When discussing suspected Middle Eastern hacker groups with
destructive capabilities, many automatically think of the href="/content/fireeye-www/en_US/blog/threat-research/2016/11/fireeye_respondsto.html">suspected
Iranian group that previously used SHAMOON – aka href="https://www.microsoft.com/security/portal/threat/encyclopedia/entry.aspx?Name=Trojan%3AWin32%2FWipMBR.B">Disttrack
– to target organizations in the Persian Gulf. However, over the past
few years, we have been tracking a separate, less widely known
suspected Iranian group with potential destructive capabilities, whom
we call APT33. Our analysis reveals that APT33 is a capable group that
has carried out cyber espionage operations since at least 2013. We
assess APT33 works at the behest of the Iranian government.
Recent investigations by FireEye’s href="/content/fireeye-www/en_US/services.html">Mandiant incident
response consultants combined with FireEye iSIGHT Threat
Intelligence analysis have given us a more complete picture of APT33’s
operations, capabilities, and potential motivations. This blog
highlights some of our analysis. Our detailed report on href="/content/fireeye-www/en_US/products/isight-cyber-threat-intelligence-subscriptions.html">FireEye
MySIGHT contains a more thorough review of our supporting evidence
and analysis. We will also be discussing this threat group further
during our href="https://www.brighttalk.com/webcast/10703/275683?utm_source=FireEye_blog">webinar
on Sept. 21 at 8 a.m. ET.
APT33 has targeted organizations – spanning multiple industries –
headquartered in the United States, Saudi Arabia and South Korea.
APT33 has shown particular interest in organizations in the aviation
sector involved in both military and commercial capacities, as well as
organizations in the energy sector with ties to petrochemical production.
From mid-2016 through early 2017, APT33 compromised a U.S.
organization in the aerospace sector and targeted a business
conglomerate located in Saudi Arabia with aviation holdings.
During the same time period, APT33 also targeted a South Korean
company involved in oil refining and petrochemicals. More recently, in
May 2017, APT33 appeared to target a Saudi organization and a South
Korean business conglomerate using a malicious file that attempted to
entice victims with job vacancies for a Saudi Arabian petrochemical company.
We assess the targeting of multiple companies with aviation-related
partnerships to Saudi Arabia indicates that APT33 may possibly be
looking to gain insights on Saudi Arabia’s military aviation
capabilities to enhance Iran’s domestic aviation capabilities or to
support Iran’s military and strategic decision making vis a vis Saudi Arabia.
We believe the targeting of the Saudi organization may have been an
attempt to gain insight into regional rivals, while the targeting of
South Korean companies may be due to South Korea’s recent partnerships
with Iran’s petrochemical industry as well as South Korea’s
relationships with Saudi petrochemical companies. Iran has href="https://financialtribune.com/articles/energy/41665/call-for-restoring-past-petrochemical-status">expressed
interest in