Microsoft says Iranian hackers (APT33) have targeted thousands of organizations in the US and around the world in password spraying attacks. These attacks have been ongoing since February 2023.
Iranian state hackers appear to have managed to steal sensitive information from a limited number of victims in the defense, satellite, and pharmaceutical sectors.

The cyber-espionage group, known as APT33 (also known as Peach Sandstorm, HOLMIUM, or Refined Kitten), has been active since 2013 and has targeted a variety of industries, including government, defense, research, financial, and engineering organizations in the United States, Saudi Arabia, and South Korea. The group has become one of the most recognizable hacking groups and continues to operate with great determination and skill.
See also: 'ThemeBleed': Windows 11 RCE flaw gets PoC
“ Between February and July 2023, Peach Sandstorm carried out a wave of password spraying attacks, attempting to gain access to thousands of environments ,” the Microsoft Threat Intelligence team said
“Throughout 2023, Peach Sandstorm has consistently shown interest in organizations in the US and other countries in the satellite, defense, and, to a lesser extent, pharmaceutical sectors,” Sherrod DeGrippo, Threat Intelligence Strategy Director at Microsoft, told BleepingComputer.
In password spraying attacks, attackers attempt to gain access to multiple accounts using a single password or a list of commonly used passwords. Password spraying attacks are different from brute-forceattacks. In the latter category, a single account is targeted with a long list of passwords. However, password spraying attacks allow attackers to significantly increase their chances of success while reducing the risk of automatic account lockout.
According to Microsoft, however, Iranian hackers are also using exploits targeting unpatched Confluence and ManageEngine appliances to compromise targets' networks.
See also: Ongoing Webex malvertising campaign spreads BatLoader
After successful attempts, APT33 hackers used AzureHound or Roadtools open-source security frameworks for reconnaissance on victims' Azure Active Directory to collect data from their cloud environments.
They also used compromised Azure credentials, created new Azure subscriptions in the victims' tenants, or abused Azure Arc for persistence to control devices on the victims' network.

Finally, Iranian hackers used Golden SAML attack techniques for lateral movement, using AnyDesk for persistence, sideloading custom malicious DLLs to execute malicious payloads, and using a tunneling tool known as EagleRelay to funnel malicious traffic into the command-and-control (C2) infrastructure.
Based on the targets and attack method , Microsoft estimates that this access campaign is likely being used to gather information in support of Iranian state interests.
“Many of the tactics, techniques, and procedures (TTPs) featured in these most recent campaigns are substantially more sophisticated than the capabilities Peach Sandstorm used in the past,” the company added.
See also: Ransomware: White House urges dozens of countries to pledge not to pay ransoms
Iranian hackers APT33 have become particularly active in recent years, with password spraying attacks increasing their effectiveness. It is clear that these attacks are much more sophisticated than previous ones, indicating a continuous evolution and improvement of their skills. The ability of Iranian hackers to adapt and evolve in this rapidly changing digital environment is worrying, as attacks become increasingly successful and widespread.
Source: www.bleepingcomputer.com
