Cybersecurity entity

APT33

threat-actor

The clearest coverage concentration is threat-intel: 18 of 20 stories, with the rest divided among 1 other category. Iran is the most frequent co-covered peer, appearing in 19 of the 20 tracked stories. Against the same-window beat baseline of 60% negative, this entity's 85% share is more negative.

Last mentioned: Mar 25, 2026

Entity pulse

Recent coverage · APT33

20 stories
8.2 avg impact
0% positive
85% negative

Coverage balance Negative coverage leads. Negative coverage exceeds positive coverage by 85 percentage points.

  • 15% neutral
  • 85% negative

Figures are computed live from our source-verified story record — see our methodology for how impact and sentiment are derived.

What the coverage shows about APT33

The clearest coverage concentration is threat-intel: 18 of 20 stories, with the rest divided among 1 other category. Iran is the most frequent co-covered peer, appearing in 19 of the 20 tracked stories. Against the same-window beat baseline of 60% negative, this entity's 85% share is more negative. Their average consequence score of 8.2 runs above the beat's 7.1 for that window. Each story carries 3.5 original sources on average, compared with 2.8 for the broader beat in this window. That works out to roughly 7.4 stories per week across a 19-day span. The busiest single day carried 2. This profile follows 20 Cybersecurity stories mentioning APT33 across the period from March 7, 2026 to March 25, 2026.

Stories tracked
20
Per week
7.4
Negative
85%
Sources per story
3.5

Computed from the 20 stories linked to this entity, with beat comparisons drawn from all 306 Cybersecurity stories published in the same date window. Shares are omitted below five stories and comparisons below a twenty-story baseline.

Coverage cohort

Appears alongside

Other entities that clear the same relevance threshold in stories also covering APT33. Shared-story counts are live from our verified record — not editorial picks.

Timeline

  1. Projected Tactical Shift

    Expected increase in Iranian cyber espionage and influence operations.

  2. Operational Horizon

    The minimum date for the conclusion of the currently planned Israeli military operations.

  3. Deadline Expiration

    The 48-hour window is set to expire, potentially triggering strikes on Iranian energy infrastructure.

  4. Projected Retaliation

    Threat intelligence firms predict a surge in Iranian-backed cyber activity against US targets.

  5. Commander Update

    Top US commander announces the campaign is 'ahead or on plan' during a press briefing.

  6. The U-Turn

    President Trump announces a new diplomatic path, signaling a shift away from confrontation.

  7. Nuclear Site Security

    Reports emerge of strikes specifically targeting Israeli-linked nuclear infrastructure areas.

  8. Cyber Alert Issued

    Global threat intelligence firms report increased scanning activity from Iranian-linked IP ranges.

  9. Diplomatic Escalation

    US and Iran trade public threats regarding the expansion of the current conflict.

  10. Kinetic Strikes Reported

    Explosions confirmed near sites associated with nuclear research and development.

  11. Ultimatum Issued

    President Trump announces a 48-hour window for Iran to restore commercial traffic in the Strait of Hormuz.

  12. Market Paralysis

    Reports confirm that oil and gas shipments through the Persian Gulf have come to a complete standstill.

  13. Cyber Suppression

    Reports of widespread internet outages and military network failures within Iran.

  14. De-escalation Signal

    President Trump announces consideration of winding down the war.

  15. Threat Analysis

    Intelligence analysts identify the specific focus on 'world tourism sites' as a new hybrid threat vector.

  16. Troop Surge Confirmed

    Official confirmation that thousands of U.S. troops are being deployed to the region.

  17. Initial Reports

    First reports emerge of a significant U.S. military buildup and Iranian threats against tourism.

  18. Operation Commencement

    IRGC announces the start of Operation True Promise 4 targeting regional adversaries.

  19. Kinetic Strikes Reported

    Initial reports confirm missile and drone strikes on military assets in the region.

  20. Targeted Retaliation Window

    Historical window for more complex, state-directed cyber disruptions or wiper deployments.

Stories mentioning APT33 20

Security Strongly negative

Trump Issues 48-Hour Ultimatum to Iran Over Hormuz Strait Blockade

President Trump has issued a 48-hour deadline for Iran to reopen the Strait of Hormuz to commercial traffic, threatening targeted strikes against the nation's power plants. The escalation follows a total paralysis of oil and gas shipments through the world's most critical energy chokepoint.

2 sources
Threat Intelligence Strongly negative

Operation True Promise 4: IRGC Strikes Trigger Global Cyber-Kinetic Alert

The Islamic Revolutionary Guard Corps (IRGC) has initiated 'Operation True Promise 4,' targeting U.S. and Israeli military installations with kinetic strikes. This escalation marks a critical shift in the regional conflict, prompting cybersecurity agencies to warn of imminent state-sponsored cyber offensives and infrastructure targeting.

2 sources
Threat Intelligence Negative

US-Iran Kinetic Escalation Triggers Global Cyber Alert for Infrastructure

As the United States intensifies military operations against Iran and deploys Marines to the Middle East, cybersecurity agencies have issued urgent warnings regarding retaliatory cyberattacks. Iranian state-sponsored threat actors are expected to target Western critical infrastructure, specifically the energy and financial sectors, using destructive wiper malware.

2 sources
Threat Intelligence Negative

Iran Leadership Shift Signals Heightened Cyber Offensive Amid Regional War

Iran has issued a formal statement from its new leadership as active hostilities with the United States and Israel escalate into a broader regional conflict. This transition marks a critical juncture for global cybersecurity, with intelligence analysts warning of a significant shift in Iranian state-sponsored cyber doctrine and offensive operations.

2 sources
Threat Intelligence Negative

US-Iran Escalation: Cyber Fallout Expected After Record Kinetic Strikes

Following what U.S. officials describe as the most intense day of kinetic strikes against Iranian targets, cybersecurity experts are warning of immediate retaliatory cyber operations. Defense Secretary Pete Hegseth confirmed the scale of the military action, signaling a significant shift in the regional conflict that historically triggers high-volume Iranian cyber offensives.

2 sources
Threat Intelligence Negative

US-Iran Escalation: Cybersecurity Risks and the Push for Senate Oversight

Democratic US senators are demanding immediate hearings following an escalation in conflict with Iran, signaling a critical shift in national security priorities. This geopolitical flashpoint significantly raises the threat level for US critical infrastructure as Iranian-aligned APT groups are expected to launch retaliatory cyber operations.

2 sources
Threat Intelligence Negative

Global Cyber Fallout Intensifies One Week Into Iran Conflict

One week after the commencement of kinetic operations involving Iran, the digital battlefield has expanded into a global 'gray zone' conflict. State-aligned threat actors have transitioned from espionage to destructive operations, targeting critical infrastructure and financial systems across the West and the Middle East.

2 sources

APT33 is linked from 24 stories on this site, each scored at or above our 35% relevance threshold — see how these pages are built.

See something wrong on this page — a misattributed entity, a wrong stat, a broken source link? Report a data issue.