Breaking cybersecurity news, news analysis, commentary, and other content from around the world, with an initial focus on the Middle East & Africa and the Asia Pacific
Iran's 'Peach Sandstorm' Cyberattackers Target Global Defense Network
The FalseFont backdoor allows operators to remotely access an infected system and launch additional files.
Microsoft has observed the Iranian nation-state cyberattackers known as Peach Sandstorm attempting to deliver a backdoor to individuals working for organizations in the military-industrial sector.
In a series of messages on X, formerly Twitter, Microsoft Threat Intelligence said the Peach Sandstorm advanced persistent threat (aka APT33, Elfin, Holmium, or Refined Kitten) has been attempting to deliver the FalseFont backdoor to various organizations within the global infrastructure that enables the research and development of military weapons, systems, subsystems, and components.
Microsoft Threat Intelligence says FalseFont is a custom backdoor with a "wide range of functionalities" that allow operators to remotely access an infected system, launch additional files, and send information to its command and control servers.
FalseFont was first observed being used against targets in early November. It was not clear if there were any detections of successful infections.
Microsoft said Peach Sandstorm has consistently demonstrated interest in organizations in the satellite and defense sectors in 2023. The development and use of FalseFont is consistent with Peach Sandstorm activity observed by Microsoft over the past year, suggesting the group is continuing to improve their tradecraft.
Read more about:
DR Global Middle East & AfricaAbout the Author
You May Also Like
Transform Your Security Operations And Move Beyond Legacy SIEM
Nov 6, 2024Unleashing AI to Assess Cyber Security Risk
Nov 12, 2024Securing Tomorrow, Today: How to Navigate Zero Trust
Nov 13, 2024The State of Attack Surface Management (ASM), Featuring Forrester
Nov 15, 2024Applying the Principle of Least Privilege to the Cloud
Nov 18, 2024