Iranian cybercriminals target US defense targets with brand new malware

Microsoft has released new intelligence claim that Iranian state-sponsored cybercriminal Peach Sandstorm is using a tailored backdoor and password spraying attack for intelligence operations on satellite communications.

The backdoor, dubbed “Tickler” by Microsoft Threat Intelligence, is a specialized multi-stage malicious software are used to compromise target organizations and then laterally gather information using Server Message Block (SMB), remote monitoring and management (RMM) tools, and Active Directory (AD) snapshots.