Curious Serpens’ FalseFont Backdoor: Technical Analysis, Detection and Prevention
ID: cabc37cb-ea44-562f-8ecc-1cfdc9286c2e
STIX ID: report--cabc37cb-ea44-562f-8ecc-1cfdc9286c2e
Feed Name: Palo Alto Networks Unit 42
Date Published: 2024-03-21
Date Updated: 2026-04-28
Author: Tom Fakterman, Daniel Frank and Jerome Tujague
Unit 42 analyzes FalseFont, an ASP.NET Core backdoor used by the suspected Iranian-affiliated APT Curious Serpens that masquerades as aerospace hiring software to target job applicants; FalseFont provides remote command execution, file operations, credential theft, screen capture, persistent installation, and dual C2 channels (periodic HTTP polling and real-time SignalR), and the report supplies technical details, IOCs (hashes, mutex, persistence paths, C2 domain/IP, AES key), and recommended detections/mitigations via Palo Alto Networks products.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
