Resource Development
1 technique·derived
Domains impersonating real aviation and defence contractors.
Aerospace and petrochemical collection with a destructive edge — linked to the Shamoon wiper attacks that destroyed 30,000 Saudi Aramco workstations.
APT33 targets aerospace, defence, and petrochemical organisations, with a strong emphasis on the aviation supply chain and on Saudi and Gulf energy companies.
Its initial access approach is consistent: elaborate job-recruitment lures. Operators register domains impersonating real aviation and defence contractors — Boeing, Alsalam Aircraft Company, Northrop Grumman affiliates, Vinnell Arabia — and send convincing recruitment emails to employees at competitors and suppliers. The industry is small, contract work is common, and unsolicited recruitment is entirely ordinary, which makes the lure unusually effective.
What separates APT33 from a purely collection-focused actor is its association with destruction. FireEye and other researchers have documented links between APT33 and the Shamoon wiper campaigns — the 2012 attack that destroyed roughly 30,000 workstations at Saudi Aramco and the 2016–2017 resurgence against Saudi government and petrochemical targets. Shamoon overwrites the master boot record and file contents, in the 2012 case with a burning-flag image, rendering machines unbootable and unrecoverable.
More recently, Microsoft has documented the group conducting extensive password spraying against defence, satellite, and pharmaceutical organisations, and exploiting internet-facing vulnerabilities for access — a shift from targeted social engineering toward higher-volume opportunistic access alongside it.
Down to the named unit where public evidence supports it.
Assessed as working on behalf of the Iranian government, based on FireEye/Mandiant analysis identifying operator artifacts including a handle linked to an Iranian who had worked for an Iranian government contractor, activity timed to Iranian working hours, and targeting aligned with Iranian strategic interests. The specific service relationship is less firmly established than for MuddyWater; reporting variously associates the group with the IRGC. No individuals have been indicted.
Attributing sources
10 designators across 9 organisations.
Assigns a stable Gxxxx group ID and adopts the most widely used public name. Deliberately conservative — MITRE merges clusters only when public reporting supports it.
Weather-event family encodes the attributed origin; the adjective is arbitrary. Renamed from the older element taxonomy (STRONTIUM, NOBELIUM, HAFNIUM) in April 2023. 'Storm-####' is a temporary designator for a cluster still in development.
Animal denotes attributed nation-state or motive; the adjective distinguishes clusters. The original public adversary taxonomy, in use since 2012.
APTxx for state-nexus espionage, FINxx for financially motivated, UNCxxxx ('uncategorized') for clusters not yet graduated to a named group. Many UNC numbers are later merged into an APT/FIN designator.
Metal prefix encodes attributed origin, paired with an arbitrary uppercase codeword.
Constellation denotes attributed origin or motive, adopted in 2023 to replace ad-hoc naming.
Mineral names for groups with demonstrated or assessed intent against industrial control systems. A Dragos designator is a meaningful signal: it means OT/ICS capability, not just IT intrusion.
Insect, animal, and plant names assigned in the order clusters were first identified.
U.S. government advisories generally reference groups by the most common industry name plus the attributed unit. Joint advisories are the authoritative source for unit-level attribution.
Target sectors
Target geography
Custom tooling is a strong clustering signal; shared and commodity tooling is not.
Custom / bespoke
Disk wiper overwriting the MBR and file contents using a signed raw-disk driver. Destroyed roughly 30,000 Saudi Aramco workstations in 2012.
Malpedia ↗Custom backdoor supporting file upload/download, reverse shell, and screenshot capture.
Malpedia ↗Wiper with anti-analysis features and a browser-injection module, related to the Shamoon lineage.
Malpedia ↗Custom backdoor presenting a fake job-application interface to targets in the defence industrial base.
Scripted loaders delivered through recruitment-themed lure documents.
Shared, commodity & living-off-the-land
Commodity RATs used alongside custom tooling to complicate attribution.
Filtered on the date this actor was first reported exploiting the flaw — not the CVE's publication date.
| CVE | Product | Usage by APT33 | ||
|---|---|---|---|---|
| CVE-2022-47966KEVransomware | 9.8 | Zoho ManageEngineZoho | 1 Feb 2023 | Zoho ManageEngine unauthenticated RCE used for initial access to defence-sector networks.SRCMicrosoft Threat Intelligence ↗ |
| CVE-2021-44228KEVransomware | 10.0 | Apache Log4j2Apache | 1 Jan 2022 | Log4Shell exploited against internet-facing applications for access to targeted networks.SRCMicrosoft Threat Intelligence ↗ |
| CVE-2018-13379KEVransomware | 9.8 | FortiOS SSL VPNFortinet | 1 Jun 2020 | FortiOS SSL VPN traversal used to harvest credentials from perimeter appliances at targeted organisations.SRCMicrosoft Threat Intelligence ↗ |
| CVE-2019-11510KEVransomware | 10.0 | Pulse Connect SecureIvanti / Pulse Secure | 1 May 2020 | Pulse Secure file read exploited for VPN credential theft prior to network access.SRCMicrosoft Threat Intelligence ↗ |
Actors sharing exploited CVEs
How this actor moves through an intrusion, stage by stage, titled by ATT&CK tactic. Read left to right.
1 technique·derived
Domains impersonating real aviation and defence contractors.
2 techniques·derived
Job-recruitment lures targeting aviation and defence employees.
2 techniques·derived
Scheduled Task, Valid Accounts.
2 techniques·derived
Large-scale spraying against defence, satellite, and pharmaceutical targets.
1 technique·derived
Web Protocols.
2 techniques·derived
Shamoon MBR destruction.
Scroll horizontally · characteristic chain across documented operations, not a single incident
Grouped in kill-chain order.
Domains impersonating real aviation and defence contractors
Job-recruitment lures targeting aviation and defence employees
Large-scale spraying against defence, satellite, and pharmaceutical targets
Shamoon MBR destruction
Destruction of roughly 30,000 workstations at Saudi Aramco in 2012, overwriting the master boot record and file contents with a burning-flag image, followed by resurgent campaigns against Saudi government and petrochemical targets in 2016–2017 and against Italian energy contractors in 2018.
Relationship type and confidence stated explicitly — 'related' without qualification is not an assessment.
Both Iranian state-nexus against energy targets, with distinct toolsets and different services.
Both assessed as IRGC-aligned with complementary target sets.
Both Iranian actors willing to cross from collection into destructive or disruptive effect.
Curated links to the reports that established what is known about this group.