ZeroHour
CyberScooppublished ()ingested @AJVicens

Microsoft: Iranian espionage campaign targeted satellite and defense sectors

criticalThreat actor exploited in the wildimportance 60
Full article755 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

Tehran's latest hacking activity involves easy-to-detect techniques to gain access and then pivoting to stealthier methods.

Iranian flag waving with cityscape on background in Tehran, Iran. (Sir Francis Canker Photography/Getty Images)
Iranian flag waving with cityscape on background in Tehran, Iran. (Sir Francis Canker Photography/Getty Images)

An Iranian cyber espionage group successfully compromised dozens of entities and exfiltrated data from a subset of them as part of a campaign targeting organizations in the satellite, defense and pharmaceutical sectors, Microsoft said in a report published Thursday.

The group in question — which Microsoft tracks as Peach Sandstorm but known otherwise as Holmium, APT33 or Elfin — compromised the accounts as part of a high volume of password spray attacks, where attackers try one known password against a list of usernames. The campaign began in February and targeted thousands of organizations, according to Microsoft.

Microsoft did not say where the targeted organizations are based but noted that previous Peach Sandstorm activity occurred during a “rise in tensions between the United States and the Islamic Republic of Iran.” Researchers have linked some of the group’s previous operations to the devastating destructive Shamoon malware attacks that targeted Saudi Aramco, the oil company, in 2012 and other targets in subsequent years.

The news comes on the heels of an incipient deal between the U.S. and Iranian governments that would allow banks to transfer $6 billion in frozen Iranian oil funds and see U.S. authorities release of five Iranian citizens held in the United States in exchange for the release of five American citizens detained in Iran, the Washington Post reported Monday.

The hacking activity disclosed on Monday took place between February and July this year, and Microsoft said that the hackers used the access they gained to maintain persistence on breached systems and carry out other, unspecified activity. Password spray attacks are noisy and easy to detect, but Microsoft researchers said that the activity is concerning because once the hackers gain access, they are in some cases pivoting toward stealthier, more sophisticated methods that represent an increase in capability compared to Peach Sandstorm’s past activity.

Researchers observed two pathways into targeted organizations associated with the campaign. The first, via the password spray route, allowed researchers to learn more about the campaign, showing, for instance, that the activity occurred almost exclusively between 9 a.m. and 5 p.m. Iran Standard Time. The second pathway saw the group attempt to exploit a pair of vulnerabilities from 2022 affecting a subset of on-premises Zoho ManageEngine products and the Confluence Server and Data Center.

More Scoops

Gwengoat, iStock/Getty Images Plus

Feds quash widespread Russia-backed espionage network spanning 18,000 devices

Forest Blizzard, a threat group attributed to Russia’s GRU, hijacked network traffic to steal credentials and tokens for Microsoft accounts and other services.

Miguel Escamilla Jr., mannufacturing manager of ShayoNano, demonstrates the operation of programmable logic controller at the company’s production plant July 25, 2017, in Stafford. The Singapore-based company chose Stafford to be their U.S. headquarters. (Photo by Yi-Chin Lee/Houston Chronicle via Getty Images)

Iranian hackers launching disruptive attacks at U.S. energy, water targets, feds warn

A man talks on the phone walking along Red Square in front of St. Basil’s Cathedral in central Moscow on February 28, 2023. (Photo by Alexander NEMENOV / AFP) (Photo by ALEXANDER NEMENOV/AFP via Getty Images)

New Russian state-sponsored APT quickly gains global reach, hitting expansive targets

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/iran-peach-sandstorm-apt33/