Notorious Iranian Hackers Have Been Targeting the Space Industry With a New Backdoor
55 years, 2 months ago

Notorious Iranian Hackers Have Been Targeting the Space Industry With a New Backdoor

Wired  

The Iranian government-backed hacking group known as APT 33 has been active for more than 10 years, conducting aggressive espionage operations against a diverse array of public and private sector victims around the world, including critical infrastructure targets. The backdoor, which Microsoft named “Tickler” for some reason, infects a target after the hacking group gains initial access via password spraying or social engineering. The researchers observed Peach Sandstorm deploying Tickler and then manipulating victim Azure cloud infrastructure using the hackers’ Azure subscriptions to gain full control of target systems. Since February 2023, the researchers say they have observed the hackers “carrying out password spray activity against thousands of organizations.” And in April and May 2024, Microsoft observed Peach Sandstorm using password spraying to target United States and Australian organizations that are in the space, defense, government, and education, sectors. “Peach Sandstorm also continued conducting password spray attacks against the educational sector for infrastructure procurement and against the satellite, government, and defense sectors as primary targets for intelligence collection,” Microsoft wrote.

History of this topic

A Hacker Group Within Russia’s Notorious Sandworm Unit Is Breaching Western Networks
1 month, 2 weeks ago
Microsoft: Russian-backed hackers targeting cloud services
3 years, 5 months ago
SolarWinds hackers continue to hit technology companies, says Microsoft
3 years, 5 months ago
The Russian hacker group behind the SolarWinds attack is at it again, Microsoft says
3 years, 5 months ago
Russian-backed hackers are targeting cloud services, Microsoft says
3 years, 5 months ago
Russian agency behind Solarwinds still targeting US: Microsoft
3 years, 5 months ago
SolarWinds hacking campaign puts Microsoft in the hot seat
3 years, 11 months ago
SolarWinds hacking campaign puts Microsoft in hot seat
3 years, 11 months ago
SolarWinds hack: Russian cybercriminals attack CrowdStrike, attempt to read emails
4 years, 3 months ago

Discover Related