Elfin: Relentless Espionage Group Targets Multiple Organizations in Saudi Arabia and U.S.
ID: 269a9555-8275-4867-9230-a38472b7e2b9
STIX ID: report--269a9555-8275-4867-9230-a38472b7e2b9
Threat Score
88/100
Uploaded: 2026-08-14
Published Date: 2019-03-28
Last Modified Date: 2019-03-28
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This Symantec report profiles Elfin (APT33), an active espionage group that has targeted ~50 organizations (notably in Saudi Arabia and the U.S.) since 2016, describing their reconnaissance and website-scanning approach, exploitation of a WinRAR vulnerability, use of custom and commodity malware (POSHC2, Quasar, DarkComet, AutoIt tools), a detailed case study of intrusion and exfiltration, and a comprehensive set of IoCs and recommended protections.
