Cyber threat actor
APT33
Iranian state-sponsored (IRGC-linked) · active since 2013
Espionage and destructive-capable group targeting US and allied aerospace, defense and energy sectors, with reported password-spray campaigns against satellite and defense companies.
Aliases
ElfinPeach SandstormRefined Kitten
Primary targets
Aerospace Defense contractors Energy sector Satellite/telecom
MITRE ATT&CK techniques
0 techniques mapped · click any technique ID to open the MITRE ATT&CK entry, any CVE to view its NVD record, or any citation for source reporting.
No MITRE ATT&CK mapping available yet for APT33.
Curated incidents
- 2023-09-14·Defense / Aerospace·United StatesPeach Sandstorm (APT33) password-spray campaign hits US defense and satellite firms
Microsoft details large-scale password-spray activity enabling intelligence collection against satellite, defense, and pharmaceutical organizations.