IR

APT33

High ConfidenceHigh Threat

Elfin • HOLMIUM • Refined Kitten • Peach Sandstorm • Magnallium

APT33, known as Elfin, HOLMIUM, or Peach Sandstorm, is an Iranian state-sponsored cyber espionage group active since at least 2013. The group primarily targets aerospace, energy, and petrochemical sectors in the United States, Saudi Arabia, and South Korea. APT33 is notable for their development of destructive capabilities, including links to the Shamoon disk-wiping malware. Their operations support Iranian strategic interests, particularly regarding regional rivals and the global energy sector. The group employs spear-phishing campaigns with malicious documents and has demonstrated password spraying capabilities against thousands of organizations.

Origin: Iran
Sponsor: IRGC (Islamic Revolutionary Guard Corps)
Active: 2013 - Present
Victims: 150+ organizations
Advanced
Active
EspionageSabotageDestruction
Risk Assessment
84
Composite Risk Score
High Risk
ARCS Compliance80
Escalation Risk85
Grievance Index88
Infrastructure Impact82
History & Evolution

APT33, known as Elfin, HOLMIUM, or Peach Sandstorm, is an Iranian state-sponsored cyber espionage group active since at least 2013. The group primarily targets aerospace, energy, and petrochemical sectors in the United States, Saudi Arabia, and South Korea. APT33 is notable for their development of destructive capabilities, including links to the Shamoon disk-wiping malware. Their operations support Iranian strategic interests, particularly regarding regional rivals and the global energy sector. The group employs spear-phishing campaigns with malicious documents and has demonstrated password spraying capabilities against thousands of organizations.

Targeting

Target Sectors

AerospaceEnergyPetrochemicalDefenseGovernment

Target Regions

Saudi ArabiaUnited StatesSouth KoreaMiddle East
Attribution & Affiliations

Attributed to IRGC (Islamic Revolutionary Guard Corps) (Iran). Attribution confidence: High.

Intelligence Assessment
High
Threat Level
Moderately
Targeting
Moderately
Adaptability
High
Persistence
Continuous
Op Tempo
Active
Status

Future Outlook

APT33 is expected to continue operations targeting Aerospace sectors.

Timeline of Key Events
2013
Major

First observed activity of APT33

2024
Moderate

Continued active operations