HIGHApt
Verified
United States

Iranian APT Targets US Defense Industrial Base with New MalwareLoader

·Source: Microsoft Threat Intelligence

Updated:

Executive Summary

Iranian threat actor Peach Sandstorm deploys novel loader in campaign against US defense industrial base. Targets include drone and satellite manufacturers.

Analysis

Microsoft Threat Intelligence has identified Iranian threat actor Peach Sandstorm (APT33/Elfin) deploying a new custom loader dubbed FalconDrop against US defense industrial base companies. Targets include manufacturers of drones, satellites, and radar systems. Initial access via password spray attacks against Azure AD. The loader evades detection by masquerading as legitimate Windows Update components.

Timeline

Discovered
Feb 10, 2026
Exploitation Detected
Feb 10, 2026
Published
Feb 27, 2026
Source Attribution

Originally published by Microsoft Threat Intelligence on Feb 27, 2026. Verified by: Microsoft, CISA, NSA.

Related Threats

MEDIUMApt

Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials

The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider malware-as-a-service (MaaS) platform called Lunex. The new findings come from Ontinue, which described the activity as a four-stage attack chain aimed at targeting Ukrainian-speaking users. "The attack chain begins with a fake CAPTCHA page and

The Hacker News
MEDIUMApt

Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee

I feel like someone who reads this blog will want to go to this : Families are invited to dive into the fascinating world of marine biology during an exciting, hands-on Family Squid Dissection at the Hands-On Science Center. Designed for curious learners of all ages, this unique experience combines an interactive lesson with the opportunity to explore the anatomy and adaptations of real ocean life

Schneier on Security
MEDIUMApt

AI tools help hacker break in for $25 per target

It’s cheap to set yourself up as a hacker these days using AI. Someone attacked 105 online retailers over a period of five days, compromising 27 of them — all for an average of $25 per attack, according to research by Israeli security company Gambit . But the attacks have been going on for much longer. Whoever is responsible used open-source AI harnesses to mount the attack. Gambit has identified

CSO Online