Cotton Sandstorm — APT Profile

Cotton Sandstorm is an IRGC-linked Iranian APT tracked by Microsoft as NEPTUNIUM, conducting cyber-enabled influence operations and destructive attacks primarily targeting Israeli and US entities. The group deploys the WezRat infostealer for credential harvesting and uses WhiteLock ransomware as a disruptive cover for espionage objectives. Cotton Sandstorm has been linked to the reactivation of the Altoufan Team hacktivist persona and has targeted media organizations, government portals, and maritime sectors. Their operations blend data theft, hack-and-leak tactics, and psychological operations to amplify geopolitical narratives.

Also tracked as

NEPTUNIUM, DEV-0198, Vice Leaker, Emennet Pasargad, Aria Sepehr Ayandehsazan, ASA, Marnanbridge, Haywire Kitten, Holy Souls, Eeleyanet Gostar

Tools & malware

Vendor research

Countries linked to this actor

Read the full analysis on IntelFusions