APT33 is a suspected Iranian state-aligned threat group assessed to have conducted cyber-espionage operations since at least 2013 on behalf of the Iranian government. The group is widely associated with targeting organizations of strategic relevance to Iran, especially aerospace, aviation, energy, and petrochemical entities. Reported victim geography includes the United States, Saudi Arabia, and South Korea, with activity suggesting interest in Saudi military and commercial aviation capabilities and petrochemical relationships relevant to Iranian strategic priorities. APT33 is known for spear-phishing operations using recruitment- and job-themed lures, including malicious HTML application payloads that present decoy employment content while downloading custom malware. The group has also used publicly available phishing tooling to distribute large volumes of phishing emails and has registered lookalike infrastructure impersonating aviation-related organizations and partners. Malware associated with APT33 includes the TURNEDUP backdoor and the DROPSHOT dropper. DROPSHOT has been observed delivering TURNEDUP and has also been linked to SHAPESHIFT, a wiper capable of disk, volume, and file destruction, indicating the group has access to tooling that could support destructive operations in addition to espionage. Attribution to Iran is supported by victimology aligned with Iranian state interests, operational timing consistent with the Iranian workweek and time zone, and links between APT33 tooling and an Iranian online persona known as xman_1365_x. Open-source reporting has associated that persona with the Nasr Institute, an organization tied in public reporting to Iranian government-directed cyber activity. Although the name Shabgard appears in connection with forum account registrations by the linked persona, there is no evidence that APT33 was a formal member of the Shabgard hacktivist group. APT33 is best understood as an Iranian espionage-focused threat actor with demonstrated phishing, malware delivery, persistence, and potential destructive capabilities.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.