Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Groups/G0064
MITRE ATT&CK Group

APT33 (G0064)

HOLMIUMElfinPeach Sandstorm
ShareXLinkedInRedditHN

[APT33](https://attack.mitre.org/groups/G0064) is a suspected Iranian threat group that has carried out operations since at least 2013. The group has targeted organizations across multiple industries in the United States, Saudi Arabia, and South Korea, with a particular interest in the aviation and energy sectors.(Citation: FireEye APT33 Sept 2017)(Citation: FireEye APT33 Webinar Sept 2017)

▪Techniques used (34)

T1552.001Credentials In FilesT1003.005Cached Domain CredentialsT1560.001Archive via UtilityT1555.003Credentials from Web BrowsersT1552.006Group Policy PreferencesT1027.013Encrypted/Encoded FileT1566.001Spearphishing AttachmentT1003.001LSASS MemoryT1566.002Spearphishing LinkT1110.003Password SprayingT1003.004LSA SecretsT1053.005Scheduled TaskT1555Credentials from Password StoresT1546.003Windows Management Instrumentation Event SubscriptionT1105Ingress Tool TransferT1048.003Exfiltration Over Unencrypted Non-C2 ProtocolT1588.002ToolT1040Network SniffingT1071.001Web ProtocolsT1059.001PowerShellT1547.001Registry Run Keys / Startup FolderT1078Valid AccountsT1573.001Symmetric CryptographyT1059.005Visual BasicT1132.001Standard EncodingT1571Non-Standard PortT1078.004Cloud AccountsT1203Exploitation for Client ExecutionT1204.002Malicious FileT1204.001Malicious LinkT1068Exploitation for Privilege EscalationT0852Screen CaptureT0865Spearphishing AttachmentT0853Scripting

▪Software used (16)

S0194PowerSploittoolS0129AutoIt backdoormalwareS0378PoshC2toolS0358RulertoolS0002MimikatztoolS0336NanoCoremalwareS1134DEADWOODmalwareS0380StoneDrillmalwareS0371POWERTONmalwareS0349LaZagnetoolS0199TURNEDUPmalwareS0198NETWIREmalwareS0039NettoolS0192PupytoolS0363EmpiretoolS0095ftptool
G0064on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.