APT33

APT / StateG0064 ↗
Origin🇮🇷 Irã
Techniques (MITRE ATT&CK)31
SourceMITRE ATT&CK
State sponsor: Iran (Islamic Republic of)Attribution confidence: 50%Target categories: Private sector
Targeted regions: United States · Saudi Arabia · South Korea
Also known as:ATK35BLEAK IONCOBALT TRINITYElfinG0064HOLMIUMMAGNALLIUMPeach SandstormRefined KittenTA451

Vexday analysis

Grupo de origem iraniana rastreado pelo MITRE ATT&CK como G0064, o APT33 — também conhecido como HOLMIUM, Elfin e Peach Sandstorm — conduz operações desde pelo menos 2013, tendo como alvos organizações nos Estados Unidos, Arábia Saudita e Coreia do Sul, com interesse particular nos setores de aviação e energia. Ao grupo são atribuídas 31 técnicas documentadas no framework MITRE ATT&CK e 4 CVEs conhecidas por sua exploração.

Attack chain

Plausible scenario built from the group's real techniques, ordered by the phases of an attack. Each step shows how the group typically operates.

Arsenal severity63
Impact: High
T1566.001T1053.005T1547.001T1068T1003.001T1560.001ENTRYInitial accessSpearphishingAttachmentEXECExecutionScheduled TaskPERSPersistenceRegistry Run Keys/ Startup FolderPRIVPrivilege escalationExploitation forPrivilege Escalat…CREDCredential accessLSASS MemoryCOLLCollectionArchive viaUtilityEXFILExfiltrationExfiltration OverUnencrypted Non-C…

Illustrative chain derived from techniques documented in MITRE ATT&CK — it does not represent a specific past attack. Severity summarizes the known arsenal (kill-chain coverage, actively exploited CVEs, techniques).

Exploited vulnerabilities 4

CVEs this group is known to exploit, per MITRE ATT&CK. Ordered by real-world severity.

Known infrastructure 28

Real indicators (C2, domains, URLs and hashes) associated with the malware this group uses. Source: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).

sha256_hashea9f1901741fb76ca5eb7f48415d33d4eb7bc6fa3f3d8a47aa3babe8c1376efdNanoCoremalwarebazaar
urlhttp://92.127.156.174:8880/master.exeMimiKatzthreatfox
ip:port137.184.139.185:8080PoshC2threatfox
sha256_hashf634762210e39bf8b8f436b40ee1cb122431f5558f96465c9f2e01cd8856296dNanoCoremalwarebazaar
sha256_hashe946713a98d119096e00d3c536d74608269bc402e0af213ec77e874a17f3164aNanoCoremalwarebazaar
sha256_hash22ae11d4d8971b1b1bc2c80b7a70e59dadd6112bc1ecfce750093d1d5f87e27fPoshC2threatfox
sha256_hashb106b83f8537dd027ba91b3994e1990c0ad195cc8a6ad37115cf8627b21a8797NanoCoremalwarebazaar
sha256_hash2471a6c8da3933f1d8ba41a136fa0ca185801dfd26f73d2f8791449007153444NanoCoremalwarebazaar
md5_hashfec27228340485485f6902f8759bbd62MimiKatzthreatfox
sha256_hashf9d53fdcc12d548e6c9bd395642f30d2b2c6a9a4204bc0948badf8a7c571c072MimiKatzthreatfox
sha1_hash07b35a3b431e653ddcf36cecd49793d538e2aa79MimiKatzthreatfox
ip:port52.41.190.254:443PoshC2threatfox
ip:port137.184.139.185:443PoshC2threatfox
ip:port159.223.145.166:443PoshC2threatfox
ip:port13.236.153.60:443PoshC2threatfox
sha256_hashbf5fb2be03196a2931ed05489bcd245fabaa63ecd4ba67eee64af468c12f6148NanoCoremalwarebazaar
sha256_hash24f100f0064fceabca8917f51631a4a987dc20cea19dda11d11f773534c54c8eNanoCoremalwarebazaar
sha256_hash9bf266d90d33000f52e6d46a6329a4b85c9477180b8eb20f840a0852bf3e9814NanoCoremalwarebazaar
sha256_hash50c73ca933a5d95e73a74b83d62084c85ad3f8acd39af2d218763a9270825dc2NanoCoremalwarebazaar
sha256_hashd733c41692ef27d0a925ed79d5b09d9ff981c943e6a686d245cf420e06043b95NanoCoremalwarebazaar
sha256_hashd96fc5f700b931e47dee0b979f267ac803f02a6726a4cb6464daf7dd17bc17feNanoCoremalwarebazaar
ip:port176.120.22.129:443PoshC2threatfox
sha256_hash551aa018350fcf2b435b4d361dd4f117349a5136851f84ac10c02da1526e4e67NanoCoremalwarebazaar
sha1_hashc5ec7e2ad924e832e49fbac9d0c82719b570e080MimiKatzthreatfox
md5_hash77c96f339974b65ae435313a8fcc3b35MimiKatzthreatfox
sha256_hash889cc3e793cb39889c7acc8e73a84973e9a08fcd69451f7b546509c74ffdda90MimiKatzthreatfox
urlhttp://spasopro.at/Lsge63sd3/bb.exeNanoCoreurlhaus
urlhttp://spasopro.at/Lsge63sd3/okey.exeNanoCoreurlhaus

APT33 uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →