Threats Feed|Peach Sandstorm|Last Updated 08/07/2026|AuthorCertfa Radar|Publish Date21/12/2023

Peach Sandstorm's FalseFont Backdoor Targets Defense Industrial Base

  • Actor Motivations: Espionage,Exfiltration
  • Attack Vectors: Backdoor,Malware
  • Attack Complexity: Medium
  • Threat Risk: High Impact/Low Probability

Threat Overview

The Iranian nation-state actor Peach Sandstorm has been observed by Microsoft deploying a new backdoor, FalseFont, targeting individuals in the Defense Industrial Base (DIB) sector. FalseFont is a sophisticated tool with capabilities for remote access, launching files, and data exfiltration to C2 servers. Initially used in early November 2023, its deployment marks a continuation of Peach Sandstorm's evolving cyber tradecraft.

Detected Targets

TypeDescriptionConfidence
SectorDefense
Verified

Extracted IOCs

  • digitalcodecrafters[.]com
  • 364275326bbfc4a3b89233dabdaf3230a3d149ab774678342a40644ad9f8d614
download

Tip: 2 related IOCs (0 IP, 1 domain, 0 URL, 0 email, 1 file hash) to this threat have been found.

Overlaps

Curious SerpensCurious Serpens’ FalseFont Backdoor Targets US Aerospace Job Applicants

Source: Palo Alto Networks - March 2024

Detection (two cases): 364275326bbfc4a3b89233dabdaf3230a3d149ab774678342a40644ad9f8d614, digitalcodecrafters[.]com

Peach SandstormPeach Sandstorm Exploits Maxar Technologies’ Branding in Cyber Espionage

Source: Nextron Systems - January 2024

Detection (two cases): 364275326bbfc4a3b89233dabdaf3230a3d149ab774678342a40644ad9f8d614, digitalcodecrafters[.]com

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

Peach Sandstorm and the FalseFont Cyberattack

A cyberattack campaign was discovered where a newly created malicious software, called FalseFont, was delivered to targeted computer systems. This software acts as a secret "backdoor," giving attackers remote control over the infected computers.

The attack is attributed to Peach Sandstorm, an Iranian nation-state group. This group has been actively tracked over the past year and is known for continuously improving its tools and cyber espionage tactics.

The goal of the attack was to secretly infect systems to gain remote access. Once inside, the attackers used the FalseFont software to launch additional malicious files and steal information, sending it back to their own servers.

Yes. The attackers focused specifically on individuals who work for organizations within the Defense Industrial Base sector.

The attackers developed custom software and delivered it to their targets. Once installed, this software opened a hidden channel to the attackers, allowing them to move deeper into the organization's network and quietly extract data.

Organizations in the Defense Industrial Base handle sensitive technologies, manufacturing, and operational data. This makes them highly attractive targets for state-sponsored groups looking to steal valuable defense-related information.

This is a highly targeted issue. Instead of indiscriminately attacking the general public, the threat actors focused their efforts specifically on individuals tied to the defense sector.

Organizations should ensure their security software is fully updated to detect this specific threat. Security teams should also actively search their networks for the specific digital signatures and web addresses associated with the FalseFont software to ensure they have not been compromised.

About Affiliation
Peach Sandstorm
Peach Sandstorm is Microsoft's current name for the Iranian nation-state threat actor known across the industry as APT33. Active since at least 2013, the group conducts espionage operations targeting organizations in the satellite, defense, aerospace, energy, and pharmaceutical sectors globally. Peach Sandstorm is best known for conducting large-scale password spray campaigns against thousands of organizations, followed by stealthy post-compromise activity using cloud-based tools such as AzureHound, Roadtools, and the TICKLER backdoor to collect intelligence in support of Iranian state interests.
View Peach Sandstorm's Insights