logo

Iranian cyberspies target US defense orgs with a brand new backdoor

ID: a8b45af1-b5b2-580e-99ec-704fdf3b05c4

STIX ID: report--a8b45af1-b5b2-580e-99ec-704fdf3b05c4

Feed Name: The Register (Security)

Threat Score
85/100

Date Published: 2023-12-23

Date Updated: 2026-04-26

Author: Jessica Lyons Hardcastle

...
...

Infosec roundup: Microsoft and Mandiant report Iran-linked Peach Sandstorm/APT33 using a custom FalseFont backdoor to target defense industrial base employees, alongside credential-stuffing/password-spray campaigns and observed data exfiltration; separately, law enforcement and security firms uncovered a JS-sniffer operation that infected 443 e-commerce sites to skim payment data, and multiple critical vulnerabilities (including a Chrome WebRTC heap overflow CVE-2023-7024 reportedly under active exploitation) and high-severity flaws in enterprise and ICS products were disclosed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.