Iranian cybercriminals are targeting US defense targets with all-new malware



Microsoft has released new intelligence claiming Iranian state-sponsored threat actor Peach Sandstorm is using a custom-built backdoor and password spraying attacks for intelligence operations on satellite communications.

The backdoor, named ‘Tickler’ by Microsoft Threat Intelligence, is a specialized multi-stage malware used to compromise target organizations, before moving laterally to gather intelligence using Server Message Block (SMB), remote monitoring and management (RMM) tools, and Active Directory (AD) snapshots.

https://cdn.mos.cms.futurecdn.net/KALRKd3RmsBrSJxrqLTgQK-1200-80.jpg



Source link
benedict.collins@futurenet.com (Benedict Collins)

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img