Skip to content
IranState-SponsoredActiveMITRE G0064Malpedia ↗

APT33

Aerospace and petrochemical collection with a destructive edge — linked to the Shamoon wiper attacks that destroyed 30,000 Saudi Aramco workstations.

Open MITRE Navigator layer ↗Download profile JSON
Active
2013–present
Motivation
Espionage, Sabotage / Destruction, IP Theft
Aliases
10
Exploited CVEs
4
ATT&CK techniques
10
Cited sources
9

Overview

APT33 targets aerospace, defence, and petrochemical organisations, with a strong emphasis on the aviation supply chain and on Saudi and Gulf energy companies.

Its initial access approach is consistent: elaborate job-recruitment lures. Operators register domains impersonating real aviation and defence contractors — Boeing, Alsalam Aircraft Company, Northrop Grumman affiliates, Vinnell Arabia — and send convincing recruitment emails to employees at competitors and suppliers. The industry is small, contract work is common, and unsolicited recruitment is entirely ordinary, which makes the lure unusually effective.

What separates APT33 from a purely collection-focused actor is its association with destruction. FireEye and other researchers have documented links between APT33 and the Shamoon wiper campaigns — the 2012 attack that destroyed roughly 30,000 workstations at Saudi Aramco and the 2016–2017 resurgence against Saudi government and petrochemical targets. Shamoon overwrites the master boot record and file contents, in the 2012 case with a burning-flag image, rendering machines unbootable and unrecoverable.

More recently, Microsoft has documented the group conducting extensive password spraying against defence, satellite, and pharmaceutical organisations, and exploiting internet-facing vulnerabilities for access — a shift from targeted social engineering toward higher-volume opportunistic access alongside it.

Attribution

Down to the named unit where public evidence supports it.

IranIslamic Revolutionary Guard Corps (IRGC), assessedModerate confidence

Assessed as working on behalf of the Iranian government, based on FireEye/Mandiant analysis identifying operator artifacts including a handle linked to an Iranian who had worked for an Iranian government contractor, activity timed to Iranian working hours, and targeting aligned with Iranian strategic interests. The specific service relationship is less firmly established than for MuddyWater; reporting variously associates the group with the IRGC. No individuals have been indicted.

Attributing sources

Cross-vendor naming crosswalk

10 designators across 9 organisations.

MITRE ATT&CK

index ↗
  • APT33

Assigns a stable Gxxxx group ID and adopts the most widely used public name. Deliberately conservative — MITRE merges clusters only when public reporting supports it.

Microsoft Threat Intelligence

index ↗
  • Peach SandstormFormerly HOLMIUM
  • HOLMIUMRetired designator

Weather-event family encodes the attributed origin; the adjective is arbitrary. Renamed from the older element taxonomy (STRONTIUM, NOBELIUM, HAFNIUM) in April 2023. 'Storm-####' is a temporary designator for a cluster still in development.

CrowdStrike

index ↗
  • Refined Kitten

Animal denotes attributed nation-state or motive; the adjective distinguishes clusters. The original public adversary taxonomy, in use since 2012.

Mandiant / Google Threat Intelligence

index ↗
  • APT33

APTxx for state-nexus espionage, FINxx for financially motivated, UNCxxxx ('uncategorized') for clusters not yet graduated to a named group. Many UNC numbers are later merged into an APT/FIN designator.

Secureworks CTU

index ↗
  • COBALT TRINITY

Metal prefix encodes attributed origin, paired with an arbitrary uppercase codeword.

Palo Alto Networks Unit 42

index ↗
  • Curious Serpens

Constellation denotes attributed origin or motive, adopted in 2023 to replace ad-hoc naming.

Dragos

index ↗
  • MAGNALLIUM

Mineral names for groups with demonstrated or assessed intent against industrial control systems. A Dragos designator is a meaningful signal: it means OT/ICS capability, not just IT intrusion.

Symantec (Broadcom)

index ↗
  • Elfin

Insect, animal, and plant names assigned in the order clusters were first identified.

CISA / NSA / FBI

index ↗
  • APT33

U.S. government advisories generally reference groups by the most common industry name plus the attributed unit. Joint advisories are the authoritative source for unit-level attribution.

Targeting

Target geography

Saudi ArabiaUnited StatesSouth KoreaUnited Arab EmiratesIsraelQatarKuwait

Tools & malware

Custom tooling is a strong clustering signal; shared and commodity tooling is not.

Custom / bespoke

Shamoon / Disttrackwiper

Disk wiper overwriting the MBR and file contents using a signed raw-disk driver. Destroyed roughly 30,000 Saudi Aramco workstations in 2012.

Malpedia ↗
TURNEDUPbackdoor

Custom backdoor supporting file upload/download, reverse shell, and screenshot capture.

Malpedia ↗
DROPSHOT / StoneDrillwiper

Wiper with anti-analysis features and a browser-injection module, related to the Shamoon lineage.

Malpedia ↗
FalseFontbackdoor

Custom backdoor presenting a fake job-application interface to targets in the defence industrial base.

AutoIt droppersloader

Scripted loaders delivered through recruitment-themed lure documents.

Shared, commodity & living-off-the-land

NANOCORE / NETWIREbackdoor

Commodity RATs used alongside custom tooling to complicate attribution.

Exploited vulnerabilities

Filtered on the date this actor was first reported exploiting the flaw — not the CVE's publication date.

CVEUsage by APT33
CVE-2022-47966KEVransomware9.81 Feb 2023Zoho ManageEngine unauthenticated RCE used for initial access to defence-sector networks.SRCMicrosoft Threat Intelligence
CVE-2021-44228KEVransomware10.01 Jan 2022Log4Shell exploited against internet-facing applications for access to targeted networks.SRCMicrosoft Threat Intelligence
CVE-2018-13379KEVransomware9.81 Jun 2020FortiOS SSL VPN traversal used to harvest credentials from perimeter appliances at targeted organisations.SRCMicrosoft Threat Intelligence
CVE-2019-11510KEVransomware10.01 May 2020Pulse Secure file read exploited for VPN credential theft prior to network access.SRCMicrosoft Threat Intelligence

Kill chain

How this actor moves through an intrusion, stage by stage, titled by ATT&CK tactic. Read left to right.

6 stages · 10 techniques

Scroll horizontally · characteristic chain across documented operations, not a single incident

MITRE ATT&CK techniques

Grouped in kill-chain order.

Open in Navigator ↗
10 techniques across 6 tactics · 4 with actor-specific notes

Resource Development

1

Initial Access

2

Credential Access

2

Campaign timeline

  1. landmark

    Shamoon Wiper Campaigns

    Destruction of roughly 30,000 workstations at Saudi Aramco in 2012, overwriting the master boot record and file contents with a burning-flag image, followed by resurgent campaigns against Saudi government and petrochemical targets in 2016–2017 and against Italian energy contractors in 2018.

    EnergyOil & GasGovernmentChemical

Known to work with

Relationship type and confidence stated explicitly — 'related' without qualification is not an assessment.

Primary-source reporting

Curated links to the reports that established what is known about this group.