Clankerusecase
Threat-actor profile
← Back to main site
Home/ Threat Actors/ APT33

🇮🇷APT33

🇮🇷 APT33 is a tracked threat actor in the Clankerusecase corpus. Attributed to IR. Primary motivation: State. We map 25 detection use cases to this actor across 47 MITRE ATT&CK techniques, with 1 threat-intel article citing them. Active in our corpus from 2026-03-12 to 2026-03-12.

crit 1
View full actor card → All threat actors MITRE ATT&CK group spec (G0064) ↗
25Use cases
1Articles
47Techniques
0IOCs

Known aliases

APT33Refined KittenElfinHolmiumPeach SandstormHOLMIUM

Top techniques

All other tracked techniques

Detection use cases (25)

APT33 / Peach Sandstorm password-spray → successful Entra ID sign-in → new device registration AI · profile S APT33 hands-on-keyboard: AnyDesk / Plink deployment after Entra ID foothold (Tickler / FalseFont staging) AI · profile SΣ MuddyWater SimpleHelp RMM client spawning shell or recon LOLBin Bespoke Iran-aligned MFA push-bombing followed by new auth method registered (AA24-290A) Bespoke Phishing-link click correlated to endpoint execution Internal Email attachment opened from external sender Internal Office app spawning script/LOLBin child process Internal Fake CAPTCHA / clipboard-injected PowerShell (ClickFix / FakeCaptcha) Internal Ransomware-style mass file rename / extension change Internal LSASS process access / dump (credential theft) Internal Remote service execution — PsExec / SMB lateral movement Internal RMM tool installed by non-IT user — remote-access utility for hands-on-keyboard Internal Trusted vendor binary / installer launching unusual children Internal 1Password impossible-travel sign-in MITRE match 1Password item exfiltration attempt MITRE match 1Password vault export attempted MITRE match AI/LLM Agent Framework Runtime Spawning Shell, Recon, or Egress Child Process MITRE match AI/LLM Framework Web Service Spawns Shell or Network Tool (Agent-Framework Unauthenticated RCE) MITRE match Auth-Bypass on Public-Facing Service → Post-Exploit Action on Same Host (≤10 min) MITRE match Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes MITRE match Cross-category credential-store enumeration with rapid egress to anonymizing tunnel/CDN MITRE match Cross-Platform ClickFix Paste-to-Pipe Loader (UI-Parent Shell with Decode-and-Execute Payload) MITRE match Developer package install spawning script-host with non-registry C2 within 5 minutes MITRE match Internet-Facing Service Process Spawning Unix Shell or Ingress-Tool LOLBin (Edge Zero-Day Post-Exploit) MITRE match Internet-facing service process spawns shell/LOLBin within minutes of public inbound connection — post-RCE command execution MITRE match

Threat-intel articles (1)