APT33
Also reported as Elfin, Peach Sandstorm, HOLMIUM, APT 33, Refined Kitten and 12 other names. Linked to Iran by four sources.
Reports per quarter
Techniques seen in the last two years
- T1059.001 7 reports in ATT&CK
- T1204.002 5 reports in ATT&CK
- T1566.001 5 reports in ATT&CK
- T1583.001 5 reports reports only
- T1027 4 reports reports only
- T1041 4 reports reports only
- T1082 4 reports reports only
- T1112 4 reports reports only
- T1583.003 4 reports reports only
- T1583.004 4 reports reports only
Show all 81 techniques Show fewer
- T1027.010 3 reports reports only
- T1036 3 reports reports only
- T1055.002 3 reports reports only
- T1071.001 3 reports in ATT&CK
- T1102 3 reports reports only
- T1105 3 reports in ATT&CK
- T1219 3 reports reports only
- T1566.002 3 reports in ATT&CK
- T1584.001 3 reports reports only
- T1620 3 reports reports only
- T1012 2 reports reports only
- T1027.002 2 reports reports only
- T1047 2 reports reports only
- T1059.003 2 reports reports only
- T1059.007 2 reports reports only
- T1204.001 2 reports in ATT&CK
- T1555.003 2 reports in ATT&CK
- T1583.008 2 reports reports only
- T1591 2 reports reports only
- T1591.002 2 reports reports only
- T1608.001 2 reports reports only
- T1657 2 reports reports only
- T1003 1 report reports only
- T1005 1 report reports only
- T1014 1 report reports only
- T1016 1 report reports only
- T1020 1 report reports only
- T1027.003 1 report reports only
- T1027.006 1 report reports only
- T1027.012 1 report reports only
- T1036.005 1 report reports only
- T1037.001 1 report reports only
- T1053.005 1 report in ATT&CK
- T1055 1 report reports only
- T1055.012 1 report reports only
- T1056.001 1 report reports only
- T1059.005 1 report in ATT&CK
- T1071 1 report reports only
- T1113 1 report reports only
- T1114 1 report reports only
- T1123 1 report reports only
- T1125 1 report reports only
- T1132 1 report reports only
- T1137 1 report reports only
- T1140 1 report reports only
- T1190 1 report reports only
- T1204 1 report reports only
- T1480 1 report reports only
- T1485 1 report reports only
- T1489 1 report reports only
- T1491 1 report reports only
- T1497.003 1 report reports only
- T1518.001 1 report reports only
- T1546.015 1 report reports only
- T1547 1 report reports only
- T1547.001 1 report in ATT&CK
- T1547.004 1 report reports only
- T1548.002 1 report reports only
- T1552.001 1 report in ATT&CK
- T1555 1 report in ATT&CK
- T1564 1 report reports only
- T1564.001 1 report reports only
- T1571 1 report in ATT&CK
- T1573.001 1 report in ATT&CK
- T1573.002 1 report reports only
- T1574.001 1 report reports only
- T1584.004 1 report reports only
- T1587.001 1 report reports only
- T1608.004 1 report reports only
- T1614 1 report reports only
- T1614.001 1 report reports only
Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.
Also listed by ATT&CK
CVEs named in reports
- CVE-2009-0927 KEV
- CVE-2009-3129 KEV
- CVE-2010-0188 KEV ransomware
- CVE-2010-0232 KEV
- CVE-2010-0249 KEV
- CVE-2010-3333 KEV
- CVE-2010-4398 KEV
- CVE-2011-0609 KEV
- CVE-2011-0611 KEV
- CVE-2011-2005 KEV
- CVE-2011-2110
- CVE-2011-3544 KEV
Show all 206 CVEs Show fewer
- CVE-2011-4369
- CVE-2012-0158 KEV ransomware
- CVE-2012-0422
- CVE-2012-0779
- CVE-2012-11882
- CVE-2012-1535 KEV
- CVE-2012-1723 KEV ransomware
- CVE-2012-1856 KEV
- CVE-2012-1875
- CVE-2012-1889 KEV
- CVE-2012-4681 KEV ransomware
- CVE-2012-4792 KEV
- CVE-2012-5469
- CVE-2013-0422 KEV ransomware
- CVE-2013-0808
- CVE-2013-1331 KEV
- CVE-2013-1347 KEV
- CVE-2013-1493
- CVE-2013-2729 KEV
- CVE-2013-3346 KEV
- CVE-2013-3660 KEV
- CVE-2013-3893 KEV
- CVE-2013-3897 KEV
- CVE-2013-3906 KEV
- CVE-2013-4979
- CVE-2013-5065 KEV
- CVE-2013-7331 KEV
- CVE-2014-0160 KEV
- CVE-2014-0322 KEV
- CVE-2014-0346
- CVE-2014-0497 KEV
- CVE-2014-0515
- CVE-2014-1761 KEV
- CVE-2014-1776 KEV
- CVE-2014-4076
- CVE-2014-4114 KEV
- CVE-2014-6332 KEV
- CVE-2014-6352 KEV
- CVE-2014-8439 KEV
- CVE-2015-1641 KEV
- CVE-2015-1642 KEV
- CVE-2015-1701 KEV ransomware
- CVE-2015-2051 KEV
- CVE-2015-2387 KEV
- CVE-2015-2419 KEV
- CVE-2015-2424 KEV
- CVE-2015-2545 KEV
- CVE-2015-2546 KEV ransomware
- CVE-2015-2590 KEV
- CVE-2015-3043 KEV
- CVE-2015-3105
- CVE-2015-4902 KEV
- CVE-2015-5119 KEV
- CVE-2015-5122 KEV
- CVE-2015-7645 KEV ransomware
- CVE-2015-8651 KEV
- CVE-2016-0034 KEV ransomware
- CVE-2016-0167 KEV ransomware
- CVE-2016-1019 KEV ransomware
- CVE-2016-4117 KEV ransomware
- CVE-2016-4119
- CVE-2016-4171 KEV
- CVE-2016-7255 KEV ransomware
- CVE-2016-7855 KEV
- CVE-2016-9192
- CVE-2017-0143 KEV ransomware
- CVE-2017-0144 KEV ransomware
- CVE-2017-0146 KEV ransomware
- CVE-2017-0147 KEV ransomware
- CVE-2017-0199 KEV ransomware
- CVE-2017-0213 KEV ransomware
- CVE-2017-0261 KEV
- CVE-2017-0262 KEV
- CVE-2017-0263 KEV
- CVE-2017-11317 KEV
- CVE-2017-11357 KEV ransomware
- CVE-2017-11774 KEV
- CVE-2017-11882 KEV ransomware
- CVE-2017-12824
- CVE-2017-15399
- CVE-2017-5689 KEV
- CVE-2017-7269 KEV
- CVE-2017-8291 KEV
- CVE-2017-8570 KEV
- CVE-2017-8759 KEV
- CVE-2017-9248 KEV
- CVE-2018-0802 KEV ransomware
- CVE-2018-10561 KEV
- CVE-2018-13379 KEV ransomware
- CVE-2018-1579
- CVE-2018-20250 KEV ransomware
- CVE-2018-2025010
- CVE-2018-2025036
- CVE-2018-4878 KEV ransomware
- CVE-2018-6055
- CVE-2018-8174 KEV ransomware
- CVE-2018-8440 KEV ransomware
- CVE-2019-0604 KEV ransomware
- CVE-2019-0708 KEV ransomware
- CVE-2019-0797 KEV
- CVE-2019-0803 KEV ransomware
- CVE-2019-0808 KEV
- CVE-2019-0859 KEV ransomware
- CVE-2019-10149 KEV
- CVE-2019-1132 KEV
- CVE-2019-11510 KEV ransomware
- CVE-2019-11707 KEV
- CVE-2019-11708 KEV
- CVE-2019-1367 KEV ransomware
- CVE-2019-13720 KEV
- CVE-2019-1458 KEV ransomware
- CVE-2019-1579 KEV ransomware
- CVE-2019-1652 KEV
- CVE-2019-1653 KEV
- CVE-2019-17026 KEV
- CVE-2019-17100
- CVE-2019-18935 KEV ransomware
- CVE-2019-19781 KEV ransomware
- CVE-2019-2215 KEV
- CVE-2019-2725 KEV ransomware
- CVE-2019-3568 KEV
- CVE-2019-5786 KEV
- CVE-2019-6225
- CVE-2019-7286 KEV
- CVE-2019-7287 KEV
- CVE-2019-7609 KEV
- CVE-2019-8518
- CVE-2019-9489
- CVE-2019-9670 KEV
- CVE-2020-0674 KEV
- CVE-2020-0688 KEV ransomware
- CVE-2020-0796 KEV ransomware
- CVE-2020-10189 KEV
- CVE-2020-10826
- CVE-2020-10827
- CVE-2020-11899 KEV
- CVE-2020-11901
- CVE-2020-13756
- CVE-2020-1472 KEV ransomware
- CVE-2020-14882 KEV
- CVE-2020-17144 KEV
- CVE-2020-2021 KEV ransomware
- CVE-2020-4006 KEV
- CVE-2020-5902 KEV ransomware
- CVE-2020-6418 KEV
- CVE-2020-6819 KEV
- CVE-2020-6820 KEV
- CVE-2020-7961 KEV
- CVE-2020-8467 KEV
- CVE-2020-8468 KEV
- CVE-2021-1675 KEV ransomware
- CVE-2021-1732 KEV ransomware
- CVE-2021-21972 KEV ransomware
- CVE-2021-26411 KEV ransomware
- CVE-2021-26855 KEV ransomware
- CVE-2021-26857 KEV ransomware
- CVE-2021-26858 KEV ransomware
- CVE-2021-27065 KEV ransomware
- CVE-2021-31207 KEV ransomware
- CVE-2021-3156 KEV
- CVE-2021-34473 KEV ransomware
- CVE-2021-34523 KEV ransomware
- CVE-2021-34527 KEV ransomware
- CVE-2021-36934 KEV
- CVE-2021-4034 KEV ransomware
- CVE-2021-4044
- CVE-2021-40444 KEV ransomware
- CVE-2021-40449 KEV ransomware
- CVE-2021-41379 KEV ransomware
- CVE-2021-43936
- CVE-2021-44228 KEV ransomware
- CVE-2021-44832
- CVE-2021-45046 KEV ransomware
- CVE-2021-45105
- CVE-2022-1040 KEV
- CVE-2022-1096 KEV
- CVE-2022-24086 KEV
- CVE-2022-26134 KEV ransomware
- CVE-2022-42475 KEV ransomware
- CVE-2022-47966 KEV ransomware
- CVE-2023-23397 KEV
- CVE-2023-2868 KEV
- CVE-2023-28771 KEV
- CVE-2023-34362 KEV ransomware
- CVE-2023-38331
- CVE-2023-38831 KEV ransomware
- CVE-2023-42793 KEV ransomware
- CVE-2023-4966 KEV ransomware
- CVE-2024-43451 KEV
- CVE-2024-4577 KEV ransomware
- CVE-2025-0411 KEV
- CVE-2025-55182 KEV ransomware
- CVE-2025-6218 KEV
- CVE-2025-8088 KEV ransomware
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor StoneDrill (Malware Family)
Show all 406 reports Show fewer
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Helix Kitten
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor NetWire RC (Malware Family)
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
Living off the Land - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Living off the Land - Threat Group Cards: A Threat Actor Encyclopedia
-
APT 33, Elfin, Magnallium - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor APT 33, Elfin, Magnallium - Threat Group Cards: A Threat Actor Encyclopedia
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Remcos (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Nanocore RAT (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Elfin Team
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Charming Kitten
-
Imminent Monitor RAT (Malware Family)
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Imminent Monitor RAT (Malware Family)
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
OilRig, APT 34, Helix Kitten, Chrysene
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor OilRig, APT 34, Helix Kitten, Chrysene
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Quasar RAT (Malware Family)
-
logpoint-etpr-a-comprehensive-overview-on-stealer-malware-families.pdf
The original link failed its last check. Original publisher Detailsfor logpoint-etpr-a-comprehensive-overview-on-stealer-malware-families.pdf
-
Spam trends campaigns senior superlatives 2023
The original link failed its last check. Original publisher Detailsfor Spam trends campaigns senior superlatives 2023
-
en_netwire_technical_analysis_report_02.pdf
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor en_netwire_technical_analysis_report_02.pdf
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Analysis Of Netwire RAT
-
Advanced Persistent Threats (APTs)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Advanced Persistent Threats (APTs)
-
Russian Ransomware C2 Network Discovered in Censys Data
The original link failed its last check. Original publisher Detailsfor Russian Ransomware C2 Network Discovered in Censys Data
-
THALES%20THREAT%20HANDBOOK%202022%20Light%20Version_1.pdf
The original link failed its last check. Original publisher Detailsfor THALES%20THREAT%20HANDBOOK%202022%20Light%20Version_1.pdf
-
Threat Hunting for Malicious PowerShell Usage in Gigasheet
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Hunting for Malicious PowerShell Usage in Gigasheet
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor 2021trends.pdf
-
Advanced Persistent Threats (APTs)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Advanced Persistent Threats (APTs)
-
report-old-dogs-new-tricks.pdf
The original link failed its last check. Original publisher Detailsfor report-old-dogs-new-tricks.pdf
-
The original link failed its last check. Original publisher Detailsfor mtrends-2018.pdf
-
The original link failed its last check. Original publisher Detailsfor https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/image-file-trickery-part-ii-fake-icon-delivers-nanocore/
-
Intezer-2020-Go-Malware-Round-Up.pdf
The original link failed its last check. Original publisher Detailsfor Intezer-2020-Go-Malware-Round-Up.pdf
-
The original link failed its last check. Original publisher Detailsfor Analytics
-
Attack Activities by Quasar Family
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Attack Activities by Quasar Family
-
Group-IB_Hi-Tech_Crime_Trends_2020-2021_en
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Group-IB_Hi-Tech_Crime_Trends_2020-2021_en
-
ALFA TEaM Shell ~ v4.1-Tesla- A Feature Update Analysis
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor ALFA TEaM Shell ~ v4.1-Tesla- A Feature Update Analysis
-
2020.10.15_Operation_Quicksand_MuddyWater’s_Offensive_Attack_Against_Israeli
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 2020.10.15_Operation_Quicksand_MuddyWater’s_Offensive_Attack_Against_Israeli
-
FY20 Microsoft Digital Defense Report
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor FY20 Microsoft Digital Defense Report
-
Elfin- Latest U.S. Indictments Appear to Target Iranian Espionage Group
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Elfin- Latest U.S. Indictments Appear to Target Iranian Espionage Group
-
Research Roundup- Activity on Previously Identified APT33 Domains
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Research Roundup- Activity on Previously Identified APT33 Domains
-
Iranian hackers are selling access to compromised companies on an underground forum
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Iranian hackers are selling access to compromised companies on an underground forum
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Dream-Job-Campaign
-
FBI says an Iranian hacking group is attacking F5 networking devices
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor FBI says an Iranian hacking group is attacking F5 networking devices
-
2020-q2-spamhaus-botnet-threat-report.pdf
The original link failed its last check. Original publisher Detailsfor 2020-q2-spamhaus-botnet-threat-report.pdf
-
SCANdalous! (External Detection Using Network Scan Data and Automation)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor SCANdalous! (External Detection Using Network Scan Data and Automation)
-
analyses/RemcosDocDropper.MD at master · 1d8/analyses
The original link failed its last check. Original publisher Detailsfor analyses/RemcosDocDropper.MD at master · 1d8/analyses
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 0628-2020APT上半年报告-画册
-
Inside Microsoft Threat Protection- Mapping attack chains from cloud to endpoint (APT33-HOLMIUM)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Inside Microsoft Threat Protection- Mapping attack chains from cloud to endpoint (APT33-HOLMIUM)
-
The original link failed its last check. Detailsfor #ThreatThursday - APT33
-
ThreatConnect Research Roundup- Possible APT33 Infrastructure
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor ThreatConnect Research Roundup- Possible APT33 Infrastructure
-
CTNT_Q1_2020_COVID-Report_Final.pdf
The original link failed its last check. Original publisher Detailsfor CTNT_Q1_2020_COVID-Report_Final.pdf
-
New Cyber Operation Targets Italy- Digging Into the Netwire Attack Chain
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New Cyber Operation Targets Italy- Digging Into the Netwire Attack Chain
-
The original link failed its last check. Original publisher Detailsfor Nanocore & CypherIT
-
Report2020CrowdStrikeGlobalThreatReport
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Report2020CrowdStrikeGlobalThreatReport
-
The ICS Threat Landscape and Activity Groups
The original link failed its last check. Original publisher Detailsfor The ICS Threat Landscape and Activity Groups
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Fox Kittens report 16.2.2020
-
2020.02.22_APT_threat_report_2019_CN_version
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 2020.02.22_APT_threat_report_2019_CN_version
-
Current Iran-Associated Cyber Threats
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Current Iran-Associated Cyber Threats
-
Iranian Threat Actors- Preliminary Analysis
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Iranian Threat Actors- Preliminary Analysis
-
Iranian Cyber Response to Death of IRGC Head Would Likely Use Reported TTPs and Previous Access
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Iranian Cyber Response to Death of IRGC Head Would Likely Use Reported TTPs and Previous Access
-
First Active Attack Exploiting CVE-2019-2215 Found on Google Play, Linked to SideWinder APT Group
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor First Active Attack Exploiting CVE-2019-2215 Found on Google Play, Linked to SideWinder APT Group
-
North American Electric Cyber Threat Perspective
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor North American Electric Cyber Threat Perspective
-
Cyber Threat Landscape in Japan – Revealing Threat in the Shadow
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cyber Threat Landscape in Japan – Revealing Threat in the Shadow
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor [CB19] Cyber Threat Landscape in Japan – Revealing Threat in the Shadow by Chi En Shen (Ashley) Oleg Bondarenko
-
Drilling Deep: A Look at Cyberattacks on the Oil and Gas Industry
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Drilling Deep: A Look at Cyberattacks on the Oil and Gas Industry
-
Obfuscated APT33 C&Cs Used for Narrow Targeting
The original link failed its last check. Original publisher Detailsfor Obfuscated APT33 C&Cs Used for Narrow Targeting
-
More than a Dozen Obfuscated APT33 Botnets Used for Extreme Narrow Targeting
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor More than a Dozen Obfuscated APT33 Botnets Used for Extreme Narrow Targeting
-
Operation Gamework: Infrasturcture Overlaps Found Between BlueAlpha and Iranian APTs
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Gamework: Infrasturcture Overlaps Found Between BlueAlpha and Iranian APTs
-
Group-IB_Hi-Tech_Crime_Trends_2019-2020_en
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Group-IB_Hi-Tech_Crime_Trends_2019-2020_en
-
PoshC2 (specifically as used by APT33)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor PoshC2 (specifically as used by APT33)
-
Group-IB_Hi-Tech_Crime_Trends_2019-2020
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Group-IB_Hi-Tech_Crime_Trends_2019-2020
-
REWTERZ THREAT ALERT – IRANIAN APT USES JOB SCAMS TO LURE TARGETS
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor REWTERZ THREAT ALERT – IRANIAN APT USES JOB SCAMS TO LURE TARGETS
-
More than a Dozen Obfuscated APT33 Botnets Used for Extreme Narrow Targeting
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor More than a Dozen Obfuscated APT33 Botnets Used for Extreme Narrow Targeting
-
LYCEUM Takes Center Stage in Middle East Campaign
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor LYCEUM Takes Center Stage in Middle East Campaign
-
Cyber Threat Group LYCEUM Takes Center Stage in Middle East Campaign
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Cyber Threat Group LYCEUM Takes Center Stage in Middle East Campaign
-
APT_trends_report_Q2_2019_Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT_trends_report_Q2_2019_Securelist
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT trends report Q2 2019
-
Dragos - Global Oil and Gas Cyber Threat Perspctive
The original link failed its last check. Original publisher Detailsfor Dragos - Global Oil and Gas Cyber Threat Perspctive
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT33 PowerShell Malware
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Twas the night before
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Iranian Threat Actor Amasses Large Cyber Operations Infrastructure Network to Target Saudi Organizations
-
The original link failed its last check. Original publisher Detailsfor rpt-mtrends-2019.pdf
-
mpressioncss_ta_report_2019.pdf
The original link failed its last check. Original publisher Detailsfor mpressioncss_ta_report_2019.pdf
-
Elfin: Relentless Espionage Group Targets Multiple Organizations in Saudi Arabia and U.S.
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Elfin: Relentless Espionage Group Targets Multiple Organizations in Saudi Arabia and U.S.
-
Elfin- Relentless Espionage Group Targets Multiple Organizations in Saudi Arabia and U.S.
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Elfin- Relentless Espionage Group Targets Multiple Organizations in Saudi Arabia and U.S.
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor rpt-mtrends-2019
-
yir-ics-activity-groups-threat-landscape-2018.pdf
The original link failed its last check. Original publisher Detailsfor yir-ics-activity-groups-threat-landscape-2018.pdf
-
Shamoon Attackers Employ New Tool Kit to Wipe Infected Systems
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Shamoon Attackers Employ New Tool Kit to Wipe Infected Systems
-
HITB-SG-2018-E - In the trails of WINDSHIFT [Autosaved]
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor HITB-SG-2018-E - In the trails of WINDSHIFT [Autosaved]
-
Decrypting APT33’s Dropshot Malware with Radare2 and Cutter – Part 2
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Decrypting APT33’s Dropshot Malware with Radare2 and Cutter – Part 2
-
Decrypting APT33’s Dropshot Malware with Radare2 and Cutter – Part 1
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Decrypting APT33’s Dropshot Malware with Radare2 and Cutter – Part 1
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor cta-2018-0509
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT33
-
Industrial Control System Threats
The original link failed its last check. Original publisher Detailsfor Industrial Control System Threats
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Iran_Cyber_Final_Full_v2
-
Advanced Persistent Threat Groups
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Advanced Persistent Threat Groups
-
A dive into MuddyWater APT targeting Middle-East
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor A dive into MuddyWater APT targeting Middle-East
-
Anomali - Iran Country Profile relating to Security.pdf
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Anomali - Iran Country Profile relating to Security.pdf
-
APT33- New Insights into Iranian Cyber Espionage Group
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT33- New Insights into Iranian Cyber Espionage Group
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Insights into Iranian Cyber Espionage_ APT33 Targets Aerospace and Energy Sectors and has Ties to Destructive Malware « Threat Research Blog _ FireEye Inc
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Insights into Iranian Cyber Espionage- APT33 Targets Aerospace and Energy Sectors and has Ties to Destructive Malware
-
Iranian Hackers Have Been Infiltrating Critical Infrastructure Companies
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Iranian Hackers Have Been Infiltrating Critical Infrastructure Companies
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Ghosts in the Endpoint
Newest first. Details opens the report in Explore.