IRIran (Islamic Republic of)confidence: 50G0064
APT33APT33
Also known as: APT 33 · Elfin · MAGNALLIUM · Refined Kitten · HOLMIUM · COBALT TRINITY · G0064 · ATK35 · Peach Sandstorm · TA451 · APT33
Origin
IR
Known aliases
11
Target sectors
1
Attribution
State-sponsored
Profile
APT33 is a Iranian-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as APT 33, Elfin, MAGNALLIUM (and 7 more). Operational targeting focuses on the Private sector sector. Documented victim organisations include United States, Saudi Arabia, South Korea. Original record: Our analysis reveals that APT33 is a capable group that has carried out cyber espionage operations since at least 2013. We assess APT33 works at the behest of the Iranian government.
Aliases· 11
APT 33ElfinMAGNALLIUMRefined KittenHOLMIUMCOBALT TRINITYATK35Peach SandstormTA451APT33
Target sectors· 1
Private sector
Known victims· 3
- United States
- Saudi Arabia
- South Korea
MITRE ATT&CK Group crosswalk
References
- https://www.fireeye.com/blog/threat-research/2017/09/apt33-insights-into-iranian-cyber-espionage.html
- https://blog.trendmicro.com/trendlabs-security-intelligence/more-than-a-dozen-obfuscated-apt33-botnets-used-for-extreme-narrow-targeting/
- https://www.brighttalk.com/webcast/10703/275683
- https://symantec-blogs.broadcom.com/blogs/threat-intelligence/elfin-apt33-espionage
- https://www.secureworks.com/research/threat-profiles/cobalt-trinity
- https://attack.mitre.org/groups/G0064/
- https://threatconnect.com/blog/research-roundup-activity-on-previously-identified-apt33-domains/
- https://www.cfr.org/interactive/cyber-operations/apt-33
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.