EagleRelay is a custom tunneling tool observed by Microsoft in operations attributed to the Iranian nation-state threat actor Peach Sandstorm (also tracked as HOLMIUM, with public reporting overlap to APT33/Elfin/Refined Kitten). Microsoft reported the actor used EagleRelay in a handful of compromised environments to tunnel traffic back to attacker-controlled infrastructure. In some cases, Peach Sandstorm created a new virtual machine in a compromised Azure subscription specifically to run EagleRelay for this traffic tunneling. The malware was part of broader post-compromise activity following initial access obtained through large-scale password spraying and, in some cases, exploitation of internet-facing applications including Zoho ManageEngine CVE-2022-47966 and Atlassian Confluence CVE-2022-26134. The overall campaign targeted thousands of organizations globally, with emphasis on satellite, defense, and to a lesser extent pharmaceutical sectors, and was assessed by Microsoft as likely supporting Iranian intelligence collection. EagleRelay was used alongside other tooling for reconnaissance, persistence, lateral movement, and remote access, including AzureHound, ROADtools, AnyDesk, Azure Arc abuse, Golden SAML activity, DLL search order hijacking using a legitimate VMware executable, and RDP-based lateral movement. No standalone EagleRelay-specific indicators of compromise were provided beyond Microsoft’s observation that it tunneled traffic to actor infrastructure from compromised Azure-hosted systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"...Microsoft observed Peach Sandstorm using EagleRelay to tunnel traffic back to their infrastructure."
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom tunneling tool used to proxy/tunnel traffic between actor-controlled systems and victim systems (including via attacker-created Azure VMs), supporting stealthy access and operations.
Custom tunneling tool run from attacker-controlled Azure VMs to relay/tunnel traffic between actor systems and victim systems, supporting stealthy access and operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.