Peach Sandstorm, an Iranian Hackers group, targets diverse sectors globally, and this group is linked to:-
This nation-state group focuses primarily on the following sectors:-
In 2023, the group shows persistent interest in satellite, defense, and pharmaceutical sectors. Using password spray campaigns, Peach Sandstorm exhibits opportunistic behavior, with a history of relying on this tactic.
However, besides this, stealthier 2023 activities contrast with past noisy operations, showcasing advanced cloud-based techniques.
Cybersecurity researchers at Microsoft Threat Intelligence team recently discovered a new backdoor dubbed “FalseFont,” that enables threat actors to hack Microsoft’s Windows operating system, and it’s been reported that the Iranian Hacker group Peach Sandstorm has developed this new backdoor.
This custom backdoor, FalseFont, provides the following capabilities to its operators:-
This custom backdoor, FalseFont, was detected in early November 2023 during operations against its targets.
FalseFont’s development aligns with Microsoft’s year-long observation of Peach Sandstorm, indicating ongoing enhancement of their newly developed custom backdoor.
Moreover, the security solution of Microsoft that comes pre-embedded with its Windows operating system, Microsoft Defender Antivirus, detected the “FalseFont” backdoor as:-
Here below, we have mentioned the IOCs that will help the organizations detect this sophisticated backdoor in their environment:-
Cybersecurity researchers at the Microsoft Threat Intelligence team are actively continuing their ongoing investigations in an attempt to hunt down all the associated activity of Peach Sandstorm through Microsoft Defender XDR.
Here below we have mentioned all the mitigations provided by the cybersecurity researchers at the Microsoft Threat Intelligence team:-
Along with the release of Kali Linux 2025.3, a major update introduces an innovative tool that…
ChaosBot surfaced in late September 2025 as a sophisticated Rust-based backdoor targeting enterprise networks. Initial…
Threat actors have reemerged in mid-2025 leveraging previously disclosed vulnerabilities in SonicWall SSL VPN appliances…
Menlo Park, USA, October 10th, 2025, CyberNewsWire AccuKnox, a leader in Zero Trust Cloud Native…
Socket's Threat Research Team has uncovered a sophisticated phishing campaign involving 175 malicious npm packages…
Since its emergence in early 2025, RondoDox has rapidly become one of the most pervasive…