APT
ATLAS
Atlas
Actors
147
Names
471
Sectors
40
Requirements
480
⌘K
▸
sign in
Atlas
Actors
147
Names
471
Sectors
40
Requirements
480
LOADING
Actors
/
Nation-state / APT
/
Asia
APT33
G0064
APT
IR · Iran
AKA
Magnallium · HOLMIUM · Elfin · ATK35
CrowdStrike
:
REFINED KITTEN
Microsoft
:
Peach Sandstorm
MITRE
:
G0064
Secureworks
:
IRON TILDEN
Targets
9
Sectors
6
Threat types
2
GIRs covered
0/480
Active since
2013
Pin to atlas
Watch
Share
Export
Also tracked as
5 vendor names · 4 other aliases
Open Rosetta Stone
CrowdStrike
REFINED KITTEN
Mandiant
APT33
Microsoft
Peach Sandstorm
MITRE
G0064
Secureworks
IRON TILDEN
UNATTRIBUTED ALIASES
Magnallium
HOLMIUM
Elfin
ATK35
Victimology
Geographic footprint · 9 countries
Region filter
Export
origin · Iran
targeted countries · 9
ASIA ·
4
United Arab Emirates
·
Japan
·
South Korea
·
Saudi Arabia
OCEANIA ·
1
Australia
AMERICAS ·
2
Canada
·
United States
EUROPE ·
2
Switzerland
·
Netherlands
Sectors targeted
6 of 40
Defense
72 actors
Aerospace
59 actors
Energy / Utilities
59 actors
Oil and Gas
21 actors
Industrials / Engineering
29 actors
Private Sector (generic)
29 actors
Tactics, techniques, procedures
Threat types + MITRE ATT&CK mapping
THREAT TYPES
ESP · Espionage
SUP · Supply Chain
MITRE ATT&CK · 24 techniques
Initial Access
· 2
T1566.001
Spearphishing Attachment
T1566.002
Spearphishing Link
Execution
· 5
T1053.005
Scheduled Task
Persistence
· 1
Privilege Escalation
· 1
T1068
Exploitation for Privilege Escalation
Credential Access
· 8
T1003.001
LSASS Memory
Collection
· 1
T1560.001
Archive via Utility
Exfiltration
· 1
T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
Command And Control
· 3
T1071.001
Web Protocols
Stealth
· 2
T1078
Valid Accounts
GIR coverage
0 / 480 requirements satisfied
Open matrix
No GIRs mapped yet for this actor.
Open data
Machine-readable exports of this profile
JSON · REST
Actor record
Full profile via the public v1 API
STIX 2.1
Intrusion-set bundle
Deterministic ids · techniques + targeted countries
ATT&CK NAVIGATOR
Technique layer
24 techniques · layer format 4.5
Related actors
By origin and actor type
APT31
nation-state
China · 6 targets · since 2013
APT8
nation-state
China · 5 targets · since —
APT24
nation-state
China · 3 targets · since 2008
APT27
nation-state
China · 23 targets · since 2010
APT44
nation-state
Russia · 25 targets · since 2009
APT21
nation-state
China · 5 targets · since 2010
T1059.001
PowerShell
T1059.005
Visual Basic
T1203
Exploitation for Client Execution
T1204.001
Malicious Link
T1547.001
Registry Run Keys / Startup Folder
T1003.004
LSA Secrets
T1003.005
Cached Domain Credentials
T1040
Network Sniffing
T1552.001
Credentials In Files
T1552.006
Group Policy Preferences
T1555
Credentials from Password Stores
T1555.003
Credentials from Web Browsers
T1105
Ingress Tool Transfer
T1571
Non-Standard Port
T1078.004
Cloud Accounts