Tickler is a custom multi-stage backdoor used by the Iranian state-sponsored threat actor Peach Sandstorm, also referred to in the content as APT33 / Refined Kitten / Curious Serpens. Microsoft observed it deployed between April and July 2024 in campaigns targeting organizations in the satellite, communications equipment, oil and gas, and U.S. federal, state, and local government sectors, including victims in the United States and the United Arab Emirates. The activity is assessed to support Iranian intelligence collection interests and is linked to the IRGC. Tickler has also been described in the content as used against defense, energy, telecom, space, and government-related targets, including a compromised U.S. local government.
The malware is described as a custom multi-stage backdoor that collects initial host and network information, communicates with attacker-controlled Azure resources, and uses fraudulent or compromised Azure subscriptions and Azure App Service for command and control. Microsoft observed Peach Sandstorm using compromised education-sector accounts to access existing Azure subscriptions or create new Azure infrastructure used as Tickler C2 or operational hop points. Tickler was observed beaconing to Azure-hosted infrastructure to download additional payloads, including a backdoor, a persistence-setting batch script, legitimate Windows-signed binaries likely used for DLL sideloading, and malicious DLLs.
Observed delivery and execution details include an archive named "Network Security.zip" containing benign PDF decoys and a file named "YAHSAT NETWORK_INFRASTRUCTURE_SECURITY_GUIDE_20240421.pdf.exe," a 64-bit C/C++ PE sample. The initial sample launched a benign PDF decoy, resolved APIs from kernel32.dll via PEB traversal, collected host network information, and sent it to C2 via HTTP POST. A later sample, "sold.dll," acted as a Trojan dropper that downloaded additional components. Persistence was established via a batch script adding a registry Run key for "SharePoint.exe." The malware is also described as using legitimate Windows binaries to evade detection and establish persistence.
Tickler supports typical backdoor functionality including host and network discovery, directory listing, command execution, file deletion, configurable beacon interval changes, and file upload/download. Explicitly reported commands include systeminfo, dir, run, delete, interval, upload, and download. Legitimate signed files downloaded in observed activity included msvcp140.dll, LoggingPlatform.dll, vcruntime140.dll, and Microsoft.SharePoint.NativeMessaging.exe. High-confidence indicators directly mentioned in the content include the filenames "YAHSAT NETWORK_INFRASTRUCTURE_SECURITY_GUIDE_20240421.pdf.exe" and "sold.dll," the archive "Network Security.zip," and the persistence artifact of a registry Run key for "SharePoint.exe."
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
These actors maintain mature IT-centric tradecraft—phishing, credential theft, webshelling, and custom backdoors (e.g., multi-stage implants like Tickler)—to achieve persistent access in defense, energy, and telecom sectors.
In 2024, they... deployed Tickler malware against US and UAE satellite, government, and energy sectors.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
Peach Sandstorm deployed a new custom multi-stage backdoor, Tickler, and leveraged Azure infrastructure hosted in fraudulent, attacker-controlled Azure subscriptions for command-and-control (C2).
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A multi-stage implant/custom backdoor referenced as part of IRGC-linked enterprise intrusion tradecraft used for persistent access in enterprise environments.
Malware deployed in targeted intrusions affecting satellite, government, and energy-related targets (as described in the report).
Malware used by Peach Sandstorm (APT33) for targeting satellite, government, and energy sectors.
Custom backdoor malware used by Curious Serpens (Peach Sandstorm) for espionage and data collection.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.