Peach Sandstorm
Named by MicrosoftSuspected state sponsor: Islamic Republic of IranPeach Sandstorm is Microsoft's current name for the Iranian nation-state threat actor known across the industry as APT33. Active since at least 2013, the group conducts espionage operations targeting organizations in the satellite, defense, aerospace, energy, and pharmaceutical sectors globally. Peach Sandstorm is best known for conducting large-scale password spray campaigns against thousands of organizations, followed by stealthy post-compromise activity using cloud-based tools such as AzureHound, Roadtools, and the TICKLER backdoor to collect intelligence in support of Iranian state interests.
Targeted Regions
AustraliaAustralia
Nov 2021 ~ Aug 2024
Nov 2021 ~ Aug 2024
Nov 2021 ~ Aug 2024
Nov 2021 ~ Aug 2024
Nov 2021 ~ Aug 2024
Nov 2021 ~ Aug 2024
Nov 2021 ~ Aug 2024
Nov 2021 ~ Aug 2024
Nov 2021 ~ Aug 2024
Nov 2021 ~ Aug 2024
Nov 2021 ~ Aug 2024
Nov 2021 ~ Aug 2024
United Arab EmiratesUnited Arab Emirates
Nov 2021 ~ Aug 2024
Nov 2021 ~ Aug 2024
Nov 2021 ~ Aug 2024
Nov 2021 ~ Aug 2024
Nov 2021 ~ Aug 2024
Nov 2021 ~ Aug 2024
Nov 2021 ~ Aug 2024
Nov 2021 ~ Aug 2024
Nov 2021 ~ Aug 2024
Nov 2021 ~ Aug 2024
Nov 2021 ~ Aug 2024
Nov 2021 ~ Aug 2024
United StatesUnited States
Nov 2021 ~ Aug 2024
Nov 2021 ~ Aug 2024
Nov 2021 ~ Aug 2024
Nov 2021 ~ Aug 2024
Nov 2021 ~ Aug 2024
Nov 2021 ~ Aug 2024
Nov 2021 ~ Aug 2024
Nov 2021 ~ Aug 2024
Nov 2021 ~ Aug 2024 Dec 2023 ~ Jan 2024
Nov 2021 ~ Aug 2024 Dec 2023 ~ Jan 2024
Nov 2021 ~ Aug 2024
Nov 2021 ~ Aug 2024
Targeted Sectors
Recent Indexed Reports
Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.