Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Cotton Sandstorm

Also known as: Emennet Pasargad, Holy Souls, MARNANBRIDGE, NEPTUNIUM, HAYWIRE KITTEN

Description

Cotton Sandstorm is an Iranian threat actor involved in hack-and-leak operations. They have targeted various organizations, including the French satirical magazine Charlie Hebdo, where they obtained and leaked personal information of over 200,000 customers. The group has been linked to the Iranian government and has been sanctioned by the US Treasury

Goals & Targeting

Targeted Sectors

Government
Financial services
Telecommunications
Non profit
Energy

AI Analysis

· 1 week ago

Executive Summary

Cotton Sandstorm is an Iranian state-sponsored Advanced Persistent Threat (APT) group known for conducting hack-and-leak operations targeting critical sectors such as government, financial services, telecommunications, non-profits, and energy. The group has been linked to the Iranian government and sanctioned by the U.S. Treasury, with notable campaigns including the attack on Charlie Hebdo, where they leaked personal data of over 200,000 individuals. Their primary objectives appear to be intelligence gathering and political influence through the exposure of sensitive information.

Goals & Targeting

Cotton Sandstorm's strategic objectives are centered on intelligence gathering and political influence. Their targeting profile focuses on sectors that hold sensitive information relevant to national security and economic interests, such as government agencies, financial institutions, and critical infrastructure. The group's choice of victims indicates a focus on disrupting adversaries' operations and embarrassing target nations through data leaks. Given the Iranian government's geopolitical interests, Cotton Sandstorm likely targets countries or organizations perceived as opposing Iranian policies or strategic interests.

Enhanced Description

Cotton Sandstorm operates as a sophisticated Iranian cyber threat group primarily engaged in hack-and-leak activities. The group has demonstrated the ability to target high-profile organizations across various sectors, including media, government, and finance. Their operations often involve compromising victim systems to extract sensitive data, which is then leaked or used for political advantage. The group's association with the Iranian government suggests a state-sponsored mandate aimed at advancing national interests through cyber espionage and information warfare. Cotton Sandstorm has employed various tactics to infiltrate their targets, including initial access via spear-phishing emails with malicious payloads, credential harvesting techniques such as keylogging, and lateral movement within networks. Data extraction is typically conducted using custom tools or existing frameworks to ensure stealth and persistence.

Key Capabilities

  • State-sponsored resources enabling prolonged campaigns
  • Advanced cyber espionage techniques
  • Custom malware development for persistent access
  • Spear-phishing with malicious Office documents
  • Lateral movement within compromised networks
  • Data exfiltration using encrypted channels

MITRE ATT&CK Tactics

Espionage
Disruption
Exfiltration

ATT&CK Techniques

T1072.001 - Spear Phishing Email
T1055 - Pico Bid-stealing
T1566.001 - Exfiltration over User Channels
T1093.001 - Domain Fronting

Software / Tooling

Custom malware for initial access and persistence
Cobalt Strike for C2 communication
SMB/FTP for data exfiltration

Campaigns & Victims

Cotton Sandstorm has demonstrated persistence in targeting high-value assets across multiple sectors. Their campaigns often involve a phased approach, starting with initial access through spear-phishing emails containing malicious attachments. Once inside the network, they employ techniques to achieve persistence and lateral movement before exfiltrating sensitive data. Notable campaigns include the attack on Charlie Hebdo, which highlighted their ability to compromise and leak large volumes of personal data. Their operational tempo suggests a focus on long-term objectives, likely aligned with broader state-sponsored goals.

IOC Patterns

  • Spear-phishing emails with malicious Office documents
  • C2 communication over Domain Fronting techniques
  • Staging infrastructure using bulletproof hosting services
  • Data exfiltration via encrypted protocols

Recommended Actions

  • Implement robust email filtering to detect spear-phishing attempts
  • Monitor for lateral movement and credential theft indicators
  • Conduct regular network visibility audits to identify APT tactics
  • Enhance incident response plans with TTPs specific to Cotton Sandstorm
  • Use MITRE ATT&CK framework for defensive strategy

Suggested Tags

APT
Hack-and-leak
State-sponsored
Cyber espionage
Government sector
Financial services sector

Confidence Assessment

Confidence in the description of Cotton Sandstorm is low due to limited publicly available information on their exact TTPs, toolset, and specific campaign details. While linked to the Iranian government and involved in high-profile attacks like the Charlie Hebdo case, gaps exist in understanding their full capabilities, such as the extent of their tool development and the geographic scope of their operations.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Government Targeting
APT
Hack-and-leak
State-sponsored
Cyber espionage
Government sector
Financial services sector

Details

Type
Unknown
Country of Origin
I
Confidence
50%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.