APT33__2017__Insights_into_Iranian_Cyber_Espionage_APT33_Targets_Aerospace_and_Energy_Sectors_and_has_Ties_to_Destructive_Malware_Threat_Research_Blog_FireEye_Inc.pdf
ID: 941a5809-4022-4aa5-8918-57c20be70e5f
STIX ID: report--941a5809-4022-4aa5-8918-57c20be70e5f
Threat Score
90/100
Uploaded: 2026-08-14
Published Date: 2017-09-21
Last Modified Date: 2017-09-21
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
FireEye details APT33, a suspected Iran-linked APT active since at least 2013 that has targeted aerospace and energy organizations in the United States, Saudi Arabia, and South Korea using spear-phishing and malicious .hta lures; the report describes custom and public backdoors (TURNEDUP, DROPSHOT, NANOCORE, NETWIRE), potential ties to destructive wiper malware (SHAPESHIFT), provides domains, hashes and C2s as IOCs, and assesses operational patterns and indicators that suggest government sponsorship and high capability.
