LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G0064: APT33

APT33 is a suspected Iranian threat group that has carried out operations since at least 2013. The group has targeted organizations across multiple industries in the United States, Saudi Arabia, and South Korea, with a particular interest in the aviation and energy sectors.CitationFireEye APT33 Sept 2017CitationFireEye APT33 Webinar Sept 2017

EnterpriseG0064GroupObject v2.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

APT33 matters because MITRE describes it as a suspected Iranian group active since at least 2013 with reported targeting across the United States, Saudi Arabia, and South Korea, especially aviation and energy. The relationship set is operationally important: it links the group to credential-dumping, PowerShell/post-exploitation frameworks, remote access tools, FTP transfer, Exchange/Office abuse tooling, and wiper malware. For leaders, the decision value is not the name alone; it is whether identity controls, Windows endpoint visibility, email security, remote access monitoring, and recovery plans can withstand the behaviors represented by these relationships.

Executive priority

Prioritize APT33 as a threat-intelligence-informed readiness driver if the organization operates in aviation, energy, Saudi/U.S./South Korea exposure, or environments where IT compromise could affect operational technology. Executive questions should focus on: can the SOC prove visibility over credential theft and PowerShell activity; can IR contain compromised Windows credentials quickly; are destructive-malware recovery assumptions tested; and do audit/compliance records show controls over email attachments, privileged accounts, logging, segmentation, and backups?

Technical view

MITRE provides no official detection text for the group, so defenders should build coverage from the related software and techniques. Validate detections for Windows credential access involving LSASS memory, LSA Secrets, and cached domain credentials; command-line use of Net and ftp; PowerShell-heavy frameworks such as PowerSploit, Empire, PoshC2, and POWERTON; RAT/backdoor families including NETWIRE, NanoCore, Pupy, TURNEDUP, and AutoIt backdoor; Exchange/Office abuse associated with Ruler; obfuscated or encoded files; and network sniffing behavior where relevant. The ICS relationships for screen capture, scripting, and spearphishing attachment make OT-facing monitoring and phishing controls relevant where control-system environments exist.

Likely telemetry

  • Endpoint process creation, command-line, parent/child process, module load, and script execution logs, especially on Windows systems
  • PowerShell logging and administrative shell telemetry
  • Windows security events and EDR signals related to LSASS access, registry access to LSA Secrets, and credential-dumping tools such as Mimikatz and LaZagne
  • Email gateway, attachment detonation, and user-reporting telemetry for spearphishing attachments
  • Office Suite and Exchange service logs relevant to Ruler-like abuse

Detection direction

  • Correlate across aliases APT33, HOLMIUM, Elfin, and Peach Sandstorm so intelligence, case management, and SIEM content do not fragment the same ATT&CK group reference.
  • Do not rely only on malware names. Several related tools are public or legitimate administrative utilities, so detection should combine behavior, execution context, privilege level, destination, and sequence.
  • Tune for credential-access chains: suspicious LSASS access, LSA Secrets access, cached credential access, followed by lateral movement or remote administration activity should receive higher priority.
  • Validate PowerShell and scripting coverage because multiple related tools and backdoors use scripting or PowerShell-style post-exploitation.
  • Review false positives for Net, ftp, PowerSploit, Empire, PoshC2, Pupy, and other dual-use tools by comparing expected administrative baselines with unusual hosts, users, timing, and network destinations.

Mitigation priorities

  • Start with identity hardening: restrict privileged access, reduce credential exposure, monitor administrative accounts, and limit cached or reusable credentials where operationally feasible.
  • Harden Windows endpoints against credential dumping and unauthorized access to LSASS and sensitive registry secrets.
  • Constrain and log PowerShell, scripting interpreters, and command-line administrative utilities without blocking legitimate operations blindly.
  • Strengthen email attachment defenses, user reporting, and investigation workflows for targeted phishing scenarios.
  • Control outbound transfer paths such as FTP and monitor unusual remote administration traffic.
Additional notes and limits

This take is based on MITRE ATT&CK group G0064, its aliases, official description, external references, and supplied relationship context. The most useful defensive interpretation comes from the related software and techniques rather than from a group-level detection field, which is not provided. APT33 should be used as a threat-informed planning scenario, especially for aviation, energy, identity, endpoint, email, and recovery readiness.

MITRE does not specify group-level platforms, tactics, or official detection guidance for this object. Relationship descriptions include multiple public, dual-use, and cross-platform tools, so local baselines are required before treating activity as malicious. The supplied data supports historical targeting and relationships, not current exploitation, confirmed attribution in a local incident, or guaranteed detection coverage.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

APT33

APT33 is a suspected Iranian threat group that has carried out operations since at least 2013. The group has targeted organizations across multiple industries in the United States, Saudi Arabia, and South Korea, with a particular interest in the aviation and energy sectors.CitationFireEye APT33 Sept 2017CitationFireEye APT33 Webinar Sept 2017

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

Relationship explorer

All related ATT&CK context

No relationships are available in the current normalized data for this object.

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
2.0
Created
Modified
Raw hash
8bce83bff7b0e88f...
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.