APT33
Our analysis reveals that APT33 is a capable group that has carried out cyber espionage operations since at least 2013. We assess APT33 works at the behest of the Iranian government.
APT33 is an Iranian state group known for cyber espionage operations.
APT33 is an Iranian nation-state group conducting cyber espionage since at least 2013. The group targets private sector entities primarily in the United States, Saudi Arabia, and South Korea. It leverages spearphishing attachments and links for initial access, followed by PowerShell and Scheduled Tasks for execution, and often uses Mimikatz, PowerShell tooling (PowerSploit, PoshC2), and custom backdoors like AutoIt backdoor for credential access and C2. Defenders should enforce strict email security controls, closely monitor PowerShell execution, and prioritize detecting anomalous credential access activities, particularly those associated with Mimikatz.
Our analysis reveals that APT33 is a capable group that has carried out cyber espionage operations since at least 2013. We assess APT33 works at the behest of the Iranian government.
Organizations should monitor their external sources to detect acquisition or development of tools.
Monitoring suspicious email attachments and links and educating users against Spearphishing attacks is necessary.
Organizations should monitor creation of Scheduled Tasks and execution of PowerShell.
Monitoring Registry Run Keys and Startup Folder modifications is necessary.
Organizations should monitor Windows Management Instrumentation Event Subscription and privilege escalation attempts.
Monitoring encrypted files and valid accounts is necessary.
Monitoring cached domain credentials and credentials in files is necessary.
Monitoring use of archive utilities is necessary.
Detecting use of web protocols and ingress tool transfer is necessary.
Monitoring exfiltration over unencrypted non-C2 protocol is necessary.
APT33 uses Spearphishing Attachment/Link methods for initial access.
APT33 works at the behest of the Iranian government.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.