APT33

APT / StateG0064
Origin🇮🇷 Irã
Techniques (MITRE ATT&CK)31
SourceMITRE ATT&CK
State sponsor: Iran (Islamic Republic of)Attribution confidence: 50%Target categories: Private sector
Targeted regions: United States · Saudi Arabia · South Korea
Also known as:HOLMIUMElfinPeach Sandstorm

Vexday analysis

Grupo de origem iraniana rastreado pelo MITRE ATT&CK como G0064, o APT33 — também conhecido como HOLMIUM, Elfin e Peach Sandstorm — conduz operações desde pelo menos 2013, tendo como alvos organizações nos Estados Unidos, Arábia Saudita e Coreia do Sul, com interesse particular nos setores de aviação e energia. Ao grupo são atribuídas 31 técnicas documentadas no framework MITRE ATT&CK e 4 CVEs conhecidas por sua exploração.

Attack chain

Plausible scenario built from the group's real techniques, ordered by the phases of an attack. Each step shows how the group typically operates.

Arsenal severity63
Impact: High
T1566.001T1053.005T1547.001T1068T1003.001T1560.001ENTRYInitial accessSpearphishingAttachmentEXECExecutionScheduled TaskPERSPersistenceRegistry Run Keys/ Startup FolderPRIVPrivilege escalationExploitation forPrivilege Escalat…CREDCredential accessLSASS MemoryCOLLCollectionArchive viaUtilityEXFILExfiltrationExfiltration OverUnencrypted Non-C…

Illustrative chain derived from techniques documented in MITRE ATT&CK — it does not represent a specific past attack. Severity summarizes the known arsenal (kill-chain coverage, actively exploited CVEs, techniques).

Exploited vulnerabilities 4

CVEs this group is known to exploit, per MITRE ATT&CK. Ordered by real-world severity.

Known infrastructure 14

Real indicators (C2, domains, URLs and hashes) associated with the malware this group uses. Source: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).

ip:port13.236.153.60:443PoshC2threatfox
sha256_hashbf5fb2be03196a2931ed05489bcd245fabaa63ecd4ba67eee64af468c12f6148NanoCoremalwarebazaar
sha256_hash24f100f0064fceabca8917f51631a4a987dc20cea19dda11d11f773534c54c8eNanoCoremalwarebazaar
sha256_hash9bf266d90d33000f52e6d46a6329a4b85c9477180b8eb20f840a0852bf3e9814NanoCoremalwarebazaar
sha256_hash50c73ca933a5d95e73a74b83d62084c85ad3f8acd39af2d218763a9270825dc2NanoCoremalwarebazaar
sha256_hashd733c41692ef27d0a925ed79d5b09d9ff981c943e6a686d245cf420e06043b95NanoCoremalwarebazaar
sha256_hashd96fc5f700b931e47dee0b979f267ac803f02a6726a4cb6464daf7dd17bc17feNanoCoremalwarebazaar
ip:port176.120.22.129:443PoshC2threatfox
sha256_hash551aa018350fcf2b435b4d361dd4f117349a5136851f84ac10c02da1526e4e67NanoCoremalwarebazaar
sha1_hashc5ec7e2ad924e832e49fbac9d0c82719b570e080MimiKatzthreatfox
md5_hash77c96f339974b65ae435313a8fcc3b35MimiKatzthreatfox
sha256_hash889cc3e793cb39889c7acc8e73a84973e9a08fcd69451f7b546509c74ffdda90MimiKatzthreatfox
urlhttp://spasopro.at/Lsge63sd3/bb.exeNanoCoreurlhaus
urlhttp://spasopro.at/Lsge63sd3/okey.exeNanoCoreurlhaus

APT33 uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →