Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Altoufan Team

Also known as: Haywire Kitten, Emennet Pasargad, Aria Sepehr Ayandehsazan, MarnanBridge, Mango Sandstorm, Static Kitten, Pink Sandstorm, Agonizing Serpens, AMERICIUM, BlackShadow, DEV-0022, Agrius, UNC2428, Black Shadow, SPECTRAL KITTEN

Description

Altoufan Team (also known as Cotton Sandstorm) is widely recognized as an IRGC‑affiliated cyber threat group that aligns its attacks with regional political objectives. The actor is adept at high–trust impersonation, leveraging spearphishing campaigns that masquerade as urgent software updates or legitimate messaging app notifications to harvest credentials and session tokens. Once inside a network, Altoufan Team deploys credential stealers such as RedLine Stealer and WezRat, enabling lateral movement via compromised accounts and internal phishing. The group commonly uses remote‑monitoring and management (RMM) tools delivered through file‑sharing services, while also deploying ASPX web shells for persistence and command & control. Attackers frequently pair destructive tactics with fake‑ransomware efforts—most notably WhiteLock ransomware—to sow confusion or drive down costs of remediation. They exploit misconfigured or weakly secured internet‑exposed assets like IP cameras and external applications and often probe services for default credentials. In parallel, the actor conducts hack–and–leak operations that amplify stolen data through fake personas and impersonation, reinforcing their influence campaigns. Altoufan’s operational tempo shows a pattern of targeted attacks linked to geopolitical events, shifting focus among Bahrain, Israel, UAE, and other countries while maintaining an emphasis on critical infrastructures and politically vocal targets.

Goals & Targeting

Targeted Sectors

Defense
Critical infrastructure
Government
Energy
Aviation
Telecommunications
Manufacturing
Financial services
Media
Healthcare
Education
Aerospace
Non profit

Targeted Countries / Regions

IR
IL
US
TR
PL
SA
IT
AE

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 1 day ago

Executive Summary

Altoufan Team, often operating under the moniker Cotton Sandstorm, is an Iran‑linked threat actor engaged in politically driven campaigns that blend credential theft, ransomware, and information‑leak tactics. Their operations target a wide array of high‑value sectors—government, defense, critical infrastructure, finance and energy—and employ sophisticated social engineering to obtain access before launching destructive or leak‑based actions.

Goals & Targeting

This group pursues multi‑layered objectives that range from influencing public perception through hack‑and‑leak campaigns to collecting actionable intelligence for future operations. By targeting sectors directly tied to security, energy, finance and government, Altoufan Team seeks both reputational damage and strategic advantage for its aligned political entities. The use of high‑trust impersonation and fake‑ransomware tactics underscores a dual intent: immediate disruptive impact while preserving long‑term influence through data leaks.

Enhanced Description

Key Capabilities

  • High‑trust impersonation via social engineering
  • Targeted spearphishing campaigns (urgent software update themes)
  • Credential theft using RedLine Stealer, WezRat
  • Lateral movement through compromised accounts and internal phishing
  • Deployment of WhiteLock ransomware and fake‑ransomware tactics
  • Remote monitoring and management tool delivery via legitimate file sharing
  • ASPX webshell deployment for persistence and C2
  • Exploitation of misconfigured or weak internet‑exposed assets (IP cameras, external apps)
  • Supply‑chain footholds through IT/service providers
  • DDoS attacks to overwhelm targets
  • Website defacement to convey political messaging
  • VPN usage for traffic obfuscation and tunneling
  • Hack‑and‑leak amplification with fake personas

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Credential Access
Defense Evasion
Discovery
Lateral Movement
Collection
Impact

ATT&CK Techniques

T1078
T1003
T1021
T1086
T1496
T1486
T1059.003
T1566
T1566.001
T1071
T1534
T1193
T1194

Software / Tooling

Brute Ratel C4
RedLine Stealer
WezRat
WhiteLock
Mullvad VPN
NordVPN
PIA VPN
ProtonVPN

Campaigns & Victims

Altoufan Team’s activity is tightly linked to regional conflicts and political events, with notable operations in Bahrain and Israel where they have used credential theft and ransomware to disrupt. The actor demonstrates a consistent pattern of executing supply‑chain footholds and leveraging social engineering, enabling rapid compromise of high‑trust accounts. Their use of commercial VPN services and Starlink IP ranges points to deliberate obfuscation efforts. While the group’s first or most recent sightings remain unclear due to limited public data, their campaigns often involve large scale leak‑outs followed by targeted phishing or ransomware attempts aimed at creating sustained pressure on victims.

IOC Patterns

  • Malicious email attachment mimicking urgent software update
  • Phishing URL masquerading as WhatsApp, Microsoft Teams, or Google Meet
  • Credential harvesting via fake messaging service phishing kit
  • WezRat infostealer delivery
  • WhiteLock ransomware activity
  • Legitimate file sharing services used to transfer malicious RMM tools
  • Starlink IP range affiliation
  • Misconfigured or weak credentials on internet‑facing applications
  • ASPX webshell deployment
  • Living‑off‑the‑land binaries usage
  • Vulnerable IP cameras with default credentials and older CVEs

Recommended Actions

  • Block or quarantine email attachments purporting to be urgent software updates.
  • Implement MFA—preferably phishing‑resistant—for privileged and high‑trust accounts.
  • Detect and block phishing URLs mimicking messaging apps (WhatsApp, Microsoft Teams, Google Meet).
  • Deploy endpoint detection for WezRat, RedLine Stealer, and other infostealers.
  • Monitor network for WhiteLock ransomware indicators and apply ransomware defenses.
  • Vet or restrict external RMM tool usage; enforce strict acquisition policies.
  • Detect and mitigate DDoS activity originating from compromised hosts.
  • Monitor traffic to commercial VPN exit nodes (Mullvad, NordVPN, PIA, ProtonVPN).
  • Audit internet‑exposed assets—especially IP cameras—for default credentials and known CVEs.
  • Apply MFA on cloud services such as Google Workspace and Microsoft 365.

Suggested Tags

Altoufan Team
Cotton Sandstorm
IRGC-affiliated
High-trust impersonation
Credential stealer
WezRat
WhiteLock
Ransomware
Supply-chain foothold
Hack-and-leak
Fake-ransomware
Disinformation
Spearphishing
Webshell
VPN obfuscation
Starlink IP range

Confidence Assessment

The assessment is based on limited publicly disclosed incidents and reports; while there is consistent evidence of credential theft, ransomware deployment, and social‑engineering tactics tied to Altoufan Team, details such as the full spectrum of tools, exact attribution links, operational tempo over time, and direct impact metrics remain incomplete. Additional intelligence—particularly from OSINT monitoring of attacker infrastructure and deeper forensic analysis of compromised systems—would enhance confidence.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. blog.checkpoint.com — Cited by web research for: Emennet Pasargad
  2. www.rescana.com — Cited by web research for: T1566.001
  3. www.safebreach.com — Cited by web research for: T1566
  4. https://malpedia.caad.fkie.fraunhofer.de/details/win.brute_ratel_c4 — Cited by AI analysis.
  5. https://malpedia.caad.fkie.fraunhofer.de/details/win.redline_stealer — Cited by AI analysis.

Intel Summary

16

Techniques

46

Tools

0

Campaigns

6

IOCs

0

Observed Data

8

Tactics

Tags

Data Exfiltration
Government Targeting
Hacktivism
Politically Motivated
Middle East
Bahrain
Israel
Altoufan Team
Cotton Sandstorm
IRGC-affiliated
High-trust impersonation
Credential stealer
WezRat
WhiteLock
Ransomware
Supply-chain foothold
Hack-and-leak
Fake-ransomware
Disinformation
Spearphishing
Webshell
VPN obfuscation
Starlink IP range

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
Iran (IR)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.