Tickler is a custom multi-stage Windows backdoor deployed by the Iranian state-sponsored threat actor Peach Sandstorm, also tracked as APT33, in 2024. It has targeted satellite, communications equipment, oil and gas, defense, and U.S. federal and state government organizations, principally in the United States and the United Arab Emirates, in support of Iranian intelligence-collection objectives. Tickler has been delivered in decoy-laden archives and evolved to use DLL sideloading with legitimate signed Windows binaries. It communicates with attacker-controlled Azure infrastructure, including Azure App Service resources, to beacon, retrieve additional payloads, and receive tasking. Its supported functions include host and network discovery, directory enumeration, command execution, file deletion, configurable beacon intervals, and file upload and download. Tickler establishes persistence through Windows Registry Run-key execution and employs legitimate binaries for defense evasion.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The content cites unverified third-party reporting that APT33 may host Tickler backdoor C2 infrastructure on fraudulent Azure subscriptions.
In 2024, they... deployed Tickler malware against US and UAE satellite, government, and energy sectors.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
Peach Sandstorm deployed a new custom multi-stage backdoor, Tickler, and leveraged Azure infrastructure hosted in fraudulent, attacker-controlled Azure subscriptions for command-and-control (C2).
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A backdoor mentioned only as a comparison to alleged APT33 Azure-hosted C2 practices; it is not linked to the Screening Serpens campaigns under analysis.
A multi-stage implant/custom backdoor referenced as part of IRGC-linked enterprise intrusion tradecraft used for persistent access in enterprise environments.
Malware deployed in targeted intrusions affecting satellite, government, and energy-related targets (as described in the report).
Malware used by Peach Sandstorm (APT33) for targeting satellite, government, and energy sectors.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.