APT33
Aliases: HOLMIUM, Elfin, Peach Sandstorm
APT33 is a suspected Iranian threat group that has carried out operations since at least 2013. The group has targeted organizations across multiple industries in the United States, Saudi Arabia, and South Korea, with a particular interest in the aviation and energy sectors.
Open interactive actor investigation
ATT&CK techniques
T1552.001
Credentials In FilesT1003.005
Cached Domain CredentialsT1560.001
Archive via UtilityT1555.003
Credentials from Web BrowsersT1552.006
Group Policy PreferencesT1027.013
Encrypted/Encoded FileT1566.001
Spearphishing AttachmentT1003.001
LSASS MemoryT1566.002
Spearphishing LinkT1110.003
Password SprayingT1003.004
LSA SecretsT1053.005
Scheduled TaskT1555
Credentials from Password StoresT1546.003
Windows Management Instrumentation Event SubscriptionT1105
Ingress Tool TransferT1048.003
Exfiltration Over Unencrypted Non-C2 ProtocolT1588.002
ToolT1040
Network SniffingT1071.001
Web ProtocolsT1059.001
PowerShellT1547.001
Registry Run Keys / Startup FolderT1078
Valid AccountsT1573.001
Symmetric CryptographyT1059.005
Visual BasicT1132.001
Standard EncodingT1571
Non-Standard PortT1078.004
Cloud AccountsT1203
Exploitation for Client ExecutionT1204.002
Malicious FileT1204.001
Malicious LinkT1068
Exploitation for Privilege EscalationT1480
Execution Guardrails
Credentials In FilesT1003.005
Cached Domain CredentialsT1560.001
Archive via UtilityT1555.003
Credentials from Web BrowsersT1552.006
Group Policy PreferencesT1027.013
Encrypted/Encoded FileT1566.001
Spearphishing AttachmentT1003.001
LSASS MemoryT1566.002
Spearphishing LinkT1110.003
Password SprayingT1003.004
LSA SecretsT1053.005
Scheduled TaskT1555
Credentials from Password StoresT1546.003
Windows Management Instrumentation Event SubscriptionT1105
Ingress Tool TransferT1048.003
Exfiltration Over Unencrypted Non-C2 ProtocolT1588.002
ToolT1040
Network SniffingT1071.001
Web ProtocolsT1059.001
PowerShellT1547.001
Registry Run Keys / Startup FolderT1078
Valid AccountsT1573.001
Symmetric CryptographyT1059.005
Visual BasicT1132.001
Standard EncodingT1571
Non-Standard PortT1078.004
Cloud AccountsT1203
Exploitation for Client ExecutionT1204.002
Malicious FileT1204.001
Malicious LinkT1068
Exploitation for Privilege EscalationT1480
Execution Guardrails