{
  "name": "Adversary Atlas API",
  "version": "1.0.0",
  "description": "Read-only JSON API over the Adversary Atlas threat actor dataset. Statically generated at build time; no authentication, no rate limits.",
  "generated": "2026-07-31T01:06:07.226Z",
  "datasetCurrentAsOf": "2025-09-01",
  "license": "Data compiled from public primary sources; see /methodology/ for sourcing.",
  "actor": {
    "id": "apt33",
    "slug": "apt33",
    "name": "APT33",
    "shortName": "APT33",
    "country": "Iran",
    "countryCode": "IR",
    "sponsorship": "state-sponsored",
    "status": "active",
    "activeSince": "2013",
    "prominence": 80,
    "mitreGroupId": "G0064",
    "malpediaSlug": "apt33",
    "tagline": "Aerospace and petrochemical collection with a destructive edge — linked to the Shamoon wiper attacks that destroyed 30,000 Saudi Aramco workstations.",
    "bio": "APT33 targets aerospace, defence, and petrochemical organisations, with a strong emphasis on the aviation supply chain and on Saudi and Gulf energy companies.\n\nIts initial access approach is consistent: elaborate job-recruitment lures. Operators register domains impersonating real aviation and defence contractors — Boeing, Alsalam Aircraft Company, Northrop Grumman affiliates, Vinnell Arabia — and send convincing recruitment emails to employees at competitors and suppliers. The industry is small, contract work is common, and unsolicited recruitment is entirely ordinary, which makes the lure unusually effective.\n\nWhat separates APT33 from a purely collection-focused actor is its association with destruction. FireEye and other researchers have documented links between APT33 and the Shamoon wiper campaigns — the 2012 attack that destroyed roughly 30,000 workstations at Saudi Aramco and the 2016–2017 resurgence against Saudi government and petrochemical targets. Shamoon overwrites the master boot record and file contents, in the 2012 case with a burning-flag image, rendering machines unbootable and unrecoverable.\n\nMore recently, Microsoft has documented the group conducting extensive password spraying against defence, satellite, and pharmaceutical organisations, and exploiting internet-facing vulnerabilities for access — a shift from targeted social engineering toward higher-volume opportunistic access alongside it.",
    "attribution": {
      "sponsor": "Iran",
      "service": "Islamic Revolutionary Guard Corps (IRGC), assessed",
      "confidence": "moderate",
      "summary": "Assessed as working on behalf of the Iranian government, based on FireEye/Mandiant analysis identifying operator artifacts including a handle linked to an Iranian who had worked for an Iranian government contractor, activity timed to Iranian working hours, and targeting aligned with Iranian strategic interests. The specific service relationship is less firmly established than for MuddyWater; reporting variously associates the group with the IRGC. No individuals have been indicted.",
      "sources": [
        {
          "org": "Mandiant / FireEye",
          "title": "Insights into Iranian Cyber Espionage: APT33 Targets Aerospace and Energy Sectors",
          "url": "https://cloud.google.com/blog/topics/threat-intelligence/apt33-insights-into-iranian-cyber-espionage",
          "date": "2017-09-20"
        },
        {
          "org": "Microsoft Threat Intelligence",
          "title": "Peach Sandstorm password spray campaigns enable intelligence collection at high-value targets",
          "url": "https://www.microsoft.com/en-us/security/blog/2023/09/14/peach-sandstorm-password-spray-campaigns-enable-intelligence-collection-at-high-value-targets/",
          "date": "2023-09-14"
        }
      ]
    },
    "motivations": [
      "espionage",
      "sabotage",
      "ip-theft"
    ],
    "targetSectors": [
      "Aerospace",
      "Energy",
      "Oil & Gas",
      "ICS / SCADA",
      "Defense",
      "Chemical",
      "Government",
      "Manufacturing",
      "Pharmaceuticals",
      "Space"
    ],
    "targetCountries": [
      "Saudi Arabia",
      "United States",
      "South Korea",
      "United Arab Emirates",
      "Israel",
      "Qatar",
      "Kuwait"
    ],
    "aliases": [
      {
        "org": "mitre",
        "name": "APT33",
        "url": "https://attack.mitre.org/groups/G0064/",
        "correlation": "exact"
      },
      {
        "org": "microsoft",
        "name": "Peach Sandstorm",
        "correlation": "exact",
        "note": "Formerly HOLMIUM"
      },
      {
        "org": "microsoft",
        "name": "HOLMIUM",
        "correlation": "exact",
        "note": "Retired designator"
      },
      {
        "org": "crowdstrike",
        "name": "Refined Kitten",
        "correlation": "exact"
      },
      {
        "org": "mandiant",
        "name": "APT33",
        "correlation": "exact"
      },
      {
        "org": "secureworks",
        "name": "COBALT TRINITY",
        "correlation": "exact"
      },
      {
        "org": "unit42",
        "name": "Curious Serpens",
        "correlation": "exact"
      },
      {
        "org": "symantec",
        "name": "Elfin",
        "correlation": "exact"
      },
      {
        "org": "dragos",
        "name": "MAGNALLIUM",
        "correlation": "exact"
      },
      {
        "org": "cisa",
        "name": "APT33",
        "correlation": "exact"
      }
    ],
    "tools": [
      {
        "name": "Shamoon / Disttrack",
        "type": "wiper",
        "custom": true,
        "description": "Disk wiper overwriting the MBR and file contents using a signed raw-disk driver. Destroyed roughly 30,000 Saudi Aramco workstations in 2012.",
        "malpediaSlug": "win.disttrack"
      },
      {
        "name": "TURNEDUP",
        "type": "backdoor",
        "custom": true,
        "description": "Custom backdoor supporting file upload/download, reverse shell, and screenshot capture.",
        "malpediaSlug": "win.turnedup"
      },
      {
        "name": "DROPSHOT / StoneDrill",
        "type": "wiper",
        "custom": true,
        "description": "Wiper with anti-analysis features and a browser-injection module, related to the Shamoon lineage.",
        "malpediaSlug": "win.stonedrill"
      },
      {
        "name": "NANOCORE / NETWIRE",
        "type": "backdoor",
        "custom": false,
        "description": "Commodity RATs used alongside custom tooling to complicate attribution."
      },
      {
        "name": "FalseFont",
        "type": "backdoor",
        "custom": true,
        "description": "Custom backdoor presenting a fake job-application interface to targets in the defence industrial base."
      },
      {
        "name": "AutoIt droppers",
        "type": "loader",
        "custom": true,
        "description": "Scripted loaders delivered through recruitment-themed lure documents."
      }
    ],
    "techniques": [
      {
        "tCode": "T1585.002",
        "name": "Establish Accounts: Email Accounts",
        "tactic": "Resource Development",
        "note": "Domains impersonating real aviation and defence contractors"
      },
      {
        "tCode": "T1566.002",
        "name": "Phishing: Spearphishing Link",
        "tactic": "Initial Access",
        "note": "Job-recruitment lures targeting aviation and defence employees"
      },
      {
        "tCode": "T1110.003",
        "name": "Brute Force: Password Spraying",
        "tactic": "Credential Access",
        "note": "Large-scale spraying against defence, satellite, and pharmaceutical targets"
      },
      {
        "tCode": "T1190",
        "name": "Exploit Public-Facing Application",
        "tactic": "Initial Access"
      },
      {
        "tCode": "T1561.002",
        "name": "Disk Wipe: Disk Structure Wipe",
        "tactic": "Impact",
        "note": "Shamoon MBR destruction"
      },
      {
        "tCode": "T1485",
        "name": "Data Destruction",
        "tactic": "Impact"
      },
      {
        "tCode": "T1003.001",
        "name": "OS Credential Dumping: LSASS Memory",
        "tactic": "Credential Access"
      },
      {
        "tCode": "T1071.001",
        "name": "Application Layer Protocol: Web Protocols",
        "tactic": "Command and Control"
      },
      {
        "tCode": "T1053.005",
        "name": "Scheduled Task/Job: Scheduled Task",
        "tactic": "Persistence"
      },
      {
        "tCode": "T1078",
        "name": "Valid Accounts",
        "tactic": "Persistence"
      }
    ],
    "cves": [
      {
        "cveId": "CVE-2018-13379",
        "firstExploited": "2020-06-01",
        "usage": "FortiOS SSL VPN traversal used to harvest credentials from perimeter appliances at targeted organisations.",
        "source": {
          "org": "Microsoft Threat Intelligence",
          "title": "Peach Sandstorm password spray campaigns",
          "url": "https://www.microsoft.com/en-us/security/blog/2023/09/14/peach-sandstorm-password-spray-campaigns-enable-intelligence-collection-at-high-value-targets/",
          "date": "2023-09-14"
        }
      },
      {
        "cveId": "CVE-2019-11510",
        "firstExploited": "2020-05-01",
        "usage": "Pulse Secure file read exploited for VPN credential theft prior to network access.",
        "source": {
          "org": "Microsoft Threat Intelligence",
          "title": "Peach Sandstorm password spray campaigns",
          "url": "https://www.microsoft.com/en-us/security/blog/2023/09/14/peach-sandstorm-password-spray-campaigns-enable-intelligence-collection-at-high-value-targets/",
          "date": "2023-09-14"
        }
      },
      {
        "cveId": "CVE-2022-47966",
        "firstExploited": "2023-02-01",
        "usage": "Zoho ManageEngine unauthenticated RCE used for initial access to defence-sector networks.",
        "source": {
          "org": "Microsoft Threat Intelligence",
          "title": "Peach Sandstorm password spray campaigns",
          "url": "https://www.microsoft.com/en-us/security/blog/2023/09/14/peach-sandstorm-password-spray-campaigns-enable-intelligence-collection-at-high-value-targets/",
          "date": "2023-09-14"
        }
      },
      {
        "cveId": "CVE-2021-44228",
        "firstExploited": "2022-01-01",
        "usage": "Log4Shell exploited against internet-facing applications for access to targeted networks.",
        "source": {
          "org": "Microsoft Threat Intelligence",
          "title": "Peach Sandstorm password spray campaigns",
          "url": "https://www.microsoft.com/en-us/security/blog/2023/09/14/peach-sandstorm-password-spray-campaigns-enable-intelligence-collection-at-high-value-targets/",
          "date": "2023-09-14"
        }
      }
    ],
    "relationships": [
      {
        "relatedActorId": "apt34",
        "type": "same-sponsor",
        "confidence": "moderate",
        "note": "Both Iranian state-nexus against energy targets, with distinct toolsets and different services."
      },
      {
        "relatedActorId": "apt35",
        "type": "same-sponsor",
        "confidence": "moderate",
        "note": "Both assessed as IRGC-aligned with complementary target sets."
      },
      {
        "relatedActorId": "cyberav3ngers",
        "type": "same-sponsor",
        "confidence": "moderate",
        "note": "Both Iranian actors willing to cross from collection into destructive or disruptive effect."
      }
    ],
    "reports": [
      {
        "org": "Mandiant / FireEye",
        "title": "APT33: Insights into Iranian Cyber Espionage",
        "url": "https://cloud.google.com/blog/topics/threat-intelligence/apt33-insights-into-iranian-cyber-espionage",
        "date": "2017-09-20"
      },
      {
        "org": "Symantec",
        "title": "Elfin: Relentless Espionage Group Targets Multiple Organizations in Saudi Arabia and U.S.",
        "url": "https://symantec-enterprise-blogs.security.com/threat-intelligence/elfin-apt33-espionage",
        "date": "2019-03-27"
      },
      {
        "org": "Microsoft Threat Intelligence",
        "title": "Peach Sandstorm password spray campaigns enable intelligence collection",
        "url": "https://www.microsoft.com/en-us/security/blog/2023/09/14/peach-sandstorm-password-spray-campaigns-enable-intelligence-collection-at-high-value-targets/",
        "date": "2023-09-14"
      }
    ],
    "campaigns": [
      {
        "id": "shamoon",
        "actorId": "apt33",
        "name": "Shamoon Wiper Campaigns",
        "date": "2012-08-15",
        "endDate": "2018-12-01",
        "significance": "landmark",
        "targetSectors": [
          "Energy",
          "Oil & Gas",
          "Government",
          "Chemical"
        ],
        "targetCountries": [
          "Saudi Arabia",
          "Qatar",
          "United Arab Emirates",
          "Italy"
        ],
        "cveIds": [],
        "summary": "Destruction of roughly 30,000 workstations at Saudi Aramco in 2012, overwriting the master boot record and file contents with a burning-flag image, followed by resurgent campaigns against Saudi government and petrochemical targets in 2016–2017 and against Italian energy contractors in 2018.",
        "sources": [
          {
            "org": "Symantec",
            "title": "Shamoon: Destructive Threat Re-Emerges with New Sting in its Tail",
            "url": "https://symantec-enterprise-blogs.security.com/threat-intelligence/shamoon-destructive-threat-re-emerges-new-sting-its-tail",
            "date": "2018-12-14"
          }
        ]
      }
    ],
    "flag": "🇮🇷",
    "profile": "/apt/apt33/"
  }
}