APT33: Leveraging Known Vulnerabilities in U.S. Industry Attacks
- Actor Motivations: Espionage,Sabotage
- Attack Vectors: Vulnerability Exploitation,Malware,Spear Phishing
- Attack Complexity: Medium
- Threat Risk: High Impact/Low Probability
Threat Overview
HYAS provides a July 2020 update on APT33 activity during the COVID-19 pandemic, a period during which public attention to Iranian threat groups had diminished despite continued operations. APT33 — also known as Refined Kitten, Magnallium, and Holmium — maintained its infrastructure-building tempo throughout the pandemic, with HYAS identifying new suspicious domain registrations consistent with prior APT33 TTPs over a 90-day monitoring window. The group continued targeting US organizations in the aviation, petrochemical, and defense contractor sectors using multi-stage attacks: weaponized documents, exploitation of the Microsoft Outlook vulnerability CVE-2017-11774, and PowerShell backdoors delivered from domains mimicking legitimate business services. A key example — customermgmt[.]net — was publicly confirmed by US Cyber Command in July 2019 as an active APT33 malware delivery point. The report contextualizes this activity against escalating Iran-West tensions: the collapse of the Iran nuclear deal, the January 2020 assassination of Qasem Soleimani, and the subsequent downing of a civilian aircraft near Tehran.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Sector | Defense None | Verified |
| Sector | Aerospace None | Verified |
| Sector | Oil and Gas None | Verified |
| Region | United States | Verified |
Exploited Vulnerabilities
Extracted IOCs
- adminprofessional[.]net
- customermgmt[.]net
- mgntdesk[.]com
- signin-accounts[.]com
- systemsupports[.]net
Tip: 5 related IOCs (0 IP, 5 domain, 0 URL, 0 email, 0 file hash) to this threat have been found.
Overlaps
Source: Google Cloud - May 2024
Detection (one case): signin-accounts[.]com
Source: Hyas - September 2019
Detection (one case): customermgmt[.]net
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
Frequently Asked Questions
During the COVID-19 pandemic in 2020, APT33 — an Iranian state-aligned hacking group — continued actively targeting US organizations in the aviation, petrochemical, and defense contractor sectors. While public attention had shifted to the pandemic, HYAS Threat Intelligence tracked a 90-day window of new APT33 infrastructure registrations, confirming the group maintained its operational tempo. Attacks used weaponized documents, a known Microsoft Outlook vulnerability, and PowerShell backdoors.
APT33 is an Iranian state-aligned threat group, also tracked as Refined Kitten, Magnallium, and Holmium. The group has been operating since at least 2013 and is linked to the Iranian government. Multiple intelligence firms — including HYAS and ThreatConnect — attributed this infrastructure activity to APT33, consistent with US Cyber Command's July 2019 public confirmation of the group's use of the same domains and vulnerability.
The campaign serves dual purposes: intelligence gathering from strategically important US industries, and pre-positioning for potential sabotage — consistent with APT33's documented history of destructive operations including the Shamoon wiper campaigns. The sustained activity during a period of heightened Iran-US tensions suggests the group was maintaining readiness for escalation if geopolitical conditions warranted it.
The campaign focused on US organizations, with the aviation, petrochemical, and defense contractor sectors as the primary targets. This reflects APT33's consistent strategic interest in industries tied to Iran's economic and military rivalries with the United States. HYAS identified five domains linked to this activity, with overlap confirmed against prior APT33 infrastructure tracking reports.
US companies in aviation, petrochemical (oil and gas), and defense contracting were the named targets. These sectors have been consistent APT33 priorities across multiple campaign cycles dating back to at least 2013, reflecting Iran's strategic interest in disrupting or monitoring US capabilities in energy and defense supply chains.
APT33 used multi-stage attacks: victims first received spear-phishing emails containing weaponized documents or links that exploited CVE-2017-11774, a vulnerability in Microsoft Outlook, to execute malicious code. Once inside the network, PowerShell backdoors were deployed to maintain access and enable follow-on activity. All attack infrastructure — including delivery and command-and-control domains — was registered to look like legitimate business services, making them harder to flag without dedicated threat intelligence.
Aviation and defense companies hold sensitive technology, supply chain data, and military contract information that is directly valuable to Iranian intelligence. Petrochemical and oil and gas firms are critical to global energy markets, and disrupting or monitoring them aligns with Iran's economic and geopolitical leverage goals. APT33's consistent focus on these sectors over many years reflects deliberate strategic prioritization by the Iranian state.
Patch CVE-2017-11774 immediately if not already done — APT33 exploited this 2017 vulnerability for years against organizations that had not applied Microsoft's fix. Block the known APT33 domains at DNS and proxy layers. Monitor Microsoft Outlook for unusual child process activity as an indicator of exploitation. Alert on PowerShell being launched by Office applications, especially with obfuscated arguments. Organizations in aviation, oil and gas, and defense should conduct APT33-specific threat hunting and not assume reduced pandemic-era news coverage translates to reduced threat activity.