logo

Microsoft Warns of New 'FalseFont' Backdoor Targeting the Defense Sector

ID: b03b752e-abfa-5921-b7f2-b9ec24199072

STIX ID: report--b03b752e-abfa-5921-b7f2-b9ec24199072

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2023-12-22

Date Updated: 2026-04-23

Author: [email protected] (The Hacker News)

...
...

Microsoft reports that the Iranian-linked APT "Peach Sandstorm" (APT33) has deployed a previously unseen custom backdoor called FalseFont in campaigns targeting organizations in the Defense Industrial Base, first observed in November 2023; the disclosure aligns with prior password-spray and intelligence-collection activity attributed to the group. The report also references related activity observed by other vendors and the Israel National Cyber Directorate, including wiper malware variants (Hatef/Hamsa) delivered via a phishing decoy that referenced CVE-2023-46747 and attacker communications over Telegram, indicating expanded tradecraft and destructive operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.