← Back to all threat actors

APT33

Also known as HOLMIUM, Elfin, Peach Sandstorm
Tracked as G0064

APT33 is a suspected Iranian threat group that has carried out operations since at least 2013. The group has targeted organizations across multiple industries in the United States, Saudi Arabia, and South Korea, with a particular interest in the aviation and energy sectors.

How we source and review actor profiles
Motivation
nation-state
Attributed nexus
IR
Sectors
energy, aviation, defense
Status
Active

Activity timeline

A dated ledger of actor-claimed victims, campaigns, indicators, identity mappings, relationships, and CVE links. Each date states what it measures. For extensive leak-site histories, victim entries are limited to the 100 most recent distinct listings.

Cataloged
IdentityAlias: HOLMIUM

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Elfin

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Peach Sandstorm

Reviewed identity mapping approved on this date.

Cataloged
IdentityTracking identifier: G0064

Reviewed identity mapping approved on this date.

Identity and attribution

Exact names and tracking identifiers resolve to this canonical profile. Rebrands, affiliations, and overlapping clusters remain separate confidence-rated relationships.

Name map

APT33Canonical Name
ElfinAlias
HOLMIUMAlias
Peach SandstormAlias
G0064Tracking Id

Loading CVEs, techniques, indicators, malware, victims, and activity...