Overview 102 indicators
APT33 is a suspected Iranian threat group that has carried out operations since at least 2013. The group has targeted organizations across multiple industries in the United States, Saudi Arabia, and South Korea, with a particular interest in the aviation and energy sectors.
| domain | 99 | G0064-domain.txt |
| ipv4 | 1 | G0064.json |
| url | 1 | G0064.json |
| url_path | 1 | G0064.json |
Techniques 31 ATT&CK
Open in ATT&CK Navigator → or download the layer (31 techniques, layer 4.5)
- T1003.001 LSASS Memory
- T1003.004 LSA Secrets
- T1003.005 Cached Domain Credentials
- T1027.013 Encrypted/Encoded File
- T1040 Network Sniffing
- T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol
- T1053.005 Scheduled Task
- T1059.001 PowerShell
- T1059.005 Visual Basic
- T1068 Exploitation for Privilege Escalation
- T1071.001 Web Protocols
- T1078 Valid Accounts
- T1078.004 Cloud Accounts
- T1105 Ingress Tool Transfer
- T1110.003 Password Spraying
- T1132.001 Standard Encoding
- T1203 Exploitation for Client Execution
- T1204.001 Malicious Link
- T1204.002 Malicious File
- T1546.003 Windows Management Instrumentation Event Subscription
- T1547.001 Registry Run Keys / Startup Folder
- T1552.001 Credentials In Files
- T1552.006 Group Policy Preferences
- T1555 Credentials from Password Stores
- T1555.003 Credentials from Web Browsers
- T1560.001 Archive via Utility
- T1566.001 Spearphishing Attachment
- T1566.002 Spearphishing Link
- T1571 Non-Standard Port
- T1573.001 Symmetric Cryptography
- T1588.002 Tool
Software 16
- Mimikatz
- Net
- ftp
- AutoIt backdoor
- Pupy
- PowerSploit
- NETWIRE
- TURNEDUP
- NanoCore
- LaZagne
- Ruler
- Empire
- POWERTON
- PoshC2
- StoneDrill
- DEADWOOD
Principal sources 27 reports
Ranked by how many of this actor's indicators each report brought in.
- 29go.recordedfuture.com/hubfs/reports/cta-2019-0626.pdf
- 29otx.alienvault.com/pulse/5d13cf4759eec0125b9d8ffa
- 20hyas.com/news/hunting-apt33-campaign-infrastruct…
- 20otx.alienvault.com/pulse/5d85272acd389e89e743368c
- 14fireeye.com/blog/threat-research/2017/09/apt33-insi…
- 13blog.telsy.com/meeting-powerband-the-apt33-net-powerto…
- 13otx.alienvault.com/pulse/5e4430d06ed4c78cf4aa7872
- 10blog.trendmicro.com/trendlabs-security-intelligence/more-th…
Related groups 8
What the sources have in common — not a claim that these are the same actor. See the whole graph.
Timeline 102 indicators
Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.
No indicator matches. Only the most recent 300 are on this page — the rest are in the JSON.
-
twitter.com/banthisguy9349/status/17599841170037190… · shadowdragon.io/blog/additional-insights-into-iranian-c…
http://34.101.157.124 -
twitter.com/MsftSecIntel/status/1737895710169628824 · twitter.com/MsftSecIntel/status/1737895717870440609 · thehackernews.com/2023/12/microsoft-warns-of-new-falsefon… · unit42.paloaltonetworks.com/curious-serpens-falsefont-backdoor
digitalcodecrafters.com -
twitter.com/kyleehmke/status/1304444869809758210 · twitter.com/kyleehmke/status/1304444870979919872
akadnsplugin.com ocsp-support.com service-houston.com support-newyork.com -
twitter.com/kyleehmke/status/1293498254009815040
relaxingsports.com -
twitter.com/ShadowChasing1/status/12750420602071326… · virustotal.com/gui/file/e7b992f95b3908579d026f22c237ad…
availsqaapi.premieredigital.net -
blog.telsy.com/meeting-powerband-the-apt33-net-powerto… · otx.alienvault.com/pulse/5e4430d06ed4c78cf4aa7872
dailystudy.org eventmonitoring.org gefurrinn.com imap-outlook.com powersafety.org smtpauths.com smtpsync.com theworldjob.org world-careers.org -
twitter.com/Sam1rSQS/status/1206552916959662080
188.166.55.116:56444 -
blog.trendmicro.com/trendlabs-security-intelligence/more-th… · otx.alienvault.com/pulse/5dcd22740cea7974f1e9927b
qualitweb.com service-eset.com service-essential.com service-explorer.com service-norton.com simsoshop.com suncocity.com update-symantec.com zandelshop.com zeverco.com -
twitter.com/CTI_Marc/status/1194573048625729536 · otx.alienvault.com/pulse/5dcc25f17c401b08b33d3d84 · blog.telsy.com/meeting-powerband-the-apt33-net-powerto… · otx.alienvault.com/pulse/5e4430d06ed4c78cf4aa7872
azure-dnszones.com global-careers.org lovememories.org times-sync.com -
hyas.com/news/hunting-apt33-campaign-infrastruct… · otx.alienvault.com/pulse/5d85272acd389e89e743368c
admindirector.com businessscards.com cardchsk.com cardkuys.com ceoadminoffice.com diplomatsign.com groupchiefexecutive.com mailsarchive.com managementdirector.com moreonlineshopping.com officemngt.com phpencryptssl.com service-search.info tokensetting.com truelogon.com urlmanage.com -
hyas.com/news/hunting-apt33-campaign-infrastruct… · otx.alienvault.com/pulse/5d85272acd389e89e743368c
customermgmt.net -
go.recordedfuture.com/hubfs/reports/cta-2019-0626.pdf · otx.alienvault.com/pulse/5d13cf4759eec0125b9d8ffa
backupnet.ddns.net bistbotsproxies.ddns.net fucksaudi.ddns.net googlechromehost.ddns.net hellocookies.ddns.net hyperservice.ddns.net mynetwork.cf n3tc4t.hopto.com newhost.hopto.org njrat12.ddns.net remote-server.ddns.net remserver.ddns.net servhost.hopto.org service-avant.com srvhost.servehttp.com svcexplores.com teamnj.ddns.net trojan1117.hopto.org update-sec.com windowsx.sytes.net wwwgooglecom.sytes.net xtreme.hopto.org younesadams.ddns.net za158155.ddns.net -
fireeye.com/blog/threat-research/2017/09/apt33-insi…
chromup.com -
twitter.com/ClearskySec/status/1142749950998171648 · app.any.run/tasks/c761d00f-4897-4c9e-8468-9172fcce2… · hyas.com/news/hunting-apt33-campaign-infrastruct… · otx.alienvault.com/pulse/5d85272acd389e89e743368c
inboxsync.org whiteelection.com -
twitter.com/ClearskySec/status/1142749950998171648 · app.any.run/tasks/c761d00f-4897-4c9e-8468-9172fcce2… · hyas.com/news/hunting-apt33-campaign-infrastruct… · otx.alienvault.com/pulse/5d85272acd389e89e743368c · twitter.com/Sam1rSQS/status/1206552916959662080
backupaccount.net -
twitter.com/ClearskySec/status/1142749950998171648 · app.any.run/tasks/c761d00f-4897-4c9e-8468-9172fcce2…
becomestateman.com -
twitter.com/ClearskySec/status/1059532789572386817 · twitter.com/ClearskySec/status/1059532946045050883
domain aramcojobs.ddns.net domain dyn-corp.ddns.net domain dyncorp.ddns.net domain mynetwork2.ddns.net domain ngaaksa.ga domain sabic-co.ddns.net domain saharapcc.ddns.net domain sipchem.ddns.net url_path /aramco/ -
twitter.com/ClearskySec/status/1059532789572386817 · twitter.com/ClearskySec/status/1059532946045050883 · go.recordedfuture.com/hubfs/reports/cta-2019-0626.pdf · otx.alienvault.com/pulse/5d13cf4759eec0125b9d8ffa
mynetwork.ddns.net -
fireeye.com/blog/threat-research/2017/09/apt33-insi…
alsalam.ddns.net boeing.servehttp.com googlmail.net managehelpdesk.com microsoftupdated.net ngaaksa.ddns.net ngaaksa.sytes.net osupd.com syn.broadcaster.rocks vinnellarabia.myftp.org -
fireeye.com/blog/threat-research/2017/09/apt33-insi… · go.recordedfuture.com/hubfs/reports/cta-2019-0626.pdf · otx.alienvault.com/pulse/5d13cf4759eec0125b9d8ffa
mywinnetwork.ddns.net -
go.recordedfuture.com/hubfs/reports/cta-2019-0626.pdf · otx.alienvault.com/pulse/5d13cf4759eec0125b9d8ffa
mypsh.ddns.net -
fireeye.com/blog/threat-research/2017/09/apt33-insi… · go.recordedfuture.com/hubfs/reports/cta-2019-0626.pdf · otx.alienvault.com/pulse/5d13cf4759eec0125b9d8ffa
microsoftupdated.com -
fireeye.com/blog/threat-research/2017/09/apt33-insi… · go.recordedfuture.com/hubfs/reports/cta-2019-0626.pdf · otx.alienvault.com/pulse/5d13cf4759eec0125b9d8ffa
securityupdated.com
Further reading 32
- attack.mitre.org/groups/G0064
- learn.microsoft.com/en-us/microsoft-365/security/intelligen…
- brighttalk.com/webcast/10703/275683
- fireeye.com/blog/threat-research/2017/09/apt33-insi…
- microsoft.com/security/blog/2020/06/18/inside-microso…
- symantec.com/blogs/threat-intelligence/elfin-apt33-e…
- twitter.com/kyleehmke/status/1293498254009815040
- twitter.com/ClearskySec/status/1142749950998171648
- twitter.com/kyleehmke/status/1304444870979919872
- otx.alienvault.com/pulse/5d85272acd389e89e743368c
- twitter.com/MsftSecIntel/status/1737895710169628824
- app.any.run/tasks/c761d00f-4897-4c9e-8468-9172fcce2…
- twitter.com/Sam1rSQS/status/1206552916959662080
- twitter.com/banthisguy9349/status/17599841170037190…
- thehackernews.com/2023/12/microsoft-warns-of-new-falsefon…
- twitter.com/ClearskySec/status/1059532789572386817
- otx.alienvault.com/pulse/5d13cf4759eec0125b9d8ffa
- unit42.paloaltonetworks.com/curious-serpens-falsefont-backdoor
- go.recordedfuture.com/hubfs/reports/cta-2019-0626.pdf
- hyas.com/news/hunting-apt33-campaign-infrastruct…
- blog.telsy.com/meeting-powerband-the-apt33-net-powerto…
- virustotal.com/gui/file/e7b992f95b3908579d026f22c237ad…
- blog.trendmicro.com/trendlabs-security-intelligence/more-th…
- twitter.com/ClearskySec/status/1059532946045050883
- twitter.com/CTI_Marc/status/1194573048625729536
- twitter.com/kyleehmke/status/1304444869809758210
- otx.alienvault.com/pulse/5dcc25f17c401b08b33d3d84
- otx.alienvault.com/pulse/5e4430d06ed4c78cf4aa7872
- twitter.com/MsftSecIntel/status/1737895717870440609
- shadowdragon.io/blog/additional-insights-into-iranian-c…
- otx.alienvault.com/pulse/5dcd22740cea7974f1e9927b
- twitter.com/ShadowChasing1/status/12750420602071326…