Threat group.View on attack.mitre.org
APT33 is a suspected Iranian threat group that has carried out operations since at least 2013. The group has targeted organizations across multiple industries in the United States, Saudi Arabia, and South Korea, with a particular interest in the aviation and energy sectors.
| Technique | Procedure example |
|---|---|
| T1003.001 LSASS Memory |
APT33 has used a variety of publicly available tools like LaZagne, Mimikatz, and ProcDump to dump credentials. |
| T1003.004 LSA Secrets |
APT33 has used a variety of publicly available tools like LaZagne to gather credentials. |
| T1003.005 Cached Domain Credentials |
APT33 has used a variety of publicly available tools like LaZagne to gather credentials. |
| T1027.013 Encrypted/Encoded File |
APT33 has used base64 to encode payloads. |
| T1040 Network Sniffing |
APT33 has used SniffPass to collect credentials by sniffing network traffic. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
APT33 has used FTP to exfiltrate files (separately from the C2 channel). |
| T1053.005 Scheduled Task |
APT33 has created a scheduled task to execute a .vbe file multiple times a day. |
| T1059.001 PowerShell |
APT33 has utilized PowerShell to download files from the C2 server and run various scripts. |
| T1059.005 Visual Basic |
APT33 has used VBScript to initiate the delivery of payloads. |
| T1068 Exploitation for Privilege Escalation |
APT33 has used a publicly available exploit for CVE-2017-0213 to escalate privileges on a local system. |
| T1071.001 Web Protocols |
APT33 has used HTTP for command and control. |
| T1078 Valid Accounts |
APT33 has used valid accounts for initial access and privilege escalation. |
| T1078.004 Cloud Accounts |
APT33 has used compromised Office 365 accounts in tandem with Ruler in an attempt to gain control of endpoints. |
| T1105 Ingress Tool Transfer |
APT33 has downloaded additional files and programs from its C2 server. |
| T1110.003 Password Spraying |
APT33 has used password spraying to gain access to target systems. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.