Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Sands Casino

Description

The Sands Casino threat actor—attributed by U.S. authorities to Iran—has carried out multiple large‑scale disruptions against both private sector targets in the gambling industry and U.S. governmental entities. The 2014 attack on Las Vegas Sands Corp. involved a crude brute‑force password assault that led to credential theft of a systems engineer, followed by malware planting and data wiping that destroyed three‑quarters of the company’s servers, costing roughly $40 million. Earlier incidents between 2011–2013 targeted U.S. financial websites, while later campaigns in 2020–2021 saw the group deface sites following the death of Iranian commander Qasem Soleimani and issue death threats against U.S. election officials. These operations showcase a pattern of escalating political provocations coupled with operational sabotage aimed at high‑profile public awareness. TTP evidence indicates usage of open‑source frameworks such as Empire for post‑exploitation, Dark, Chaos, and Global tools—likely custom or heavily modified malware—to maintain persistence and exfiltrate data. The attackers appear to rely on low‑complexity password cracking before escalating privileges locally, then expanding lateral movement across corporate networks. While the toolset is not fully catalogued, the presence of domain registration activity (e.g., Casino.org, ForeignAffairs.com) suggests a use of fast‑flux or bullet‑proof hosting to conceal command and control channels. Across its campaigns, Sands Casino has employed both destructive and informational objectives: immediate system outages, long‑term data deletion, and political messaging. These actions reinforce Iran’s broader cyber strategy of using asymmetric attacks against U.S. interests to assert geopolitical influence.

Goals & Targeting

Targeted Sectors

Gaming
Government

Targeted Countries / Regions

IR

AI Analysis

Grounded in web research
· 4 days ago

Executive Summary

Sands Casino (Iranian‑sponsored) conducted a series of destructive cyber operations against the Las Vegas Sands Corporation and other U.S. targets from 2011 through 2024, primarily using brute‑force credential attacks, malware deployment, and denial‑of‑service tactics to disrupt critical gaming infrastructure. The group’s activities demonstrate a consistent focus on high‑visibility sectors such as gaming and government, with a clear intent to cripple operations and draw political attention.

Goals & Targeting

The group selects targets that provide maximum visibility and political leverage—specifically the U.S. gambling sector, which is heavily publicized and lucrative, and governmental institutions whose disruption carries strategic messaging value. By attacking gaming entities like Las Vegas Sands Corp., they expose institutional vulnerabilities, while attacks on financial websites or election officials serve to amplify Iran’s diplomatic narratives. Their primary aim appears to be disruptive sabotage rather than espionage or data exfiltration, using high‑impact methods such as data destruction and denial of service, thereby creating operational chaos and drawing international attention.

Enhanced Description

Key Capabilities

  • Password cracking via brute force
  • Credential theft and lateral movement with custom malware
  • Data wiping and server destruction
  • Distributed denial‑of‑service assaults
  • Use of open‑source post‑exploitation frameworks (Empire)
  • Domain-based C2 infrastructure (fast‑flux, bullet‑proof hosting)

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Command & Control
Exfiltration
Impact

ATT&CK Techniques

T1110.001 Password Guessing
T1110.003 Password Spraying
T1059.001 PowerShell
T1078.002 Valid Accounts: Local Account
T1075 Remote Services
T1053.006 Scheduled Task/Job
T1086 Windows Command Shell
T1105 Ingress Tool Transfer
T1212 Data Staged
T1485 Data Destruction
T1498 Network Denial of Service

Software / Tooling

Empire
Dark
Chaos
Global
Custom RAT

Campaigns & Victims

Sands Casino’s operations exhibit an annual–to‑biennial cadence, with notable strikes in 2014 (Gaming), 2020–21 (Political), and earlier financial site disruptions. Victim profiles focus on high‑traffic, publicly visible entities within the U.S., especially those linked to national security or international economics. Operationally, the group favors relatively simple attack vectors—password brute force—and escalates via malware to achieve system-level impact. The use of foreign domain indicators suggests a concerted effort to obfuscate C2 channels and evade attribution while enabling quick reconstitution after takedowns.

IOC Patterns

  • Domain registration linked to ‘casino.org’ or ‘foreignaffairs.com’, commonly used for command and control
  • Brute‑force password attempts targeting corporate SMB shares
  • Data wiping of server drives with overwriting scripts
  • Denial‑of‑service traffic spikes aimed at corporate networks
  • Malware dropping via compromised Windows services

Recommended Actions

  • Implement multi‑factor authentication on all privileged accounts to thwart credential guessing
  • Deploy advanced endpoint detection platforms capable of detecting malicious PowerShell activity and orphaned processes
  • Regularly patch and harden server infrastructure, especially unpatched Windows machines
  • Conduct periodic penetration tests against password policy enforcement and lateral movement pathways
  • Monitor for sudden spikes in network traffic that may indicate Denial‑of‑service attempts, and configure rate limiting on critical services
  • Ensure comprehensive backup strategies with offline restoration procedures to mitigate data destruction

Suggested Tags

APT
Disruption
Gaming industry attacks
Government targeting
Iranian state-sponsored
Denial of Service
Data Destruction

Confidence Assessment

The information is derived from publicly reported incident summaries and secondary sources. While the attack dates, victims, and general tactics are corroborated, specific evidence linking the cited tools (Empire, Dark, Chaos, Global) to these operations remains unverified in open‑source feeds, leading to a moderate confidence level. Additionally, precise MITRE ATT&CK mapping for certain techniques (e.g., network DoS ID) is inferred based on logical alignment rather than documented confirmation, indicating gaps that warrant further investigation.

Intel Summary

11

Techniques

5

Tools

0

Campaigns

2

IOCs

0

Observed Data

1

Tactics

Tags

Unknown
APT
Destructive
Data destruction
Denial of service
Iranian threat actor
ransomware
espionage
finance-sector
Disruption
Gaming industry attacks
Government targeting
Iranian state-sponsored
Denial of Service
Data Destruction

Details

Type
Unknown
Primary Motivation
Disruption
Country of Origin
I
Confidence
50%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.