Also known as: Emennet Pasargad, Holy Souls, MARNANBRIDGE, NEPTUNIUM, HAYWIRE KITTEN
Cotton Sandstorm is an Iranian threat actor involved in hack-and-leak operations. They have targeted various organizations, including the French satirical magazine Charlie Hebdo, where they obtained and leaked personal information of over 200,000 customers. The group has been linked to the Iranian government and has been sanctioned by the US Treasury
Targeted Sectors
Executive Summary
Cotton Sandstorm is an Iranian state-sponsored Advanced Persistent Threat (APT) group known for conducting hack-and-leak operations targeting critical sectors such as government, financial services, telecommunications, non-profits, and energy. The group has been linked to the Iranian government and sanctioned by the U.S. Treasury, with notable campaigns including the attack on Charlie Hebdo, where they leaked personal data of over 200,000 individuals. Their primary objectives appear to be intelligence gathering and political influence through the exposure of sensitive information.
Goals & Targeting
Cotton Sandstorm's strategic objectives are centered on intelligence gathering and political influence. Their targeting profile focuses on sectors that hold sensitive information relevant to national security and economic interests, such as government agencies, financial institutions, and critical infrastructure. The group's choice of victims indicates a focus on disrupting adversaries' operations and embarrassing target nations through data leaks. Given the Iranian government's geopolitical interests, Cotton Sandstorm likely targets countries or organizations perceived as opposing Iranian policies or strategic interests.
Enhanced Description
Cotton Sandstorm operates as a sophisticated Iranian cyber threat group primarily engaged in hack-and-leak activities. The group has demonstrated the ability to target high-profile organizations across various sectors, including media, government, and finance. Their operations often involve compromising victim systems to extract sensitive data, which is then leaked or used for political advantage. The group's association with the Iranian government suggests a state-sponsored mandate aimed at advancing national interests through cyber espionage and information warfare. Cotton Sandstorm has employed various tactics to infiltrate their targets, including initial access via spear-phishing emails with malicious payloads, credential harvesting techniques such as keylogging, and lateral movement within networks. Data extraction is typically conducted using custom tools or existing frameworks to ensure stealth and persistence.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Cotton Sandstorm has demonstrated persistence in targeting high-value assets across multiple sectors. Their campaigns often involve a phased approach, starting with initial access through spear-phishing emails containing malicious attachments. Once inside the network, they employ techniques to achieve persistence and lateral movement before exfiltrating sensitive data. Notable campaigns include the attack on Charlie Hebdo, which highlighted their ability to compromise and leak large volumes of personal data. Their operational tempo suggests a focus on long-term objectives, likely aligned with broader state-sponsored goals.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the description of Cotton Sandstorm is low due to limited publicly available information on their exact TTPs, toolset, and specific campaign details. While linked to the Iranian government and involved in high-profile attacks like the Charlie Hebdo case, gaps exist in understanding their full capabilities, such as the extent of their tool development and the geographic scope of their operations.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics