Loading the current evidence view. Navigation and account controls remain available.
Threat actors
Loading the current evidence view. Navigation and account controls remain available.
Also known as: HOLMIUM, Elfin, Peach Sandstorm
31
techniques
16
software
11,657
corpus matches
profile
APT33 is a suspected Iranian threat group that has carried out operations since at least 2013. The group has targeted organizations across multiple industries in the United States, Saudi Arabia, and South Korea, with a particular interest in the aviation and energy sectors.
techniques
31 attributed · most-instrumented first
software
16 malware & tools attributed
Mimikatz
S0002
Net
S0039
ftp
S0095
AutoIt backdoor
S0129
Pupy
S0192
PowerSploit
S0194
NETWIRE
S0198
TURNEDUP
S0199
NanoCore
S0336
LaZagne
S0349
read this carefully
11,657 corpus matches is not attribution
That count is indicators which exhibit techniques APT33 is known to use. Many unrelated operators use the same techniques. Treat it as a shared-technique signal for hunting, never as first-party attribution to this group.
indicators exhibiting these techniques
Top by severity: each resolves to its own verdict.
+19 more techniques
Ruler
S0358
Empire
S0363
POWERTON
S0371
PoshC2
S0378
StoneDrill
S0380
DEADWOOD
S1134
showing 30 of 11,657
known aliases
Vendors name the same group differently. Searching any alias reaches this profile.