Curious Serpens

Threat Actor updated 4 months ago (2024-05-04T17:30:10.237Z)
Download STIX
Preview STIX
Curious Serpens, also known by various other names such as Peach Sandstorm, APT33, Elfin, HOLMIUM, MAGNALIUM, and REFINED KITTEN, is a threat actor believed to be affiliated with Iran. This group has been active since at least 2013, engaging in cyber espionage activities primarily against the aerospace and energy sectors. The cybersecurity industry identifies this group under different monikers due to its diverse and sophisticated set of malicious tools and tactics. The group recently developed a new backdoor named FalseFont, as reported by Unit 42. This advanced persistent threat (APT) group's use of FalseFont showcases their evolving capabilities and continuous efforts to enhance their cyber-espionage tactics. Technical analysis of FalseFont reveals it as a powerful tool for infiltrating target systems, further demonstrating Curious Serpens' potential threat to organizations within their interest areas. The discovery of the FalseFont backdoor underscores the need for robust cybersecurity measures. Organizations, especially those operating within the aerospace and energy sectors, should remain vigilant against such threats. Given the suspected Iranian affiliation and the history of targeted attacks, it is crucial to monitor for signs of Curious Serpens activity, including the deployment of FalseFont and other associated malware.
Description last updated: 2024-03-21T22:14:51.333Z
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the Curious Serpens Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
Unit42
6 months ago
Curious Serpens’ FalseFont Backdoor: Technical Analysis, Detection and Prevention