IRIran (Islamic Republic of)confidence: 50G0064

APT33APT33

Also known as: APT 33 · Elfin · MAGNALLIUM · Refined Kitten · HOLMIUM · COBALT TRINITY · G0064 · ATK35 · Peach Sandstorm · TA451 · APT33

Origin
IR
Known aliases
11
Target sectors
1
Attribution
State-sponsored

Profile

APT33 is a Iranian-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as APT 33, Elfin, MAGNALLIUM (and 7 more). Operational targeting focuses on the Private sector sector. Documented victim organisations include United States, Saudi Arabia, South Korea. Original record: Our analysis reveals that APT33 is a capable group that has carried out cyber espionage operations since at least 2013. We assess APT33 works at the behest of the Iranian government.

Aliases· 11

APT 33ElfinMAGNALLIUMRefined KittenHOLMIUMCOBALT TRINITYATK35Peach SandstormTA451APT33
G0064

Target sectors· 1

Private sector

Known victims· 3

  • United States
  • Saudi Arabia
  • South Korea

MITRE ATT&CK Group crosswalk

G0064

References

  1. https://www.fireeye.com/blog/threat-research/2017/09/apt33-insights-into-iranian-cyber-espionage.html
  2. https://blog.trendmicro.com/trendlabs-security-intelligence/more-than-a-dozen-obfuscated-apt33-botnets-used-for-extreme-narrow-targeting/
  3. https://www.brighttalk.com/webcast/10703/275683
  4. https://symantec-blogs.broadcom.com/blogs/threat-intelligence/elfin-apt33-espionage
  5. https://www.secureworks.com/research/threat-profiles/cobalt-trinity
  6. https://attack.mitre.org/groups/G0064/
  7. https://threatconnect.com/blog/research-roundup-activity-on-previously-identified-apt33-domains/
  8. https://www.cfr.org/interactive/cyber-operations/apt-33

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
APT30
Actor
APT35
Actor
APT37
Actor
APT31
Actor
APT32
Actor
APT43
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.