THREAT_ACTOR · G0064
APT33
Also known as: APT33, HOLMIUM, Elfin, Peach Sandstorm
Profile
APT33 is a suspected Iranian threat group that has carried out operations since at least 2013. The group has targeted organizations across multiple industries in the United States, Saudi Arabia, and South Korea, with a particular interest in the aviation and energy sectors.
MITRE ATT&CK ↗Techniques
31 ATT&CK techniques attributed to this actor.
T1003.001 LSASS MemoryT1003.004 LSA SecretsT1003.005 Cached Domain CredentialsT1027.013 Encrypted/Encoded FileT1040 Network SniffingT1048.003 Exfiltration Over Unencrypted Non-C2 ProtocolT1053.005 Scheduled TaskT1059.001 PowerShellT1059.005 Visual BasicT1068 Exploitation for Privilege EscalationT1071.001 Web ProtocolsT1078 Valid AccountsT1078.004 Cloud AccountsT1105 Ingress Tool TransferT1110.003 Password SprayingT1132.001 Standard EncodingT1203 Exploitation for Client ExecutionT1204.001 Malicious LinkT1204.002 Malicious FileT1546.003 Windows Management Instrumentation Event SubscriptionT1547.001 Registry Run Keys / Startup FolderT1552.001 Credentials In FilesT1552.006 Group Policy PreferencesT1555 Credentials from Password StoresT1555.003 Credentials from Web BrowsersT1560.001 Archive via UtilityT1566.001 Spearphishing AttachmentT1566.002 Spearphishing LinkT1571 Non-Standard PortT1573.001 Symmetric CryptographyT1588.002 Tool
Software
16 malware/tools attributed to this actor.
MimikatzNetftpAutoIt backdoorPupyPowerSploitNETWIRETURNEDUPNanoCoreLaZagneRulerEmpirePOWERTONPoshC2StoneDrillDEADWOOD
Related corpus activity
10,344 indicators EXHIBIT techniques this actor uses. This is a shared-technique signal, not a first-party attribution to APT33.
| Indicator | Type | Family | Sev | Src |
|---|---|---|---|---|
| cve-2023-44976 | cve | ransomware | 85 | 2 |
| cve-2026-1969 | cve | — | 85 | 1 |
| cve-2025-68670 | cve | — | 85 | 2 |
| cve-2026-3102 | cve | — | 85 | 3 |
| cve-2025-34117 | cve | — | 85 | 1 |
| cve-2021-29441 | cve | — | 85 | 1 |
| cve-2026-22584 | cve | — | 85 | 2 |
| cve-2025-11837 | cve | — | 85 | 2 |
| cve-2025-34054 | cve | — | 85 | 4 |
| cve-2014-2321 | cve | — | 85 | 1 |
| cve-2020-22653 | cve | — | 85 | 2 |
| cve-2025-2492 | cve | — | 85 | 2 |
| cve-2017-18377 | cve | — | 85 | 1 |
| cve-2021-25646 | cve | — | 85 | 1 |
| cve-2025-66478 | cve | — | 85 | 2 |
| cve-2025-0921 | cve | — | 85 | 2 |
| cve-2021-27076 | cve | — | 85 | 1 |
| cve-2013-3307 | cve | — | 85 | 2 |
| cve-2016-5681 | cve | — | 85 | 2 |
| cve-2016-15047 | cve | — | 85 | 4 |
| cve-2024-1781 | cve | — | 85 | 1 |
| cve-2018-8007 | cve | — | 85 | 1 |
| cve-2021-4045 | cve | — | 85 | 1 |
| cve-2020-17456 | cve | — | 85 | 1 |
| cve-2022-47945 | cve | — | 85 | 1 |
| cve-2020-22658 | cve | — | 85 | 2 |
| cve-2025-23304 | cve | — | 85 | 2 |
| cve-2026-4368 | cve | ransomware | 85 | 1 |
| cve-2013-7471 | cve | — | 85 | 1 |
| cve-2026-0740 | cve | — | 85 | 1 |
Showing the top 30 by severity of 10,344.