the United States, Saudi Arabia, South Korea, and other countries. APT33 is known for spear phishing campaigns using job-recruitment lures and malicious .hta files, large-scale password spray operations, and the use of destructive malware. Microsoft tracks this cluster as Peach Sandstorm and previously as HOLMIUM.
View APT33's Insights