Also known as: Haywire Kitten, Emennet Pasargad, Aria Sepehr Ayandehsazan, MarnanBridge, Mango Sandstorm, Static Kitten, Pink Sandstorm, Agonizing Serpens, AMERICIUM, BlackShadow, DEV-0022, Agrius, UNC2428, Black Shadow, SPECTRAL KITTEN
Altoufan Team (also known as Cotton Sandstorm) is widely recognized as an IRGC‑affiliated cyber threat group that aligns its attacks with regional political objectives. The actor is adept at high–trust impersonation, leveraging spearphishing campaigns that masquerade as urgent software updates or legitimate messaging app notifications to harvest credentials and session tokens. Once inside a network, Altoufan Team deploys credential stealers such as RedLine Stealer and WezRat, enabling lateral movement via compromised accounts and internal phishing. The group commonly uses remote‑monitoring and management (RMM) tools delivered through file‑sharing services, while also deploying ASPX web shells for persistence and command & control. Attackers frequently pair destructive tactics with fake‑ransomware efforts—most notably WhiteLock ransomware—to sow confusion or drive down costs of remediation. They exploit misconfigured or weakly secured internet‑exposed assets like IP cameras and external applications and often probe services for default credentials. In parallel, the actor conducts hack–and–leak operations that amplify stolen data through fake personas and impersonation, reinforcing their influence campaigns. Altoufan’s operational tempo shows a pattern of targeted attacks linked to geopolitical events, shifting focus among Bahrain, Israel, UAE, and other countries while maintaining an emphasis on critical infrastructures and politically vocal targets.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Altoufan Team, often operating under the moniker Cotton Sandstorm, is an Iran‑linked threat actor engaged in politically driven campaigns that blend credential theft, ransomware, and information‑leak tactics. Their operations target a wide array of high‑value sectors—government, defense, critical infrastructure, finance and energy—and employ sophisticated social engineering to obtain access before launching destructive or leak‑based actions.
Goals & Targeting
This group pursues multi‑layered objectives that range from influencing public perception through hack‑and‑leak campaigns to collecting actionable intelligence for future operations. By targeting sectors directly tied to security, energy, finance and government, Altoufan Team seeks both reputational damage and strategic advantage for its aligned political entities. The use of high‑trust impersonation and fake‑ransomware tactics underscores a dual intent: immediate disruptive impact while preserving long‑term influence through data leaks.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Altoufan Team’s activity is tightly linked to regional conflicts and political events, with notable operations in Bahrain and Israel where they have used credential theft and ransomware to disrupt. The actor demonstrates a consistent pattern of executing supply‑chain footholds and leveraging social engineering, enabling rapid compromise of high‑trust accounts. Their use of commercial VPN services and Starlink IP ranges points to deliberate obfuscation efforts. While the group’s first or most recent sightings remain unclear due to limited public data, their campaigns often involve large scale leak‑outs followed by targeted phishing or ransomware attempts aimed at creating sustained pressure on victims.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The assessment is based on limited publicly disclosed incidents and reports; while there is consistent evidence of credential theft, ransomware deployment, and social‑engineering tactics tied to Altoufan Team, details such as the full spectrum of tools, exact attribution links, operational tempo over time, and direct impact metrics remain incomplete. Additional intelligence—particularly from OSINT monitoring of attacker infrastructure and deeper forensic analysis of compromised systems—would enhance confidence.
No campaigns linked yet.
No observed data linked yet.
16
Techniques
46
Tools
0
Campaigns
6
IOCs
0
Observed Data
8
Tactics