The Sands Casino threat actor—attributed by U.S. authorities to Iran—has carried out multiple large‑scale disruptions against both private sector targets in the gambling industry and U.S. governmental entities. The 2014 attack on Las Vegas Sands Corp. involved a crude brute‑force password assault that led to credential theft of a systems engineer, followed by malware planting and data wiping that destroyed three‑quarters of the company’s servers, costing roughly $40 million. Earlier incidents between 2011–2013 targeted U.S. financial websites, while later campaigns in 2020–2021 saw the group deface sites following the death of Iranian commander Qasem Soleimani and issue death threats against U.S. election officials. These operations showcase a pattern of escalating political provocations coupled with operational sabotage aimed at high‑profile public awareness. TTP evidence indicates usage of open‑source frameworks such as Empire for post‑exploitation, Dark, Chaos, and Global tools—likely custom or heavily modified malware—to maintain persistence and exfiltrate data. The attackers appear to rely on low‑complexity password cracking before escalating privileges locally, then expanding lateral movement across corporate networks. While the toolset is not fully catalogued, the presence of domain registration activity (e.g., Casino.org, ForeignAffairs.com) suggests a use of fast‑flux or bullet‑proof hosting to conceal command and control channels. Across its campaigns, Sands Casino has employed both destructive and informational objectives: immediate system outages, long‑term data deletion, and political messaging. These actions reinforce Iran’s broader cyber strategy of using asymmetric attacks against U.S. interests to assert geopolitical influence.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Sands Casino (Iranian‑sponsored) conducted a series of destructive cyber operations against the Las Vegas Sands Corporation and other U.S. targets from 2011 through 2024, primarily using brute‑force credential attacks, malware deployment, and denial‑of‑service tactics to disrupt critical gaming infrastructure. The group’s activities demonstrate a consistent focus on high‑visibility sectors such as gaming and government, with a clear intent to cripple operations and draw political attention.
Goals & Targeting
The group selects targets that provide maximum visibility and political leverage—specifically the U.S. gambling sector, which is heavily publicized and lucrative, and governmental institutions whose disruption carries strategic messaging value. By attacking gaming entities like Las Vegas Sands Corp., they expose institutional vulnerabilities, while attacks on financial websites or election officials serve to amplify Iran’s diplomatic narratives. Their primary aim appears to be disruptive sabotage rather than espionage or data exfiltration, using high‑impact methods such as data destruction and denial of service, thereby creating operational chaos and drawing international attention.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Sands Casino’s operations exhibit an annual–to‑biennial cadence, with notable strikes in 2014 (Gaming), 2020–21 (Political), and earlier financial site disruptions. Victim profiles focus on high‑traffic, publicly visible entities within the U.S., especially those linked to national security or international economics. Operationally, the group favors relatively simple attack vectors—password brute force—and escalates via malware to achieve system-level impact. The use of foreign domain indicators suggests a concerted effort to obfuscate C2 channels and evade attribution while enabling quick reconstitution after takedowns.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The information is derived from publicly reported incident summaries and secondary sources. While the attack dates, victims, and general tactics are corroborated, specific evidence linking the cited tools (Empire, Dark, Chaos, Global) to these operations remains unverified in open‑source feeds, leading to a moderate confidence level. Additionally, precise MITRE ATT&CK mapping for certain techniques (e.g., network DoS ID) is inferred based on logical alignment rather than documented confirmation, indicating gaps that warrant further investigation.
No campaigns linked yet.
No observed data linked yet.
11
Techniques
5
Tools
0
Campaigns
2
IOCs
0
Observed Data
1
Tactics