Cyber Espionage by APT33 Targets Education, National Security, and Oil Industries
- Actor Motivations: Espionage,Exfiltration
- Attack Vectors: Backdoor,Spear Phishing
- Attack Complexity: High
- Threat Risk: High Impact/Low Probability
Threat Overview
Trend Micro documents APT33's use of more than a dozen obfuscated C2 servers for extremely narrow targeting, with each botnet comprising only about 12 infected machines. The group runs a multi-layer C2 obfuscation chain: infected bots connect to cloud-hosted proxy domains, which relay traffic to shared webserver backends, which report to dedicated bot data aggregators and controllers — all administered by APT33 operators through a private VPN network with exit nodes rotated frequently. Trend Micro tracked 10 live bot aggregators in fall 2019 and 21 private VPN exit node IPs across late 2018 to late 2019, confirming sustained operations. Confirmed active victims in 2019 include two separate US national security services company locations, two US university victims, a US military-related victim, and multiple Middle East and Asia victims. Oil supply chain compromises confirmed in fall 2018 include a UK-based oil company with servers in the UK and India communicating with an APT33 C2, and a European oil company with an infected server in India for at least three weeks in November–December 2018. APT33 also used a high-ranking European politician's private website for at least two years to send spear phishing emails — with job-lure subjects spoofing aviation and oil companies including al-Salam Aircraft Company, NGAAKSA, DynCorp International, SIPCHEM, Saudi Aramco, and SAMREF — targeting oil supply chain companies including a US military water supply facility. The malware deployed (MsdUpdate.exe, DysonPart.exe — detected as NYMERIA/SCAR variants) is functionally basic: it establishes persistence and downloads additional payloads. All 11 C2 domains listed were registered in 2016–2017 and remained live at time of publication. The VPN exit nodes were also used for reconnaissance against oil exploration companies and military hospitals in the Middle East and a US oil company.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Sector | Military | Verified |
| Sector | Aerospace | Verified |
| Sector | Oil and Gas | Verified |
| Sector | University | Verified |
| Sector | Utilities | Verified |
| Region | Middle East Countries | Verified |
| Region | United Kingdom | Verified |
| Region | United States | Verified |
| Region | European Countries | Verified |
Extracted IOCs
- oorgans[.]com
- qualitweb[.]com
- service-eset[.]com
- service-essential[.]com
- service-explorer[.]com
- service-norton[.]com
- simsoshop[.]com
- suncocity[.]com
- update-symantec[.]com
- zandelshop[.]com
- zeverco[.]com
- careers@aramcojobs[.]ga
- careers@ngaaksa[.]com
- careers@sipchem[.]ga
- jobs@dyn-intl[.]ga
- jobs@mail.dyn-corp[.]ga
- jobs@ngaaksa[.]ga
- jobs@samref[.]ga
- jobs@sipchem[.]ga
- recruitment@alsalam[.]aero
- 07e1baf1d0207a139bcf39c60354666496e4331381d36eef9359120b1d8497f1
- 75e6bafc4fa496b418df0208f12e688b16e7afdb94a7b30e3eca532717beb9ba
- 8fb6cbf6f6b6a897bf0ee1217dbf738bce7a3000507b89ea30049fd670018b46
- a67461a0c14fc1528ad83b9bd874f53b7616cfed99656442fb4d9cdd7d09e449
- b58a2ef01af65d32ca4ba555bd72931dc68728e6d96d8808afca029b4c75d31e
- ba9d76cca6b5c7308961cfe3739dc1328f3dad9a824417fad73b842b043daa1a
- c303454efb21c0bf0df6fb6c2a14e401efeb57c1c574f63cdae74ef74a3b01f2
- e954ff741baebb173ba45fbcfdea7499d00d8cfa2933b69f6cc0970b294f9ffd
- 109[.]169.89.103
- 109[.]200.24.114
- 137[.]74.157.84
- 137[.]74.80.220
- 185[.]122.56.232
- 185[.]125.204.57
- 185[.]175.138.173
- 188[.]165.119.138
- 193[.]70.71.112
- 195[.]154.41.72
- 213[.]32.113.159
- 216[.]244.93.137
- 31[.]7.62.48
- 5[.]135.120.57
- 5[.]135.199.25
- 51[.]77.11.46
- 54[.]36.73.108
- 54[.]37.48.172
- 54[.]38.124.150
- 88[.]150.221.107
- 91[.]134.203.59
Tip: 49 related IOCs (21 IP, 11 domain, 0 URL, 9 email, 8 file hash) to this threat have been found.
Overlaps
Source: Threat Connect - September 2020
Detection (four cases): qualitweb[.]com, service-eset[.]com, simsoshop[.]com, zeverco[.]com
Source: ThreatConnect - May 2020
Detection (one case): 137[.]74.157.84
Source: Symantec - March 2019
Detection (one case): a67461a0c14fc1528ad83b9bd874f53b7616cfed99656442fb4d9cdd7d09e449
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
Frequently Asked Questions: APT33's Narrow-Targeting Espionage Against Oil, Aerospace, and National Security
Trend Micro researchers documented APT33's use of more than a dozen obfuscated C2 servers for highly targeted espionage operations. Each C2 server controls a micro-botnet of only about 12 infected machines — not the thousands typical of criminal botnets — reflecting a deliberate strategy of staying under the radar. Confirmed victims include US national security companies, universities, a military-related organization, and oil industry companies across the UK, Europe, and the Middle East.
The attacks are attributed to APT33, also known as Elfin, Refined Kitten, or HOLMIUM — an Iranian state-linked threat group active since at least 2013. APT33 is known for targeting the oil and aviation sectors and has been linked to destructive malware (Shamoon/Disttrack) in addition to espionage operations. Trend Micro has tracked this group's C2 infrastructure since at least 2016.
The primary goal is espionage and persistent access. The malware deployed gives operators a foothold for downloading additional tools and maintaining covert presence in target networks. The extreme narrowness of each botnet — only ~12 victims per C2 — suggests high-value, deliberate targeting rather than broad reconnaissance. Given APT33's known use of destructive malware in other campaigns, Trend Micro warns that confirmed infections should be treated as a potential precursor to sabotage operations.
Trend Micro tracked 10 active bot aggregators in fall 2019, each controlling only about 12 victims. Confirmed 2019 victims span the US (two national security company locations, two universities, one military-related victim) and multiple Middle East and Asia targets. In 2018, Trend Micro observed two oil industry compromises in real time. The spear phishing campaigns targeting oil supply chains ran continuously from December 2016 through at least October 2018, targeting recipients at major industry-relevant organizations including a US military water facility.
APT33 targets oil and gas companies, aerospace and aviation firms, national security organizations, universities, and military entities primarily across the Middle East, US, and Asia. The job-lure spear phishing campaigns specifically spoofed major oil and aviation brands — al-Salam Aircraft Company, NGAAKSA, DynCorp, SIPCHEM, Saudi Aramco, and SAMREF — indicating deliberate focus on the oil supply chain and aerospace sector workforces as entry points into high-value targets.
APT33 sent job-offer spear phishing emails from addresses impersonating aviation and oil company HR departments. Once a target opened a malicious attachment or link, the malware (MsdUpdate.exe) installed itself with persistence and connected to C2 through a multi-hop chain: first to a cloud-hosted proxy domain, which relayed traffic to a shared webserver backend, which reported to a dedicated bot aggregator. APT33 operators then connected to those aggregators through a private VPN network with frequently rotated exit nodes, issuing commands and collecting stolen data. The chain ensures that tracing back to the true operators requires penetrating multiple layers of infrastructure across different providers.
Oil and gas companies represent strategic targets for Iranian intelligence given Iran's position as a major energy producer competing directly with Gulf state rivals. Disrupting or monitoring Saudi Aramco, SIPCHEM, and their supply chain provides both commercial intelligence and potential leverage for destructive operations. Aerospace and aviation companies are targeted for military intelligence value and as vectors into defense supply chains. US national security organizations and universities are targeted for political, scientific, and strategic intelligence relevant to Iranian foreign policy and weapons development programs.
Block all 11 C2 domains and cross-reference your security logs against the 21 VPN exit node IPs in the IOC bundle — Trend Micro specifically recommends this for oil and gas organizations. Train staff to recognize job-lure phishing emails using oil and aviation company branding. Monitor for MsdUpdate.exe and DysonPart.exe using the published SHA256 hashes. Alert on external remote connections from the known APT33 VPN exit node IPs. Given APT33's history with destructive malware, treat any confirmed infection as a potential staging operation for follow-on sabotage — not just information theft — and escalate accordingly.