logo

Cloud Threats Memo: Iranian Threat Actors Continue to Exploit Azure

ID: fcd38276-d207-54e4-b67d-50daed9bbc1a

STIX ID: report--fcd38276-d207-54e4-b67d-50daed9bbc1a

Feed Name: Netskope Threat Labs

Threat Score
85/100

Date Published: 2024-09-11

Date Updated: 2026-04-28

Author: Paolo Passeri

...
...

Microsoft researchers observed APT33 (Peach Sandstorm) running an April–July 2024 campaign that used LinkedIn for target reconnaissance, password-spraying to compromise accounts, and deployed a new multi-stage backdoor named Tickler whose command-and-control infrastructure was hosted in attacker-controlled or compromised Microsoft Azure subscriptions (notably leveraging accounts in the education sector); the report also cites a similar Azure-based campaign by UNC1549 and describes how Netskope controls can mitigate cloud-hosted C2 and malware delivery.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.