APT33 is a suspected Iranian state-aligned cyber-espionage group active since at least 2013 and widely tracked as an Iran-linked advanced persistent threat. It has primarily targeted aerospace, aviation, energy, and petrochemical organizations, with documented victimology including entities in the United States, Saudi Arabia, and South Korea. The group’s targeting has been assessed as consistent with Iranian strategic intelligence requirements, including interest in Saudi military and commercial aviation and petrochemical relationships relevant to Iran. APT33 is known for spear-phishing operations using recruitment- and job-themed lures, including malicious HTML application payloads that present decoy employment content while downloading custom malware. Reported tooling associated with the group includes the TURNEDUP backdoor and the DROPSHOT dropper. DROPSHOT has also been linked to delivery of the SHAPESHIFT wiper, indicating the group has access to destructive capability in addition to espionage tooling. The actor has also used publicly available phishing tooling to distribute large volumes of phishing emails and has registered lookalike infrastructure impersonating aviation-related organizations to support credential theft and initial compromise. Attribution to Iran is supported by victimology aligned with Iranian state interests, operational timing consistent with Iran’s workweek and time zone, and links between APT33 tooling and an Iranian online persona known as xman_1365_x. Open-source reporting has associated that persona with the Nasr Institute, an organization tied in public reporting to Iranian government-directed cyber activity. Although the alias "ashiyane" appears in connection with forum registration activity by a linked persona, there is no high-confidence evidence that APT33 was a formal member of the Ashiyane hacktivist group. APT33 is best understood as an Iranian espionage actor with demonstrated phishing, malware deployment, credential-focused intrusion support, persistence, and potential destructive operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.