logo

APT33__2019__More_than_a_Dozen_Obfuscated_APT33_Botnets_Used_for_Extreme_Narrow_Targeting.pdf

ID: efe2586f-c9d8-4390-98ee-67afe9b063fb

STIX ID: report--efe2586f-c9d8-4390-98ee-67afe9b063fb

Threat Score

85/100

Uploaded: 2026-08-14

Published Date: 2019-11-14

Last Modified Date: 2019-11-14

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Trend Micro reports that APT33 has operated more than a dozen small, highly targeted botnets using multiple obfuscation layers (cloud proxies, shared webserver backends, and private OpenVPN exit nodes) to persist in networks of high-value targets—particularly in the oil, aviation, and military sectors across the Middle East, U.S., and Asia. The report includes lists of spear-phishing sender addresses, C2 domains, VPN exit-node IP addresses, and SHA256s for observed malware samples, documents evidence of active infections in supply-chain organizations and recommends remediation and detection measures.