Iranian hackers infiltrate US defense orgs using advanced cyber backdoor.

December 24, 2023
1 min read

Iranian cyberspies have targeted US defense organizations with a new backdoor called FalseFont, according to Microsoft. The malware allows operators to remotely access infected systems, launch additional files, and send information to command and control servers. The backdoor was first observed being used against targets in November 2023. The threat hunters at Mandiant, who track the Iran-backed group as APT33, say the group targets organizations in the US, Saudi Arabia, and South Korea for “strategic cyberespionage”. They have a particular interest in commercial and military aviation companies, as well as those in the energy sector with ties to petrochemical production.

Latest from Blog

Bridging the cyber talent gap: tips for CISOs

TLDR: – Global cyber threats have increased twofold in recent years, leading to a talent gap of nearly 4 million cyber professionals worldwide. – Existing cyber staff are under strain, with vacancies

North Korean hackers pivot to ransomware attacks

TLDR: North Korean hackers from APT45 have shifted from cyber espionage to ransomware attacks APT45 has targeted critical infrastructure and is linked to ransomware families SHATTEREDGLASS and Maui A North Korea-linked threat