All actors

APT33

Also reported as Elfin, Peach Sandstorm, HOLMIUM, APT 33, Refined Kitten and 12 other names. Linked to Iran by four sources.

Reports
406
Last reported
Known CVEs
206
Techniques in ATT&CK
34
Origin
Iran
ID
G0064
Merge evidence
30 alias matches

Reports per quarter

  1. 2012 Q2: 1 report
  2. 2012 Q3: no reports
  3. 2012 Q4: 1 report
  4. 2013 Q1: no reports
  5. 2013 Q2: no reports
  6. 2013 Q3: no reports
  7. 2013 Q4: no reports
  8. 2014 Q1: no reports
  9. 2014 Q2: no reports
  10. 2014 Q3: 1 report
  11. 2014 Q4: 1 report
  12. 2015 Q1: no reports
  13. 2015 Q2: no reports
  14. 2015 Q3: no reports
  15. 2015 Q4: no reports
  16. 2016 Q1: no reports
  17. 2016 Q2: 1 report
  18. 2016 Q3: no reports
  19. 2016 Q4: no reports
  20. 2017 Q1: 4 reports
  21. 2017 Q2: no reports
  22. 2017 Q3: 5 reports
  23. 2017 Q4: 5 reports
  24. 2018 Q1: 4 reports
  25. 2018 Q2: 10 reports
  26. 2018 Q3: 4 reports
  27. 2018 Q4: 3 reports
  28. 2019 Q1: 7 reports
  29. 2019 Q2: 8 reports
  30. 2019 Q3: 17 reports
  31. 2019 Q4: 15 reports
  32. 2020 Q1: 19 reports
  33. 2020 Q2: 24 reports
  34. 2020 Q3: 20 reports
  35. 2020 Q4: 15 reports
  36. 2021 Q1: 11 reports
  37. 2021 Q2: 9 reports
  38. 2021 Q3: 12 reports
  39. 2021 Q4: 10 reports
  40. 2022 Q1: 33 reports
  41. 2022 Q2: 18 reports
  42. 2022 Q3: 12 reports
  43. 2022 Q4: 4 reports
  44. 2023 Q1: 13 reports
  45. 2023 Q2: 8 reports
  46. 2023 Q3: 6 reports
  47. 2023 Q4: 7 reports
  48. 2024 Q1: 12 reports
  49. 2024 Q2: 9 reports
  50. 2024 Q3: 6 reports
  51. 2024 Q4: 3 reports
  52. 2025 Q1: 12 reports
  53. 2025 Q2: 4 reports
  54. 2025 Q3: 1 report
  55. 2025 Q4: 5 reports
  56. 2026 Q1: 3 reports
  57. 2026 Q2: 40 reports
  58. 2026 Q3: 3 reports
Dated reports, 2012 Q2 to 2026 Q3.

Techniques seen in the last two years

Show all 81 techniques Show fewer

Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.

Also listed by ATT&CK

Show all 19 techniques Show fewer

CVEs named in reports

Show all 206 CVEs Show fewer

KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.

Reports

  1. StoneDrill (Malware Family)

    date ORKL added it fromORKL

Show all 406 reports Show fewer
  1. Helix Kitten

    date ORKL added it fromORKL

  2. NetWire RC (Malware Family)

    date ORKL added it fromORKL

  3. Threat Group Cards: A Threat Actor Encyclopedia

    date ORKL added it fromORKL

  4. Remcos (Malware Family)

    date ORKL added it fromORKL

  5. Nanocore RAT (Malware Family)

    date ORKL added it fromORKL

  6. Elfin Team

    date ORKL added it fromORKL

  7. Charming Kitten

    date ORKL added it fromORKL

  8. Imminent Monitor RAT (Malware Family)

    date ORKL added it fromORKL

  9. Threat Group Cards: A Threat Actor Encyclopedia

    date ORKL added it fromORKL

  10. OilRig, APT 34, Helix Kitten, Chrysene

    date ORKL added it fromORKL

  11. Quasar RAT (Malware Family)

    date ORKL added it fromORKL

  12. CERT-UA

    Malpedia library date fromORKL

  13. CERT-UA

    Malpedia library date fromORKL

  14. CERT-UA

    Malpedia library date fromORKL

  15. CERT-UA

    Malpedia library date fromORKL

  16. en_netwire_technical_analysis_report_02.pdf

    Malpedia library date fromORKL

  17. Analysis Of Netwire RAT

    date in the title fromORKL

  18. Advanced Persistent Threats (APTs)

    date in the title fromORKL

  19. Threat Hunting for Malicious PowerShell Usage in Gigasheet

    date in the title fromORKL

  20. 2021trends.pdf

    Malpedia library date fromORKL

  21. Advanced Persistent Threats (APTs)

    date in the title fromORKL

  22. report-old-dogs-new-tricks.pdf

    Malpedia library date fromORKL

  23. mtrends-2018.pdf

    file creation date fromORKL

  24. Intezer-2020-Go-Malware-Round-Up.pdf

    Malpedia library date fromORKL

  25. Analytics

    Malpedia library date fromORKL

  26. Attack Activities by Quasar Family

    date in the title fromORKL

  27. Group-IB_Hi-Tech_Crime_Trends_2020-2021_en

    file creation date fromORKL

  28. ALFA TEaM Shell ~ v4.1-Tesla- A Feature Update Analysis

    date in the title fromORKL

  29. FY20 Microsoft Digital Defense Report

    Malpedia library date fromORKL

  30. Dream-Job-Campaign

    date in the CCS '25 data ClearSky fromORKLCCS '25 data

  31. 2020-q2-spamhaus-botnet-threat-report.pdf

    Malpedia library date fromORKL

  32. 0628-2020APT上半年报告-画册

    file creation date fromORKL

  33. #ThreatThursday - APT33

    date in the CCS '25 data SCYTHE fromCCS '25 data

  34. CTNT_Q1_2020_COVID-Report_Final.pdf

    Malpedia library date fromORKL

  35. Nanocore & CypherIT

    Malpedia library date fromORKL

  36. Report2020CrowdStrikeGlobalThreatReport

    Malpedia library date fromORKL

  37. Fox Kittens report 16.2.2020

    date in the CCS '25 data ClearSky Cyber Security ltd fromORKLCCS '25 data

  38. 2020.02.22_APT_threat_report_2019_CN_version

    Malpedia library date fromORKL

  39. Current Iran-Associated Cyber Threats

    file creation date Symantec fromORKL

  40. Iranian Threat Actors- Preliminary Analysis

    date in the title fromORKL

  41. North American Electric Cyber Threat Perspective

    Malpedia library date fromORKL

  42. Drilling Deep: A Look at Cyberattacks on the Oil and Gas Industry

    date in the CCS '25 data Trend Micro fromORKLCCS '25 data

  43. Operation Gamework: Infrasturcture Overlaps Found Between BlueAlpha and Iranian APTs

    Malpedia library date Recorded Future fromORKLCCS '25 data

  44. Group-IB_Hi-Tech_Crime_Trends_2019-2020_en

    file creation date fromORKL

  45. PoshC2 (specifically as used by APT33)

    date in the title fromORKL

  46. PoshC2 (specifically as used by APT33)

    date in the CCS '25 data Github (jeFF0Falltrades) fromCCS '25 data

  47. Group-IB_Hi-Tech_Crime_Trends_2019-2020

    date in the CCS '25 data Group-IB fromORKLCCS '25 data

  48. LYCEUM Takes Center Stage in Middle East Campaign

    date in the title fromORKL

  49. Cyber Threat Group LYCEUM Takes Center Stage in Middle East Campaign

    date in the CCS '25 data SecureWorks fromORKLCCS '25 data

  50. APT_trends_report_Q2_2019_Securelist

    file creation date fromORKL

  51. APT trends report Q2 2019

    date in the title fromORKL

  52. APT33 PowerShell Malware

    date in the title fromORKL

  53. Twas the night before

    date in the CCS '25 data Kaspersky fromORKLCCS '25 data

  54. rpt-mtrends-2019.pdf

    file creation date fromORKL

  55. mpressioncss_ta_report_2019.pdf

    Malpedia library date fromORKL

  56. rpt-mtrends-2019

    file creation date fromORKL

  57. HITB-SG-2018-E - In the trails of WINDSHIFT [Autosaved]

    date in the CCS '25 data Bellingcat fromORKLCCS '25 data

  58. cta-2018-0509

    file creation date fromORKL

  59. M-Trends Overview

    Malpedia library date Marco Rottigni fromORKL

  60. M-TRENDS2018

    file creation date FireEye fromORKL

  61. APT33

    date in the title fromORKL

  62. Industrial Control System Threats

    Malpedia library date Dragos fromORKL

  63. Iran_Cyber_Final_Full_v2

    file creation date fromORKL

  64. Advanced Persistent Threat Groups

    date in the title fromORKL

  65. A dive into MuddyWater APT targeting Middle-East

    date in the title fromORKL

  66. Anomali - Iran Country Profile relating to Security.pdf

    file creation date fromORKL

  67. APT33- New Insights into Iranian Cyber Espionage Group

    date in the title fromORKL

  68. Ghosts in the Endpoint

    date in the title fromORKL

Newest first. Details opens the report in Explore.