Iranian cybercriminals target US defense targets with new malware

Microsoft has launched new intelligence claiming that Iranian state-sponsored threat actor Peach Sandstorm is using a custom backdoor and password spraying attacks for intelligence operations on satellite communications.

The backdoor, dubbed 'Tickler' by Microsoft Threat Intelligence, is a specialized, multi-stage system. Malicious program It is used to compromise target organizations, before moving laterally to gather intelligence through the use of Server Message Block (SMB), remote management and monitoring (RMM) tools, and Active Directory (AD) snapshots.

scroll to top