HIGHApt
Verified
United States

Iranian APT Targets US Defense Industrial Base with New MalwareLoader

Friday, February 27, 2026 at 11:00 AM UTC·Source: Microsoft Threat Intelligence

Updated: Saturday, February 28, 2026 at 09:00 AM UTC

Executive Summary

Iranian threat actor Peach Sandstorm deploys novel loader in campaign against US defense industrial base. Targets include drone and satellite manufacturers.

Analysis

Microsoft Threat Intelligence has identified Iranian threat actor Peach Sandstorm (APT33/Elfin) deploying a new custom loader dubbed FalconDrop against US defense industrial base companies. Targets include manufacturers of drones, satellites, and radar systems. Initial access via password spray attacks against Azure AD. The loader evades detection by masquerading as legitimate Windows Update components.

Timeline

Discovered
Feb 10, 2026
Exploitation Detected
Feb 10, 2026
Published
Feb 27, 2026
Source Attribution

Originally published by Microsoft Threat Intelligence on Feb 27, 2026. Verified by: Microsoft, CISA, NSA.

Related Threats