🇮🇷APT33
🇮🇷 APT33 is a tracked threat actor in the Clankerusecase corpus. Attributed to IR. Primary motivation: State. We map 25 detection use cases to this actor across 47 MITRE ATT&CK techniques, with 1 threat-intel article citing them. Active in our corpus from 2026-03-12 to 2026-03-12.
crit 1
25Use cases
1Articles
47Techniques
0IOCs
Known aliases
APT33Refined KittenElfinHolmiumPeach SandstormHOLMIUM
Top techniques
All other tracked techniques
T1003 · OS Credential DumpingT1003.001 · LSASS MemoryT1003.004 · LSA SecretsT1003.005 · Cached Domain CredentialsT1021.002 · SMB/Windows Admin SharesT1027.013 · Encrypted/Encoded FileT1040 · Network SniffingT1048.003 · Exfiltration Over Unencrypted Non-C2 ProtocolT1053.005 · Scheduled TaskT1059.001 · PowerShellT1059.003 · Windows Command ShellT1059.005 · Visual BasicT1068 · Exploitation for Privilege EscalationT1071.001 · Web ProtocolsT1078 · Valid AccountsT1078.004 · Cloud AccountsT1087 · Account DiscoveryT1098.005 · Device RegistrationT1105 · Ingress Tool TransferT1110.003 · Password SprayingT1132.001 · Standard EncodingT1199 · Trusted RelationshipT1203 · Exploitation for Client ExecutionT1204.001 · Malicious LinkT1204.002 · Malicious FileT1204.004 · Malicious Copy and PasteT1218 · System Binary Proxy ExecutionT1219 · Remote Access ToolsT1546.003 · Windows Management Instrumentation Event SubscriptionT1547.001 · Registry Run Keys / Startup FolderT1552.001 · Credentials In FilesT1552.006 · Group Policy PreferencesT1555 · Credentials from Password StoresT1555.003 · Credentials from Web BrowsersT1556.006 · Multi-Factor AuthenticationT1560.001 · Archive via UtilityT1566 · PhishingT1566.001 · Spearphishing AttachmentT1566.002 · Spearphishing LinkT1569.002 · Service ExecutionT1571 · Non-Standard PortT1573.001 · Symmetric CryptographyT1588.002 · ToolT1621 · Multi-Factor Authentication Request Generation