Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Symantec reported on March 27, 2019, that the espionage group it called Elfin had attacked at least 50 organizations in Saudi Arabia, the United States, and other countries over roughly the preceding three years. In activity Symantec had observed since early 2016, 42% of attacks were against Saudi targets; it also said 18 U.S. organizations had been attacked over three years. These are Symantec’s historical figures, not a current count or a census of the group’s activity.

What is Elfin (APT33)?

Elfin is the name Symantec used for a threat group it characterized as an espionage operation and suspected of being Iranian. Actor names vary among security vendors and tracking systems. MITRE ATT&CK’s combined entry is titled APT33, HOLMIUM, Elfin, Peach Sandstorm, Group G0064; those labels reflect names associated in that knowledge base, not proof that every organization uses them identically or that naming alone establishes attribution.

In contemporaneous reporting, CyberScoop said FireEye had previously assessed APT33 as acting at the behest of the Iranian government. That is FireEye’s attributed assessment, distinct from Symantec’s characterization of Elfin as suspected Iranian. Symantec analyst Jon DiMaggio told CyberScoop, “Elfin’s goal appears to be sabotage,” phrasing the point as an assessment rather than a confirmed statement of intent.

Who did Symantec say Elfin targeted?

Symantec’s March 2019 report described attacks over approximately the previous three years and provided these figures from its own observations:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Reported figure What it refers to
At least 50 organizations Organizations in Saudi Arabia, the United States, and other countries attacked over the preceding three years, according to Symantec.
42% of observed attacks Share attributed to Saudi Arabia among attacks Symantec had observed since early 2016.
18 U.S. organizations Organizations Symantec said had been attacked over three years.

The percentages and counts describe Symantec’s reporting window and visibility; they should not be read as a complete tally of Elfin activity or as a measure of current targeting.

The reported targets extended beyond government organizations. Symantec named organizations in research, chemicals, engineering, manufacturing, consulting, finance, telecommunications, energy, information technology, and healthcare. The report therefore depicted a cross-sector target set, not a campaign limited to one industry.

What happened in the February 2019 WinRAR incident?

Symantec said Elfin attempted to exploit CVE-2018-20250, a vulnerability in WinRAR, against a Saudi chemical-sector organization in February 2019. Two users received an archive named JobDetails.rar, which Symantec said was likely delivered through spear-phishing. The vulnerability could allow a file to be installed on an unpatched computer, potentially enabling code execution.

Symantec said its protection blocked the exploit attempt and that the target was not compromised. This is a historical account of an attempted attack and its outcome, not a description of the security status of current WinRAR releases.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What tools and capabilities did Symantec describe?

Symantec described a mixed toolkit: custom malware, commonly available malicious software, and public security tools that could be repurposed. Its report named custom tools including Notestuk (also called TURNEDUP), Stonedrill, and an AutoIt backdoor; commodity malware including Remcos, DarkComet, Quasar RAT, Pupy RAT, NanoCore, and NetWeird; and public tools including LaZagne, Mimikatz, Gpppassword, and SniffPass.

Symantec described Stonedrill as destructive malware. DiMaggio told CyberScoop that “Their malware, a trojan called Stonedrill, is designed to wipe the hard drives of the systems they infect, rendering them useless to the victim.” That describes a capability; the report does not establish that Stonedrill’s destructive function was used against every organization in the target set.

For a U.S. case study, Symantec described a phishing lure followed by downloaded scripts, persistence through scheduled tasks, later use of remote-access tools, and software used to collect and exfiltrate data. The report’s account shows how espionage activity could involve multiple stages; it does not mean every reported victim experienced the same sequence.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Was Elfin linked to Shamoon?

Symantec reported that one Saudi victim of Shamoon had recently also been attacked by Elfin and infected with Stonedrill. The timing led to speculation about a relationship between the groups, but Symantec said it had no further evidence at publication that Elfin was responsible for the Shamoon attacks under discussion. Temporal proximity alone does not establish common responsibility.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Sources and scope

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.