G0064: APT33
APT33 is a suspected Iranian threat group that has carried out operations since at least 2013. The group has targeted organizations across multiple industries in the United States, Saudi Arabia, and South Korea, with a particular interest in the aviation and energy sectors.CitationFireEye APT33 Sept 2017CitationFireEye APT33 Webinar Sept 2017
Security context for executives and security teams
APT33 matters because MITRE describes it as a suspected Iranian group active since at least 2013 with reported targeting across the United States, Saudi Arabia, and South Korea, especially aviation and energy. The relationship set is operationally important: it links the group to credential-dumping, PowerShell/post-exploitation frameworks, remote access tools, FTP transfer, Exchange/Office abuse tooling, and wiper malware. For leaders, the decision value is not the name alone; it is whether identity controls, Windows endpoint visibility, email security, remote access monitoring, and recovery plans can withstand the behaviors represented by these relationships.
Executive priority
Prioritize APT33 as a threat-intelligence-informed readiness driver if the organization operates in aviation, energy, Saudi/U.S./South Korea exposure, or environments where IT compromise could affect operational technology. Executive questions should focus on: can the SOC prove visibility over credential theft and PowerShell activity; can IR contain compromised Windows credentials quickly; are destructive-malware recovery assumptions tested; and do audit/compliance records show controls over email attachments, privileged accounts, logging, segmentation, and backups?
Technical view
MITRE provides no official detection text for the group, so defenders should build coverage from the related software and techniques. Validate detections for Windows credential access involving LSASS memory, LSA Secrets, and cached domain credentials; command-line use of Net and ftp; PowerShell-heavy frameworks such as PowerSploit, Empire, PoshC2, and POWERTON; RAT/backdoor families including NETWIRE, NanoCore, Pupy, TURNEDUP, and AutoIt backdoor; Exchange/Office abuse associated with Ruler; obfuscated or encoded files; and network sniffing behavior where relevant. The ICS relationships for screen capture, scripting, and spearphishing attachment make OT-facing monitoring and phishing controls relevant where control-system environments exist.
Likely telemetry
- Endpoint process creation, command-line, parent/child process, module load, and script execution logs, especially on Windows systems
- PowerShell logging and administrative shell telemetry
- Windows security events and EDR signals related to LSASS access, registry access to LSA Secrets, and credential-dumping tools such as Mimikatz and LaZagne
- Email gateway, attachment detonation, and user-reporting telemetry for spearphishing attachments
- Office Suite and Exchange service logs relevant to Ruler-like abuse
Detection direction
- Correlate across aliases APT33, HOLMIUM, Elfin, and Peach Sandstorm so intelligence, case management, and SIEM content do not fragment the same ATT&CK group reference.
- Do not rely only on malware names. Several related tools are public or legitimate administrative utilities, so detection should combine behavior, execution context, privilege level, destination, and sequence.
- Tune for credential-access chains: suspicious LSASS access, LSA Secrets access, cached credential access, followed by lateral movement or remote administration activity should receive higher priority.
- Validate PowerShell and scripting coverage because multiple related tools and backdoors use scripting or PowerShell-style post-exploitation.
- Review false positives for Net, ftp, PowerSploit, Empire, PoshC2, Pupy, and other dual-use tools by comparing expected administrative baselines with unusual hosts, users, timing, and network destinations.
Mitigation priorities
- Start with identity hardening: restrict privileged access, reduce credential exposure, monitor administrative accounts, and limit cached or reusable credentials where operationally feasible.
- Harden Windows endpoints against credential dumping and unauthorized access to LSASS and sensitive registry secrets.
- Constrain and log PowerShell, scripting interpreters, and command-line administrative utilities without blocking legitimate operations blindly.
- Strengthen email attachment defenses, user reporting, and investigation workflows for targeted phishing scenarios.
- Control outbound transfer paths such as FTP and monitor unusual remote administration traffic.
Additional notes and limits
This take is based on MITRE ATT&CK group G0064, its aliases, official description, external references, and supplied relationship context. The most useful defensive interpretation comes from the related software and techniques rather than from a group-level detection field, which is not provided. APT33 should be used as a threat-informed planning scenario, especially for aviation, energy, identity, endpoint, email, and recovery readiness.
MITRE does not specify group-level platforms, tactics, or official detection guidance for this object. Relationship descriptions include multiple public, dual-use, and cross-platform tools, so local baselines are required before treating activity as malicious. The supplied data supports historical targeting and relationships, not current exploitation, confirmed attribution in a local incident, or guaranteed detection coverage.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
APT33
APT33 is a suspected Iranian threat group that has carried out operations since at least 2013. The group has targeted organizations across multiple industries in the United States, Saudi Arabia, and South Korea, with a particular interest in the aviation and energy sectors.CitationFireEye APT33 Sept 2017CitationFireEye APT33 Webinar Sept 2017
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
All related ATT&CK context
No relationships are available in the current normalized data for this object.
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
