Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Gray Sandstorm

Also known as: DEV-0343

Description

Gray Sandstorm is an Iran-linked threat actor that has been active since at least 2012. They have targeted defense technology companies, maritime transportation companies, and Persian Gulf ports of entry. Their primary method of attack is password spraying, and they have been observed using tools like o365spray. They have a specific focus on US and Israeli targets and are likely operating in support of Iranian interests.

AI Analysis

· 1 week ago

Executive Summary

Gray Sandstorm, also known as DEV-0343, is an Iran-linked cyber threat actor group observed since at least 2012. They primarily target defense technology companies, maritime transportation firms, and Persian Gulf ports in the U.S. and Israel. Their main tactic involves password spraying, often utilizing tools like o365spray, to compromise systems for potential espionage or disruption activities.

Goals & Targeting

Gray Sandstorm appears to target specific sectors that align with Iran's geopolitical interests, such as defense technology and maritime infrastructure in the U.S. and Israel. Their focus on these regions suggests a strategic goal to weaken adversaries' capabilities or gather intelligence that could benefit Iranian interests. The group's targeting of corporate and critical infrastructure sectors indicates a long-term operational strategy aimed at destabilizing adversaries' economic and military capacities.

Enhanced Description

Gray Sandstorm is an Iranian state-sponsored threat group with a focus on targeting strategic sectors such as defense technology, maritime transportation, and critical infrastructure in the Persian Gulf region. Their primary modus operandi involves credential theft through password spraying attacks, which they execute using tools like o365spray. This tactic suggests a focus on compromising user credentials to access sensitive systems. While their exact motivations remain unclear, their targeting of U.S. and Israeli entities strongly implies alignment with Iranian strategic interests. Gray Sandstorm's operations demonstrate a level of technical proficiency suitable for state-sponsored cyber espionage or sabotage.

Key Capabilities

  • Password spraying attacks
  • Use of tools like o365spray for credential access
  • Potential use of additional espionage or lateral movement tools

MITRE ATT&CK Tactics

Espionage
Initial Access
Credential Access

ATT&CK Techniques

T1097 - Valid Accounts
T1078 -Credential Access
T1082 -System Information Discovery
T1576 - Exfiltration Over Alternative Protocol

Software / Tooling

o365spray
Mimikatz
PsInject
Custom credential-dumping tools

Campaigns & Victims

Gray Sandstorm's campaigns have consistently targeted defense and maritime sectors in the U.S. and Israel, suggesting a sustained focus on critical infrastructure. Their operational tempo appears methodical, with a preference for password spraying as an initial access vector. No specific high-profile campaigns have been publicly identified, but their activity indicates a long-term, persistent threat to these regions.

IOC Patterns

  • Password spray attempts across O365 accounts
  • Use of o365spray tool in phishing emails or scripts
  • Credential dumping activities post-compromise
  • Exfiltration via unexpected protocols

Recommended Actions

  • Implement multi-factor authentication (MFA) for O365 and other critical systems.
  • Monitor for and block suspicious brute-force attempts on RDP and email services.
  • Conduct regular credential audits to identify weak or reused passwords.
  • Deploy network traffic analysis tools to detect anomalies indicative of Gray Sandstorm's TTPs.

Suggested Tags

APT
State-sponsored
Cyber Espionage
Maritime Sector
Defense Sector

Confidence Assessment

The confidence level in the details about Gray Sandstorm is moderate. While their primary methods and targeting patterns are known, specifics about their full capabilities, long-term goals, and potential connections to other Iranian threat groups remain unclear. Additional open-source intelligence (OSINT) and analysis would help validate these findings.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
State-sponsored
Cyber Espionage
Maritime Sector
Defense Sector

Details

Type
Unknown
Country of Origin
I
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.