APT33
APT33 is an Iranian threat actor also tracked as Elfin, Holmium, Peach Sandstorm, Refined Kitten, and G0064. The provided content associates APT33 with credential- and access-focused operations against government and defense sectors, including weaponized password spraying. It has used malicious email attachments to lure victims into executing malware, used HTTP for command and control, and encoded command-and-control traffic with Base64. The actor has used PowerShell to download files from command-and-control servers and execute scripts. For persistence, APT33 has deployed DarkComet to a victim Startup folder and used Registry Run keys. The content also states APT33 has used publicly available tools such as LaZagne to gather credentials, including credentials stored in web browsers. The content further notes association with Shamoon and states that APT33, like Lazarus Group, took advantage of Eldos RawDisk to obtain direct userland access to the filesystem without calling Windows APIs. Ruler usage is noted as having been previously associated with Iranian threat actors, most commonly APT33.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Energy
- Software & Services
- Government & Administration
- Academia & Research
- Military
Where they target
Geographies tied to known operations.
- 🇺🇸 United States
- 🇦🇪 United Arab Emirates
- 🇦🇺 Australia
Where they're from
Attributed origin per open-source reporting.
- IR
Tradecraft
52 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
30 malware families attributed to this actor across reporting.
25 additional families tracked in Mallory.
Associated vulnerabilities
5 CVEs this actor has used in observed campaigns. 5 of them exploited in the wild.
APT33 has used a publicly available exploit for CVE-2017-0213 to escalate privileges on a local system.
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
In a recent wave of attacks during February 2019, Elfin attempted to exploit a known vulnerability (CVE-2018-20250) in WinRAR... If successfully exploited on an unpatched computer, the vulnerability could permit an attacker to install any file on the computer, which effectively permits code execution on the targeted computer.
Peach Sandstorm also attempted to exploit vulnerabilities with a public proof-of-concept (POC) in Zoho ManageEngine or Confluence, to access targets’ environments. CVE-2022-47966 is a remote code execution vulnerability affecting a subset of on-premises Zoho ManageEngine products. Microsoft recommends organizations using vulnerable applications patch this vulnerability as multiple groups have been observed exploiting this vulnerability.
The following analytic detects when su runs from a page-cache-corrupted binary... This activity is significant because it indicates a possible privilege escalation attempt, allowing a user to gain root access... CVE CVE-2026-31431 ... References ... copy-fail-CVE-2026-31431
Observables
47 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced in the detection annotations as a threat actor associated with exploitation for privilege escalation activity.
Listed as a threat actor associated with PowerShell execution behavior relevant to this detection.
Listed in the analytic annotations as a threat actor associated with exploitation for privilege escalation.
Listed as a threat actor associated with exploitation for privilege escalation in the context of this Linux malformed authentication entry detection.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.