The threat group regularly referred to as APT33 is known to aggressively target the oil and aviation industries. This threat group has been reported for a number of years, but our recent findings show that the group has been using approximately a dozen live Command and Control (C&C) servers for extremely limited targeting. The group is deploying multiple layers of engagement to run these C&C servers in malware campaigns targeting organizations in the Middle East, the US , and Asia.
We believe that these botnets, each consisting of a small group of up to a dozen infected computers, are used to gain persistence within the networks of selected targets. The malware is rather basic and has limited capabilities that include downloading and running additional malware.
APT33 appears to have been more aggressive in its attacks in recent years. For example, for at least two years, the group used the private website of a high-ranking European politician to send phishing emails to companies in the oil supply chain. Targets included a water facility used by the US military to provide drinking water to one of its military bases.
These attacks have likely led to specific “intrusions” in the oil industry. For example, in the fall of 2018, we observed communications between a Ukraine-based oil company with computer servers in the UK and India and an APT33 C&C server. Another European oil company suffered an APT33 malware infection on one of its servers in India for at least 3 weeks in November and December 2018. There were many other companies in oil supply chains that were compromised in the fall of 2018. These intrusions indicate a high risk for companies in the oil industry, as the APT33 group is known to use destructive malware.

The first two emails in the table above (ending in .com and .aero) have been spoofed by the threat actor. However, the addresses ending in .ga originate from the attacker's infrastructure. All of the addresses resemble well-known aviation and oil and gas companies.

In addition to APT33's relatively high-profile attacks against oil product supply chains, we found that APT33 uses several C&C domains for small botnets consisting of about a dozen bots each.
It appears that APT33 has taken special care to make it difficult to track. The C&C domains are typically hosted on cloud-hosted proxies. These proxies relay URL requests from infected bots to shared web servers that may host thousands of legitimate domains. The backends report bot data back to a data aggregator and a bot control server located on a dedicated IP address. The attackers connect to these aggregators via a private VPN network with exit nodes that change frequently. The attackers command the bots and collect data from the bots using these VPN connections.
In the fall of 2019, we identified 10 live bot data servers and have been monitoring some of them for months. These aggregators receive data from very few C&C servers (only 1 or 2), with only a dozen victims per single C&C domain. The table below lists some of the oldest C&C domains that still exist today.

Hackers often use commercial VPN services to hide their location when running C&C servers and conducting reconnaissance. But in addition to using VPN services that are available to anyone, we regularly see attackers using private VPN networks that they have created for themselves.
Creating a private VPN can be easily done by renting two servers from data centers around the world and using open source software like OpenVPN. While connections from private VPNs still originate from seemingly unrelated IP addresses around the world, this type of traffic is actually easier to detect.
