logo

Curious Serpens’ FalseFont Backdoor: Technical Analysis, Detection and Prevention

ID: cabc37cb-ea44-562f-8ecc-1cfdc9286c2e

STIX ID: report--cabc37cb-ea44-562f-8ecc-1cfdc9286c2e

Feed Name: Palo Alto Networks Unit 42

Threat Score
85/100

Date Published: 2024-03-21

Date Updated: 2026-04-28

Author: Tom Fakterman, Daniel Frank and Jerome Tujague

...
...

Unit 42 analyzes FalseFont, an ASP.NET Core backdoor used by the suspected Iranian-affiliated APT Curious Serpens that masquerades as aerospace hiring software to target job applicants; FalseFont provides remote command execution, file operations, credential theft, screen capture, persistent installation, and dual C2 channels (periodic HTTP polling and real-time SignalR), and the report supplies technical details, IOCs (hashes, mutex, persistence paths, C2 domain/IP, AES key), and recommended detections/mitigations via Palo Alto Networks products.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.