APT33
Actor Type | Nation State |
---|---|
Attributed to Nation | Iran |
Directly Linked Intrusion Sets | Peach Sandstorm , Curious Serpens , Refined Kitten |
Associated Threat Actor | Islamic Revolutionary Guard Corps (IRGC) |
Associated MITRE ATT&CK Group | APT33 (G0064) |
APT33 is a cyber espionage group tracked by researchers at Mandiant. The group has been active since at least 2013, and is believed to be working for the Iranian government.
They have targeted organizations in the aerospace and energy sectors, particularly those with ties to petrochemical production in the US, Saudi Arabia, and South Korea.
APT33 employs spear-phishing with one campaign using malicious .hta files disguised as job vacancies to deploy custom backdoors into target systems.
While not directly observed using destructive malware, APT33 has ties to malware with disk-wiping capabilities, suggesting possible destructive intent or capabilities.
Cyber Threat Graph Context
Explore how this Intrusion Set relates to the wider threat graph