---
title: Microsoft Warns of New ‘FalseFont’ Backdoor Targeting the Defense Sector
description: Microsoft has issued a warning about a new backdoor threat named FalseFont, targeting organizations in the Defense Industrial Base sector. This campaign is attributed to an Iranian threat actor known as Peach Sandstorm (formerly Holmium), APT33, Elfin, and Refined Kitten.
image: https://blog.oitc.ca/hubfs/Imported_Blog_Media/malware-2-1.jpg
---

[Skip to content](https://blog.oitc.ca/alerts/microsoft-warns-of-new-falsefont-backdoor-targeting-the-defense-sector#main-content)

![Outsource IT Computing](https://blog.oitc.ca/hs-fs/hubfs/OITC%20Logo-1.png?width=1408&height=302&name=OITC%20Logo-1.png)Homepage

- [Services](https://oitc.ca/services)
- [Industries](https://oitc.ca/industries)
- Company
  
    - [Careers](https://oitc.ca/careers)
    - [About Us](https://oitc.ca/about)
    - [Solution Partners](https://oitc.ca/solution-partners)
    - [Community Support](https://oitc.ca/community-support)
- Resources
  
    - [Blog](https://blog.oitc.ca)
    - [Bill Payments](https://pay.oitc.ca/)
    - [VoIP 911](https://oitc.ca/v911/)
    - [Client Portal](https://portal.oitc.ca/)

[Get started](https://oitc.ca/contact/)

- [Services](https://oitc.ca/services)
- [Industries](https://oitc.ca/industries)
- Company
  
    - [Careers](https://oitc.ca/careers)
    - [About Us](https://oitc.ca/about)
    - [Solution Partners](https://oitc.ca/solution-partners)
    - [Community Support](https://oitc.ca/community-support)
- Resources
  
    - [Blog](https://blog.oitc.ca)
    - [Bill Payments](https://pay.oitc.ca/)
    - [VoIP 911](https://oitc.ca/v911/)
    - [Client Portal](https://portal.oitc.ca/)

[Get started](https://oitc.ca/contact/)

![](https://blog.oitc.ca/hs-fs/hubfs/Imported_Blog_Media/malware-2-1.jpg?width=728&height=380&name=malware-2-1.jpg)

Alerts

# Microsoft Warns of New ‘FalseFont’ Backdoor Targeting the Defense Sector

![Nathan Zych](https://7528315.fs1.hubspotusercontent-na1.net/hub/7528315/hubfs/raw_assets/public/mV0_d-cms-elevate-theme_hubspot/elevate/images/avatar-placeholder.jpg?width=48&height=48&name=avatar-placeholder.jpg)

 Nathan Zych

December 28, 2023

Microsoft has issued a warning about a new backdoor threat named FalseFont, targeting organizations in the Defense Industrial Base sector. This campaign is attributed to an Iranian threat actor known as Peach Sandstorm (formerly Holmium), APT33, Elfin, and Refined Kitten. Read the full article [here](https://thehackernews.com/2023/12/microsoft-warns-of-new-falsefont.html).

[![GET UNLIMITED REMOTE AND ONSITE BUSINESS IT SUPPORT FOR A FIXED FEE](https://blog.oitc.ca/hs-fs/hubfs/Imported_Blog_Media/MSP-B-Jul-10-2025-10-19-45-5033-PM.png?width=900&name=MSP-B-Jul-10-2025-10-19-45-5033-PM.png)](https://www.oitc.ca/contact/)

[Click here to contact Outsource IT](https://www.oitc.ca/contact/)

## Share this post

<https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fblog.oitc.ca%2Falerts%2Fmicrosoft-warns-of-new-falsefont-backdoor-targeting-the-defense-sector><https://twitter.com/intent/tweet?url=https%3A%2F%2Fblog.oitc.ca%2Falerts%2Fmicrosoft-warns-of-new-falsefont-backdoor-targeting-the-defense-sector><https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fblog.oitc.ca%2Falerts%2Fmicrosoft-warns-of-new-falsefont-backdoor-targeting-the-defense-sector><https://pinterest.com/pin/create/button/?url=https%3A%2F%2Fblog.oitc.ca%2Falerts%2Fmicrosoft-warns-of-new-falsefont-backdoor-targeting-the-defense-sector>[mailto:https%3A%2F%2Fblog.oitc.ca%2Falerts%2Fmicrosoft-warns-of-new-falsefont-backdoor-targeting-the-defense-sector](mailto:https%3A%2F%2Fblog.oitc.ca%2Falerts%2Fmicrosoft-warns-of-new-falsefont-backdoor-targeting-the-defense-sector)

## Keep reading

### [Managed IT vs In-House IT: Why It’s Not Always an Either-Or Decision](https://blog.oitc.ca/managed-it-vs-in-house-it-why-its-not-always-an-either-or-decision)

### [Blog 10 Signs You’ve Outgrown Your Current IT Provider](https://blog.oitc.ca/10-signs-youve-outgrown-your-current-it-provider)

[![OITC Logo-1](https://blog.oitc.ca/hs-fs/hubfs/OITC%20Logo-1.png?width=300&height=64&name=OITC%20Logo-1.png "OITC Logo-1")](https://oitc.ca)

<https://www.linkedin.com/organization/1598823/><https://www.facebook.com/outsourceitcomputing/><https://x.com/oitc_ca>

---

[Privacy Policy](https://oitc.ca/privacy-policy/) · © 2025. All rights reserved.

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Nathan Zych",
    "url" : "https://blog.oitc.ca/author/nathan-zych"
  },
  "dateModified" : "2025-07-10T22:20:34.508Z",
  "datePublished" : "2023-12-28T16:10:23.000Z",
  "headline" : "Microsoft Warns of New ‘FalseFont’ Backdoor Targeting the Defense Sector",
  "mainEntityOfPage" : {
    "@id" : "https://blog.oitc.ca/alerts/microsoft-warns-of-new-falsefont-backdoor-targeting-the-defense-sector",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://blog.oitc.ca/hubfs/OITC%20Logo-1.png"
    }
  }
}
```