APT33 (Peach Sandstorm) is a suspected Iranian threat group active since at least 2013, focused on aviation, defense, energy, and oil-and-gas targets in Saudi Arabia, the wider Gulf, and the United States, with a history linking espionage access to destructive capability.
Additional names this actor is known by across other vendors' naming schemes — cross-referenced from external crosswalk sources, not RaqibCTI's own curated aliases (shown at the top of this page). Each source is attributed to its own licence.
+35 more relationships — see the relationships browser.
APT33 was first documented by FireEye in 2017 for operations dating to at least 2013. The group is assessed as Iranian and is widely linked to Iranian military/IRGC interests, though public attribution to a specific service remains less definitive than for MOIS clusters like OilRig or MuddyWater. Microsoft tracks the actor as Peach Sandstorm.
Historically APT33 combined password-spraying and credential-harvesting against cloud and enterprise accounts with custom malware, and it maintained links to destructive tooling (the SHAPESHIFT/StoneDrill wiper lineage), giving it a dual espionage-and-sabotage posture that distinguishes it from purely intelligence-driven peers.
The Gulf is APT33's principal target region. Saudi Arabia — particularly aviation and energy/petrochemical organizations — has been a persistent focus, alongside U.S. and South Korean entities in the same verticals. This targeting aligns closely with Iranian strategic and economic-rivalry interests in the Gulf.
APT33 remains active into 2025–2026. In August 2024 Microsoft detailed a custom multi-stage backdoor, Tickler, deployed April–July 2024 against satellite, communications, oil-and-gas, and government targets in the U.S. and UAE, using fraudulently created attacker-controlled Azure subscriptions for C2. Subsequent reporting describes continued Tickler activity in the UAE and broader Gulf and assesses APT33 as retaining a high-risk dual posture in which espionage footholds in aerospace and energy networks could be repurposed for wiper deployment during Iranian escalation.