Cotton Sandstorm — APT Profile
Cotton Sandstorm is an IRGC-linked Iranian APT tracked by Microsoft as NEPTUNIUM, conducting cyber-enabled influence operations and destructive attacks primarily targeting Israeli and US entities. The group deploys the WezRat infostealer for credential harvesting and uses WhiteLock ransomware as a disruptive cover for espionage objectives. Cotton Sandstorm has been linked to the reactivation of the Altoufan Team hacktivist persona and has targeted media organizations, government portals, and maritime sectors. Their operations blend data theft, hack-and-leak tactics, and psychological operations to amplify geopolitical narratives.Also tracked as
NEPTUNIUM, DEV-0198, Vice Leaker, Emennet Pasargad, Aria Sepehr Ayandehsazan, ASA, Marnanbridge, Haywire Kitten, Holy Souls, Eeleyanet Gostar
Tools & malware
- Acunetix Tool
- bd (bd.exe) RAT
- Burp Suite Tool
- CVE-2023-38831 (WinRAR) exploit Exploit
- Google Chrome Installer.msi (trojanized installer) Loader
- Masscan Tool
- Shodan Tool
- SQLMap Tool
Vendor research
- New Tradecraft of Iranian Cyber Group Aria Sepehr Ayandehsazan aka Emennet Pasargad (JCSA-20241030-001) FBI / U.S. Department of Treasury / Israel National Cyber Directorate
- Iran surges cyber-enabled influence operations in support of Hamas Microsoft
- Iran responsible for Charlie Hebdo attacks Microsoft
- Cotton Sandstorm (Threat Actor) Malpedia (Fraunhofer FKIE)