Microsoft Warns of New 'FalseFont' Backdoor Targeting the Defense Sector
ID: b03b752e-abfa-5921-b7f2-b9ec24199072
STIX ID: report--b03b752e-abfa-5921-b7f2-b9ec24199072
Feed Name: The Hacker News
Microsoft reports that the Iranian-linked APT "Peach Sandstorm" (APT33) has deployed a previously unseen custom backdoor called FalseFont in campaigns targeting organizations in the Defense Industrial Base, first observed in November 2023; the disclosure aligns with prior password-spray and intelligence-collection activity attributed to the group. The report also references related activity observed by other vendors and the Israel National Cyber Directorate, including wiper malware variants (Hatef/Hamsa) delivered via a phishing decoy that referenced CVE-2023-46747 and attacker communications over Telegram, indicating expanded tradecraft and destructive operations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
