New Tickler malware used to backdoor US govt, defense orgs
ID: 57256ad8-e46a-5f93-8904-3ca09df1ee37
STIX ID: report--57256ad8-e46a-5f93-8904-3ca09df1ee37
Feed Name: Bleeping Computer
APT33 (Peach Sandstorm) conducted a long-running intelligence-gathering campaign from April to July 2024 against government, defense, space, satellite, oil & gas, and education organizations using password-spray attacks to gain access and deploying a new Tickler backdoor. The actor leveraged compromised or attacker-created Microsoft Azure subscriptions as command-and-control infrastructure; Microsoft observed and disrupted these Azure-based C2 resources and linked the activity to prior APT33 campaigns and tooling.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
