◇ SIGN IN
← all actors
apt

APT33

activehigh confidence
APT / State-sponsored
HOLMIUMElfinPeach SandstormRefined Kitten
Attribution
Iran — suspected IRGC-aligned
Origin
Iran
First seen
2013
Last active
2026
Motivation
Espionage
Confidence
high
MENA targeting
Saudi Arabia (primary), broader Gulf
Sectors
Aviation, aerospace, energy, petrochemical
MITRE ATT&CK
Why it mattersState-sponsored / APT actor, high confidence, documented targeting Saudi Arabia (primary), broader Gulf (Aviation, aerospace, energy sectors).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.

APT33 (Peach Sandstorm) is a suspected Iranian threat group active since at least 2013, focused on aviation, defense, energy, and oil-and-gas targets in Saudi Arabia, the wider Gulf, and the United States, with a history linking espionage access to destructive capability.

History

APT33 was first documented by FireEye in 2017 for operations dating to at least 2013. The group is assessed as Iranian and is widely linked to Iranian military/IRGC interests, though public attribution to a specific service remains less definitive than for MOIS clusters like OilRig or MuddyWater. Microsoft tracks the actor as Peach Sandstorm.

Historically APT33 combined password-spraying and credential-harvesting against cloud and enterprise accounts with custom malware, and it maintained links to destructive tooling (the SHAPESHIFT/StoneDrill wiper lineage), giving it a dual espionage-and-sabotage posture that distinguishes it from purely intelligence-driven peers.

The Gulf is APT33's principal target region. Saudi Arabia — particularly aviation and energy/petrochemical organizations — has been a persistent focus, alongside U.S. and South Korean entities in the same verticals. This targeting aligns closely with Iranian strategic and economic-rivalry interests in the Gulf.

APT33 remains active into 2025–2026. In August 2024 Microsoft detailed a custom multi-stage backdoor, Tickler, deployed April–July 2024 against satellite, communications, oil-and-gas, and government targets in the U.S. and UAE, using fraudulently created attacker-controlled Azure subscriptions for C2. Subsequent reporting describes continued Tickler activity in the UAE and broader Gulf and assesses APT33 as retaining a high-risk dual posture in which espionage footholds in aerospace and energy networks could be repurposed for wiper deployment during Iranian escalation.

Notable campaigns

2017
Aviation & petrochemical espionage
FireEye-documented spearphishing against Saudi and U.S. aviation and energy organizations.
2019
Password-spraying operations
Large-scale credential attacks against Gulf and U.S. targets, blending espionage with wiper-linked tooling.
2024
Tickler backdoor campaign
Custom multi-stage backdoor deployed against U.S. and UAE satellite, oil-and-gas, and government sectors using fraudulent Azure C2.
2026
Sustained Gulf intelligence access
Continued espionage access in aerospace and energy networks assessed as repurposable for destructive operations.

Observed ATT&CK techniques · 34

TechniqueNameTacticObserved use
T1560.001Archive Collected Data: Archive via UtilitycollectionAPT33 has used WinRAR to compress data prior to exfil.
T0852Screen Capture (ICS)collection (ICS)APT33 utilizes backdoors capable of capturing screenshots.
T1071.001Application Layer Protocol: Web Protocolscommand and controlAPT33 has used HTTP for command and control.
T1132.001Data Encoding: Standard Encodingcommand and controlAPT33 has used base64 to encode command and control traffic.
T1105Ingress Tool Transfercommand and controlAPT33 has downloaded additional files and programs from its C2 server.
T1573.001Encrypted Channel: Symmetric Cryptographycommand and controlAPT33 has used AES for encryption of command and control traffic.
T1571Non-Standard Portcommand and controlAPT33 has used HTTP over TCP ports 808 and 880 for command and control.
T1110.003Brute Force: Password Sprayingcredential accessAPT33 has used password spraying to gain access to target systems.
T1003.005OS Credential Dumping: Cached Domain Credentialscredential accessAPT33 has used LaZagne to gather cached domain credentials.
T1003.001OS Credential Dumping: LSASS Memorycredential accessAPT33 used LaZagne, Mimikatz, and ProcDump to dump credentials.
T1003.004OS Credential Dumping: LSA Secretscredential accessAPT33 has used LaZagne to gather credentials from LSA Secrets.
T1552.001Unsecured Credentials: Credentials In Filescredential accessAPT33 used LaZagne to gather credentials stored in files.
T1552.006Unsecured Credentials: Group Policy Preferencescredential accessAPT33 used Gpppassword to gather credentials from Group Policy.
T1555Credentials from Password Storescredential accessAPT33 has used publicly available tools like LaZagne to gather credentials.
T1555.003Credentials from Password Stores: Credentials from Web Browserscredential accessAPT33 has used LaZagne to gather credentials from web browsers.
T1040Network Sniffingcredential access, discoveryAPT33 has used SniffPass to collect credentials by sniffing network traffic.
T1203Exploitation for Client ExecutionexecutionAPT33 exploited WinRAR vulnerability CVE-2018-20250 and CVE-2017-11774.
T1059.001Command and Scripting Interpreter: PowerShellexecutionAPT33 has utilized PowerShell to download files from C2 and run scripts.
T1059.005Command and Scripting Interpreter: Visual BasicexecutionAPT33 has used VBScript to initiate the delivery of payloads.
T1204.001User Execution: Malicious LinkexecutionAPT33 lured users to click malicious HTML app links via spearphishing.
T1204.002User Execution: Malicious FileexecutionAPT33 used malicious e-mail attachments to lure victims into execution.
T0853Scripting (ICS)execution (ICS)APT33 utilized PowerShell scripts for C2 and file installation.
T1053.005Scheduled Task/Job: Scheduled Taskexecution, persistence, privilege escalationAPT33 created a scheduled task to execute a .vbe file multiple times daily.
T1048.003Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted Non-C2 ProtocolexfiltrationAPT33 has used FTP to exfiltrate files separately from the C2 channel.
T1566.001Phishing: Spearphishing Attachmentinitial accessAPT33 has sent spearphishing e-mails with archive attachments.
T1566.002Phishing: Spearphishing Linkinitial accessAPT33 has sent spearphishing emails containing links to .hta files.
T0865Spearphishing Attachment (ICS)initial access (ICS)APT33 sent spearphishing emails with malicious HTML application links.
T1078Valid Accountsinitial access, persistence, privilege escalation, stealthAPT33 has used valid accounts for initial access and escalation.
T1078.004Valid Accounts: Cloud Accountsinitial access, persistence, privilege escalation, stealthAPT33 used compromised Office 365 accounts with Ruler for endpoint control.
T1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folderpersistence, privilege escalationAPT33 has deployed DarkComet to the Startup folder and used Registry run keys for persistence.
T1546.003Event Triggered Execution: Windows Management Instrumentation Event Subscriptionpersistence, privilege escalationAPT33 has attempted to use WMI event subscriptions for persistence.
T1068Exploitation for Privilege Escalationprivilege escalationAPT33 has used a public exploit for CVE-2017-0213 to escalate privileges.
T1588.002Obtain Capabilities: Toolresource developmentAPT33 has obtained and leveraged publicly-available tools for early intrusion.
T1027.013Obfuscated Files or Information: Encrypted/Encoded FilestealthAPT33 has used base64 to encode payloads.