APT33

G0064

Threat group.View on attack.mitre.org

About this group

APT33 is a suspected Iranian threat group that has carried out operations since at least 2013. The group has targeted organizations across multiple industries in the United States, Saudi Arabia, and South Korea, with a particular interest in the aviation and energy sectors.

Techniques used31

Procedure examples31

TechniqueProcedure example
T1003.001
LSASS Memory

APT33 has used a variety of publicly available tools like LaZagne, Mimikatz, and ProcDump to dump credentials.

T1003.004
LSA Secrets

APT33 has used a variety of publicly available tools like LaZagne to gather credentials.

T1003.005
Cached Domain Credentials

APT33 has used a variety of publicly available tools like LaZagne to gather credentials.

T1027.013
Encrypted/Encoded File

APT33 has used base64 to encode payloads.

T1040
Network Sniffing

APT33 has used SniffPass to collect credentials by sniffing network traffic.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol

APT33 has used FTP to exfiltrate files (separately from the C2 channel).

T1053.005
Scheduled Task

APT33 has created a scheduled task to execute a .vbe file multiple times a day.

T1059.001
PowerShell

APT33 has utilized PowerShell to download files from the C2 server and run various scripts.

T1059.005
Visual Basic

APT33 has used VBScript to initiate the delivery of payloads.

T1068
Exploitation for Privilege Escalation

APT33 has used a publicly available exploit for CVE-2017-0213 to escalate privileges on a local system.

T1071.001
Web Protocols

APT33 has used HTTP for command and control.

T1078
Valid Accounts

APT33 has used valid accounts for initial access and privilege escalation.

T1078.004
Cloud Accounts

APT33 has used compromised Office 365 accounts in tandem with Ruler in an attempt to gain control of endpoints.

T1105
Ingress Tool Transfer

APT33 has downloaded additional files and programs from its C2 server.

T1110.003
Password Spraying

APT33 has used password spraying to gain access to target systems.

View all 31 procedure examples

Software16

Campaigns0

None recorded.

References2

  1. FireEye APT33 Sept 2017 Open source
    O'Leary, J., et al. (2017, September 20). Insights into Iranian Cyber Espionage: APT33 Targets Aerospace and Energy Sectors and has Ties to Destructive Malware. Retrieved February 15, 2018.
  2. FireEye APT33 Webinar Sept 2017 Open source
    Davis, S. and Carr, N. (2017, September 21). APT33: New Insights into Iranian Cyber Espionage Group. Retrieved February 15, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.