Cyber overview
Cyber threat actor

APT33

Iranian state-sponsored (IRGC-linked) · active since 2013

Espionage and destructive-capable group targeting US and allied aerospace, defense and energy sectors, with reported password-spray campaigns against satellite and defense companies.

Aliases
ElfinPeach SandstormRefined Kitten
Primary targets
Aerospace Defense contractors Energy sector Satellite/telecom

MITRE ATT&CK techniques

0 techniques mapped · click any technique ID to open the MITRE ATT&CK entry, any CVE to view its NVD record, or any citation for source reporting.

No MITRE ATT&CK mapping available yet for APT33.

Curated incidents

  1. 2023-09-14·Defense / Aerospace·United States
    Peach Sandstorm (APT33) password-spray campaign hits US defense and satellite firms

    Microsoft details large-scale password-spray activity enabling intelligence collection against satellite, defense, and pharmaceutical organizations.