HomeSecurityIranian hackers APT33 target defense companies with FalseFont backdoor

Iranian hackers APT33 target defense companies with FalseFont backdoor

Microsoft says Iranian cyberespionage hackers APT33 ( also known as Peach Sandstorm, HOLMIUM, Refined Kitten) are using the new FalseFont backdoor malware to attack defense companies.

APT33 hackers

The defense sector targeted in these attacks includes more than 100,000 companies and subcontractors engaged in the research and development of military weapons systems and components.

Iranian hackers APT33 have been active since at least 2013. They have targeted various industrial sectors in the United States, Saudi Arabia, and South Korea.

See also: Russian hackers APT28 infect organizations with HeadLace backdoor

The FalseFont backdoor malware used in the new attacks is a custom backdoor that provides its operators with remote access to compromised systems and allows file execution and file transfer to command and control (C2) servers.

According to Microsoft, this malware was first observed around early November 2023.

"activity Peach Sandstorm observed by Microsoft over the past year, suggesting that Peach Sandstorm continues to improve its work," the company said.

Network defenders are urged to restore credentials for accounts that have been targeted by password spray attacksto reduce the attack surface targeted by APT33 hackers.

They should also revoke session cookies and implement multi- factor authentication (MFA) to protect accounts and RDP or Windows Virtual Desktop endpoints.

Defense companies targeted by hackers

In September, Microsoft warned of another campaign coordinated by the APT33 threat group that targeted organizations around the world (including in the defense sector) through password spray attacks.

See also: TA4557 hackers target recruiters with More_Eggs backdoor

“Between February and July 2023, Peach Sandstorm carried out a wave of attacks , attempting to gain access to thousands of environments,” the Microsoft Threat Intelligence team said.

“During 2023, Peach Sandstorm (APT33) has consistently shown interest in US and other organizations in the satellite, defense, and, to a lesser extent, pharmaceutical sectors“.

FalseFont backdoor
Iranian hackers APT33 target defense companies with FalseFont backdoor

The above attacks resulted in data from a limited number of victims.

In recent years, defense agencies and contractors around the world have also been targeted by Russian, North Korean, and Chinese state hackers.

It is important for defense companies to take some protective measures:

First, defense companies must implement strong information security policies. This includes training employees on cybersecurity threats and how to respond to them, as well as implementing strict standards for accessing and handling sensitive data.

Second, companies need to invest in advanced security systems that can detect and respond to cybersecurity. This may include developing internal capabilities or outsourcing to external vendors.

See also: Kimsuky hackers target research centers for backdoor distribution

Third, the use of encryption can help protect data from breach. Data should be encrypted during transport and storage, ensuring that only authorized users can access it.

Finally, companies need to create a disaster recovery plan to ensure they can recover their data and operations quickly after an attack.

source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS