Iranian hackers APT33 have used new malware, codenamed Tickler, to infect networks of organizations in various sectors, including government, defense, satellite, oil and gas in the United States and the United Arab Emirates.

The hackers are also known as Peach Sandstorm and Refined Kitten, and Microsoft noted that they operate on behalf of Iran's Islamic Revolutionary Guard Corps (IRGC). The Iranian hackers used the Tickler malware as part of an intelligence-gathering campaign that took place between April and July 2024.
Throughout the attacks , the attackers leveraged Microsoft Azure infrastructure for command-and-control (C2) purposes, using fraudulent, attacker-controlled Azure subscriptions, which have now been discontinued by the company.
See also: Meta revealed activities of Iranian hackers APT42 on WhatsApp
APT33 hackers breached organizations in the defense, space, education, and government sectors through password spraybetween April and May 2024. Through these attacks, they attempted to gain access to multiple accounts using a small number of common passwords.
According to Microsoft, password spraying was used in almost all attacks, but in the case of the education targets, the group exclusively exploited compromised user accounts. In these cases, the Iranian hackers accessed existing Azure or created new ones using the compromised account to host their infrastructure.
Azure infrastructure was used in subsequent malicious operations targeting the government, defense, and space sectors.
Microsoft has observed that over the past year, Iranian hackers APT33 have breached multiple organizations using specialized toolsincluding the FalseFont backdoor malware.
See also: US offers $10 million reward for Iranian hackers
In September 2023, Microsoft warned of another campaign by the APT33 group, which had targeted thousands of organizations around the world, leading to breaches in the defense, satellite, and pharmaceutical sectors.

Microsoft announced that starting October 15, multi-factor authentication (MFA) is mandatory for all Azure sign-in attempts, to protect Azure accounts from potential breaches.
The attacks by Iranian hackers APT33 with the Tickler malware show that organizations within the targeted sectors need to improve security , conduct regular security assessments, and invest in advanced detection technologies to mitigate potential risks. In addition, collaboration between government agencies and private sector companies is crucial to developing comprehensive strategies that can effectively detect and respond to similar threats in the future.
See also: Iranian hackers target Albania and Israel with wiping attacks
In light of the increasing complexity of such cyber threats, it is imperative for organizations to not only strengthen their defenses but also emphasize employee training and awareness. Cybersecurity practices, such as attempts phishing and reporting suspicious activity, can significantly reduce the risk of successful intrusions. Regular training sessions and simulations can prepare staff to respond effectively in the event of a security breach. In addition, the use of threat intelligence sharing platforms can provide organizations with timely information about new vulnerabilities and emerging attack. By fostering a culture of cybersecurity awareness and preparedness, organizations can build a more resilient defense against the tactics used by groups like APT33.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: www.bleepingcomputer.com
