APT33

threat-actor

Last mentioned: Mar 25, 2026

Timeline

  1. Cyber Alert Escalation

    Threat intelligence firms report a spike in scanning activity from Iranian-affiliated IP ranges.

  2. Operation Commencement

    IRGC announces the start of Operation True Promise 4 targeting regional adversaries.

  3. Kinetic Strikes Reported

    Initial reports confirm missile and drone strikes on military assets in the region.

  4. Threat Intel Update

    Cybersecurity agencies issue warnings of sustained Iranian APT activity.

  5. Conflict Escalation

    US and Iran trade rhetoric regarding the duration and outcome of a potential war.

  6. Official Denial

    Iran's Foreign Minister formally states that no ceasefire was requested.

  7. Cyber Alert Issued

    Anticipated 'Shields Up' guidance for US critical infrastructure providers.

  8. Military Escalation

    US begins intensive strikes on Iranian targets and announces Marine deployment.

  9. Market Reaction

    Wall Street closes lower; oil prices surge amid war fears.

  10. Anticipated Retaliation

    Projected window for the first wave of Iranian cyber counter-offensives against Western targets.

  11. Hegseth Announcement

    Defense Secretary Pete Hegseth labels the operations as the 'most intense' day of strikes in the current conflict.

  12. Cyber Alert Issued

    Threat intelligence firms report a spike in scanning activity from Iranian-affiliated IP ranges targeting US infrastructure.

  13. Ceasefire Rumors

    Speculation begins regarding a potential diplomatic pause in regional hostilities.

  14. Strike Commencement

    US forces begin a series of high-intensity kinetic strikes across multiple Iranian strategic sites.

  15. Global OT Alert

    International cybersecurity agencies issue joint warning regarding vulnerabilities in ICS/SCADA systems.

  16. Defense Contractor Phishing

    Coordinated phishing campaign by APT33 targeting US and UK defense supply chains.

  17. Wiper Malware Detected

    First reports of destructive Azero-Wiper payloads in regional logistics hubs in the Middle East.

  18. Conflict Commencement

    Initial kinetic operations begin; first wave of DDoS attacks hits Iranian government portals.

  19. Post-Soleimani Surge

    Significant increase in Iranian cyber reconnaissance following the strike on Qasem Soleimani.

  20. Shamoon Attack

    Iranian-linked wiper malware destroys 35,000 computers at Saudi Aramco.

Stories mentioning APT33 9

Threat Intelligence Very Bearish

Operation True Promise 4: IRGC Strikes Trigger Global Cyber-Kinetic Alert

The Islamic Revolutionary Guard Corps (IRGC) has initiated 'Operation True Promise 4,' targeting U.S. and Israeli military installations with kinetic strikes. This escalation marks a critical shift in the regional conflict, prompting cybersecurity agencies to warn of imminent state-sponsored cyber offensives and infrastructure targeting.

2 sources
Threat Intelligence Bearish

US-Iran Kinetic Escalation Triggers Global Cyber Alert for Infrastructure

As the United States intensifies military operations against Iran and deploys Marines to the Middle East, cybersecurity agencies have issued urgent warnings regarding retaliatory cyberattacks. Iranian state-sponsored threat actors are expected to target Western critical infrastructure, specifically the energy and financial sectors, using destructive wiper malware.

2 sources
Threat Intelligence Bearish

Iran Leadership Shift Signals Heightened Cyber Offensive Amid Regional War

Iran has issued a formal statement from its new leadership as active hostilities with the United States and Israel escalate into a broader regional conflict. This transition marks a critical juncture for global cybersecurity, with intelligence analysts warning of a significant shift in Iranian state-sponsored cyber doctrine and offensive operations.

2 sources
Threat Intelligence Bearish

US-Iran Escalation: Cyber Fallout Expected After Record Kinetic Strikes

Following what U.S. officials describe as the most intense day of kinetic strikes against Iranian targets, cybersecurity experts are warning of immediate retaliatory cyber operations. Defense Secretary Pete Hegseth confirmed the scale of the military action, signaling a significant shift in the regional conflict that historically triggers high-volume Iranian cyber offensives.

2 sources
Threat Intelligence Bearish

Global Cyber Fallout Intensifies One Week Into Iran Conflict

One week after the commencement of kinetic operations involving Iran, the digital battlefield has expanded into a global 'gray zone' conflict. State-aligned threat actors have transitioned from espionage to destructive operations, targeting critical infrastructure and financial systems across the West and the Middle East.

2 sources

About APT33 coverage

This page surfaces every story mentioning APT33 across our cybersecurity coverage. We track each entity's appearance over time so readers can trace how the narrative evolves — which developments are isolated incidents, which build into longer arcs, and which reframe how operators in the space think about the entity. Story selection uses the same multi-source verification gate applied across the rest of our coverage.

Read our editorial methodology for how we identify, deduplicate, and score entity references. Our glossary defines the technical terms used across stories on this page, and our trends index contextualizes individual developments against the longer-running cybersecurity beat. Cross-entity comparisons live on our compare view.

What you seeWhat it tells you
Story countNumber of distinct stories where APT33 was a primary or referenced actor.
Recency clusteringWhether mentions are concentrated in a recent window (a news cycle) or distributed (a sustained arc).
Sentiment distributionAggregate sentiment of the stories mentioning this entity, weighted by impact score.
Cross-niche linksWhen the same entity surfaces in our sibling networks, we link to those views to enrich context.