APT33 — what to detect, and what we don’t know.

Saudi aviation and petrochemical, with a wiper in the toolkit.

31 techniques 12 detection behaviours 16 tools mapped Saudi Arabia

Also tracked as  APT 33 · Elfin · MAGNALLIUM · Refined Kitten · HOLMIUM · COBALT TRINITY · G0064 · ATK35 · Peach Sandstorm · TA451 · BLEAK ION · REFINED KITTEN

Attributed to
IR Iran (Islamic Republic of)
Gulf victimology
1 Saudi Arabia
Techniques
31 across 10 tactics
Tooling
16 5 actor-specific · 11 commodity
Reporting
16 5 outlets · 17 research hosts

Summary

The short version

APT33 is a threat actor attributed to Iran (Islamic Republic of), assessed as espionage-motivated. Its recorded targeting runs to private sector across 3 countries in the open reporting we hold — Saudi Arabia among them.

Across 31 attributed ATT&CK techniques we resolve 12 distinct behaviours — the things they do that a detection can be written against. The two that account for most of their observed tradecraft are valid account abuse or account creation and persistence pointing into world-writable staging. Their toolkit is 16 named items: 5 we see only in this actor's reporting and 11 commodity or dual-use. That ratio is the point — the first group is what identifies them, the second is what they share with every other group and with red teams.

For a Gulf defender the relevant line is the victimology: Saudi Arabia appear in the reporting behind this record. That is evidence of past targeting, not a forecast, and it is drawn from what vendors chose to publish — an actor working quietly in a market nobody reports on looks identical to one that is absent.

As MITRE describes them: “Our analysis reveals that APT33 is a capable group that has carried out cyber espionage operations since at least 2013. We assess APT33 works at the behest of the Iranian government.” — MITRE ATT&CK, CC BY 4.0.

On the name. “APT33” labels a cluster of related activity tracked under one name — not a verified organisation. Whether one team, several contractors or a rotating cast sits behind it is not something this record establishes, and the vendor names below are separate groupings that only mostly overlap.

02 — The detection plan

What to detect, ranked by what survives their retooling

Most actor profiles hand you indicators that expire in days. These are the behaviours the actor cannot drop without changing how they operate, each with the reason it holds. Weight is our own: how much of the actor's observed tradecraft the behaviour accounts for.

D1

Persistence pointing into world-writable staging

Tier 1–2

The persistence mechanism and the directory it points at both outlive the payload. The discriminator is the TARGET PATH, not the task or key name, which the actor can change freely.

8 techniques · weight 5

D2

Credential access against LSASS

Tier 3–5

Few legitimate processes read LSASS memory, so precision is high in most estates once the agents that do are excluded.

2 techniques · weight 5

D3

User-facing application spawning an interpreter

Tier 3

The delivery wrapper changes constantly; an office, archive or browser process parenting a shell is the same shape across all of them.

8 techniques · weight 5

D4

Credential store or keystroke capture

Tier 3

Kept separate from the LSASS rule because it needs different telemetry and tunes differently — a browser credential store read by a non-browser process is its own signal.

8 techniques · weight 4

D5

Encoded or obfuscated interpreter invocation

Tier 3

The command-line SHAPE — the flag combination, not the payload — is stable for months to years and cheap to match.

8 techniques · weight 4

D6

Password spraying or credential stuffing

Context

Visible only in identity telemetry, and the failure-then-success shape is what distinguishes it from ordinary user error.

6 techniques · weight 3

D7

Living-off-the-land download of a second stage

Tier 5

The set of system binaries that can fetch a file is small and changes with the OS, not with the actor.

5 techniques · weight 3

D8

Collection staged into an archive before egress

Tier 3

Staging is a step the actor cannot skip, and it happens before the data leaves — the last cheap place to catch it.

7 techniques · weight 3

D9

Exploitation of an internet-facing service

Context

Not a durable behavioural signature but the entry vector for a large public estate — worth an exposure control even where the detection is weak.

3 techniques · weight 3

D10

Protocol tunnelling or an internal proxy hop

Tier 5

The tunneller is a tool choice that persists for months, and the traffic shape is visible even when the payload is not.

8 techniques · weight 3

D11

Valid account abuse or account creation

Tier 5

Produces no malware event at all — the only trace is in identity telemetry, which is why an endpoint-only programme has a blind spot exactly here.

10 techniques · weight 3

D12

Beaconing to attacker infrastructure over web protocols

Tier 6–7

The URI shape and cadence are cheap to match and hold for weeks to months — but the destination itself rotates in days, so match the pattern rather than the host.

7 techniques · weight 3

How to score it

No single behaviour here is worth waking someone. Summed weights of 6 on one host inside a window is an alert; 10 is an incident. The pair that most reliably means this actor rather than commodity crime is Persistence pointing into world-writable staging + Credential access against LSASS — seen together, treat as an incident regardless of total.

03 — Tooling

16 named tools, and what each is for

Purpose is derived, not asserted: each tool's own ATT&CK techniques are resolved to tactics, and the tactics it spends most of its techniques in are what it is for.

Actor-specific means we have no record of it outside this actor's reporting — those are the names that identify them. Commodity covers everything sold, published or shared: Cobalt Strike and Brute Ratel are licensed red-team software every pentester owns, Mimikatz and Impacket are public, and backdoors like ShadowPad circulate between unrelated groups. Finding a commodity tool tells you far less, which is exactly why the split is drawn. ATT&CK's own “malware vs tool” type answers a different question — whether the software is malicious — so it is not used for this.

Actor-specific — 5 items

StoneDrill Actor-specific

Destruction or extortion and gathering data.

S0380  ·  15 techniques  ·  Impact, Collection, Discovery
DEADWOOD Actor-specific

Destruction or extortion and evading defences.

S1134  ·  10 techniques  ·  Impact, Stealth, Discovery
POWERTON Actor-specific

Credential theft and staying resident.

S0371  ·  6 techniques  ·  Credential Access, Persistence, Privilege Escalation
TURNEDUP Actor-specific

Gathering data and staying resident.

S0199  ·  6 techniques  ·  Collection, Persistence, Command and Control
AutoIt backdoor Actor-specific

Privilege escalation and remote control.

S0129  ·  4 techniques  ·  Privilege Escalation, Command and Control, Discovery

Commodity and dual-use — 11 items

Empire Commodity

Credential theft and gathering data.

S0363  ·  73 techniques  ·  Credential Access, Collection, Persistence
NETWIRE Commodity

Gathering data and staying resident.

S0198  ·  45 techniques  ·  Collection, Persistence, Credential Access
Pupy Commodity

Credential theft and gathering data.

S0192  ·  41 techniques  ·  Credential Access, Collection, Persistence
PoshC2 Commodity

Credential theft and gathering data.

S0378  ·  32 techniques  ·  Credential Access, Collection, Privilege Escalation
PowerSploit Commodity

Credential theft and gathering data.

S0194  ·  28 techniques  ·  Credential Access, Collection, Persistence
Mimikatz Commodity

Credential theft and moving between hosts.

S0002  ·  17 techniques  ·  Credential Access, Lateral Movement, Persistence
Net Commodity

Staying resident and moving between hosts.

S0039  ·  16 techniques  ·  Persistence, Lateral Movement, Discovery
NanoCore Commodity

Gathering data and staying resident.

S0336  ·  13 techniques  ·  Collection, Persistence, Defense Impairment
LaZagne Commodity

Credential theft.

S0349  ·  10 techniques  ·  Credential Access
Ruler Commodity

Staying resident and network reconnaissance.

S0358  ·  4 techniques  ·  Persistence, Discovery
ftp Commodity

Moving data out and moving between hosts.

S0095  ·  3 techniques  ·  Exfiltration, Lateral Movement, Command and Control

File hashes — actor-specific families — 5 held

HashTypeFamilyFirst seen
0b1de625a89da12bd1fdd292b341bad3md5AutoIt backdoor2026-07-24
07ed2c9ed61b60078af0164f061696bemd5AutoIt backdoor2026-07-24
07bb21d28ae4ab07d62f8deb4343aaebmd5AutoIt backdoor2026-07-24
05c07339603994b36dcfefcce720d03dmd5AutoIt backdoor2026-07-24
03e4bef86f3e3e6ea23eb6f017af0c98md5AutoIt backdoor2026-07-24

04 — Coverage, honestly counted

Where the 31 techniques actually go

Of the techniques attributed to APT33, 27 fold into the detection plan above, 1 describe preparation you cannot see from inside your network, and 3 are uncatalogued — we have not yet placed them. That last number is published on purpose; it is the honest size of the gap.

Credential Access9
Execution6
Command and Control5
Stealth3
Initial Access2
Privilege Escalation2
Collection1
Exfiltration1
Persistence1
Resource Development1

05 — The chain

The order it happens in

The same techniques as above, sequenced. Useful for deciding where to spend a detection: the earlier a tactic sits, the more of the intrusion you still get to prevent.

01
Resource Development
1 technique
02
Initial Access
2 techniques
03
Execution
6 techniques
04
Persistence
1 technique
05
Privilege Escalation
2 techniques
06
Credential Access
9 techniques
07
Collection
1 technique
08
Command and Control
5 techniques
09
Exfiltration
1 technique
10
Stealth
3 techniques

06 — Tradecraft artefacts

Concrete strings, each with the report it came from

Pulled from primary vendor research and kept attributed. These are hunt starting points, not detections — a path an actor used once is worth a query, not a rule.

ArtefactKind First reported byDate
%programdata%\info\info.txt file path Recorded Future 2026-02-19

07 — Sourcing, graded

Who told us, and how much that is worth

NATO Admiralty grading. The letter is the source's reliability, the number the credibility of the claim. We separate primary vendor research from outlets reporting on it, because ten articles derived from one report is one report.

GradeSourceBasis
B2MITRE actor record19 references across 17 distinct research hosts
C3Cloudsek7 items — reporting on other vendors' research
C3The Hacker News4 items — reporting on other vendors' research
B2Palo Alto Networks Unit 422 items — primary vendor research
B2Recorded Future2 items — primary vendor research
B2Group-IB1 item — primary vendor research
—Estate telemetryno data — absent, not negative

16 items · 5 outlets · 44% of reporting traces to a single outlet

08 — What we do not know

The gaps, published

Every vendor profile has these. Most omit them, which leaves you unable to tell a quiet actor from an unobserved one.

NO DATA

C2 URI fingerprints

No URI paths, headers or beacon sequences for any family we hold, and no URL indicators at all to derive them from — the indicator set is hashes, hosts and addresses.

NO DATA

Infrastructure

No domains are attributed to this actor in our holdings, so no naming convention, TLD preference or hosting pattern can be derived.

09 — Outlook

Forward judgements

Probability language is ICD 203. Likelihood and confidence are stated separately: how likely we think it is, and how good our basis is for thinking so.

Remains active
our newest reporting on this actor is from 2026-06-04, 107 days ago
VERY LIKELYconf MODERATE
persistence pointing into world-writable staging continues
a tier-1–2 behaviour, which outlives the tooling that expresses it
VERY LIKELYconf MODERATE

10 — Primary sources

Every reference behind this record

19 of them. Published in full so the page can be checked rather than believed.

fireeye.comhttps://www.fireeye.com/blog/threat-research/2017/09/apt33-insights-into-iranian-cyber-espionageblog.trendmicro.comhttps://blog.trendmicro.com/trendlabs-security-intelligence/more-than-a-dozen-obfuscated-apt33-bbrighttalk.comhttps://www.brighttalk.com/webcast/10703/275683symantec-blogs.broadcom.comhttps://symantec-blogs.broadcom.com/blogs/threat-intelligence/elfin-apt33-espionagesecureworks.comhttps://www.secureworks.com/research/threat-profiles/cobalt-trinityattack.mitre.orghttps://attack.mitre.org/groups/G0064/threatconnect.comhttps://threatconnect.com/blog/research-roundup-activity-on-previously-identified-apt33-domains/cfr.orghttps://www.cfr.org/interactive/cyber-operations/apt-33dragos.comhttps://dragos.com/media/2017-Review-Industrial-Control-System-Threats.pdfdragos.comhttps://dragos.com/adversaries.htmlmicrosoft.comhttps://www.microsoft.com/en-us/security/blog/2023/09/14/peach-sandstorm-password-spray-campaigncloud.google.comhttps://cloud.google.com/blog/topics/threat-intelligence/updated-cyber-threat-actor-naming-systeapt.etda.or.thhttps://apt.etda.or.th/cgi-bin/showcard.cgi?u=958e1f46-a2b6-4beb-8cb0-ddc90c08368esymantec.comhttps://www.symantec.com/blogs/threat-intelligence/elfin-apt33-espionagezdnet.comhttps://www.zdnet.com/article/us-cyber-command-issues-alert-about-hackers-exploiting-outlook-vulbleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/microsoft-hackers-target-defense-firms-with-new-fmicrosoft.comhttps://www.microsoft.com/en-us/security/blog/2024/08/28/peach-sandstorm-deploys-new-custom-ticken.wikipedia.orghttps://en.wikipedia.org/wiki/Elfin_Teampan-unit42.github.iohttps://pan-unit42.github.io/playbook_viewer/?pb=oilrig

Run it against your own estate

Which of these 12 behaviours do you already detect?

The library is the part we can publish. The platform runs the same detection plan against your own estate, tells you which of these behaviours you already cover, and retro-hunts the rest — on your hardware, with nothing leaving the building.

❯ ESC

THE TRACE · LOCAL INFERENCE · REASONING SHOWN STEP-BY-STEP

Try: “which of our vendors were hit by qilin” · “fortios exposure” · “what changed on our perimeter this week”