APT33

Actor Type Nation State
Attributed to Nation Iran
Directly Linked Intrusion Sets Peach Sandstorm , Curious Serpens , Refined Kitten
Associated Threat Actor Islamic Revolutionary Guard Corps (IRGC)
Associated MITRE ATT&CK Group APT33 (G0064)

APT33 is a cyber espionage group tracked by researchers at Mandiant. The group has been active since at least 2013, and is believed to be working for the Iranian government.

They have targeted organizations in the aerospace and energy sectors, particularly those with ties to petrochemical production in the US, Saudi Arabia, and South Korea.

APT33 employs spear-phishing with one campaign using malicious .hta files disguised as job vacancies to deploy custom backdoors into target systems.

While not directly observed using destructive malware, APT33 has ties to malware with disk-wiping capabilities, suggesting possible destructive intent or capabilities.

Cyber Threat Graph Context

Explore how this Intrusion Set relates to the wider threat graph

References