logo

APT33__2017__Insights_into_Iranian_Cyber_Espionage_APT33_Targets_Aerospace_and_Energy_Sectors_and_has_Ties_to_Destructive_Malware_Threat_Research_Blog_FireEye_Inc.pdf

ID: 941a5809-4022-4aa5-8918-57c20be70e5f

STIX ID: report--941a5809-4022-4aa5-8918-57c20be70e5f

Threat Score

90/100

Uploaded: 2026-08-14

Published Date: 2017-09-21

Last Modified Date: 2017-09-21

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
FireEye details APT33, a suspected Iran-linked APT active since at least 2013 that has targeted aerospace and energy organizations in the United States, Saudi Arabia, and South Korea using spear-phishing and malicious .hta lures; the report describes custom and public backdoors (TURNEDUP, DROPSHOT, NANOCORE, NETWIRE), potential ties to destructive wiper malware (SHAPESHIFT), provides domains, hashes and C2s as IOCs, and assesses operational patterns and indicators that suggest government sponsorship and high capability.