APT33__2019__More_than_a_Dozen_Obfuscated_APT33_Botnets_Used_for_Extreme_Narrow_Targeting.pdf
ID: efe2586f-c9d8-4390-98ee-67afe9b063fb
STIX ID: report--efe2586f-c9d8-4390-98ee-67afe9b063fb
Threat Score
85/100
Uploaded: 2026-08-14
Published Date: 2019-11-14
Last Modified Date: 2019-11-14
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Trend Micro reports that APT33 has operated more than a dozen small, highly targeted botnets using multiple obfuscation layers (cloud proxies, shared webserver backends, and private OpenVPN exit nodes) to persist in networks of high-value targets—particularly in the oil, aviation, and military sectors across the Middle East, U.S., and Asia. The report includes lists of spear-phishing sender addresses, C2 domains, VPN exit-node IP addresses, and SHA256s for observed malware samples, documents evidence of active infections in supply-chain organizations and recommends remediation and detection measures.
