Peach Sandstorm deploys new custom Tickler malware in long-running intelligence gathering operations
ID: 1f853cc7-a0ed-5af4-8d27-1c603de243ee
STIX ID: report--1f853cc7-a0ed-5af4-8d27-1c603de243ee
Feed Name: Microsoft Security
Between April and July 2024 Microsoft observed Iranian state-sponsored actor Peach Sandstorm deploy a new multi-stage backdoor called Tickler against targets in the satellite, communications equipment, oil and gas, federal and state government, and education sectors, using password-spray, LinkedIn-based intelligence gathering, and attacker-controlled or compromised Azure subscriptions for C2; the report provides technical analysis of samples, IOCs (domains and file hashes), hunting queries, and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
