logo

Iranian hackers ‘tickle’ targets in US, UAE with custom tool, Microsoft says

ID: 14ad0af1-09d9-5dbe-b317-dbd0d6952bac

STIX ID: report--14ad0af1-09d9-5dbe-b317-dbd0d6952bac

Feed Name: CyberScoop

Threat Score
90/100

Date Published: 2024-08-28

Date Updated: 2026-04-21

Author: Tim Starks

...
...

Microsoft researchers say Iran-linked APT Peach Sandstorm (also tracked as APT33/Refined Kitten) deployed a bespoke backdoor named Tickler and used fraudulent Azure subscriptions and password-spray attacks to target organizations across the satellite, oil & gas, communications, and government sectors in the United States and the United Arab Emirates between April and July; Microsoft assesses the group operates on behalf of the IRGC and has successfully compromised multiple organizations to facilitate intelligence collection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.