Cotton Sandstorm is an Iranian state-linked cyber threat actor associated with Iran’s Islamic Revolutionary Guard Corps Cyber-Electronic Command (IRGC-CEC). It is widely known as Emennet Pasargad and has also been tracked as Haywire Kitten, NEPTUNIUM, MarnanBridge, Shahid Shushtari, Aria Sepehr Ayandehsazan, Ayandeh Sazan Sepehr Arya, Eeleyanet Gostar, Net Peygard Samavat Company, Anzu Team, Holy Souls, and UNC5866. Active since at least 2018, the group conducts cyber-enabled influence, hack-and-leak, phishing, malware-delivery, reconnaissance, and intrusion operations, often using false-flag or hacktivist personas including Altoufan Team and Vice Leaker. The actor interfered in the 2020 U.S. presidential election by obtaining voter information and sending threatening messages while impersonating far-right extremists. It has also conducted operations against Israeli targets and targeted organizations in France and Sweden, including theft of Charlie Hebdo subscriber data, compromise of a Swedish SMS service, and propaganda displayed through hijacked advertising billboards during the Paris 2024 Olympics. Cotton Sandstorm has used the modular WezRat information stealer and, in intrusions against Israeli targets, has deployed WhiteLock ransomware. Its reported victimology includes government, financial services, health care, information technology, news, shipping, travel, energy, and telecommunications organizations across the United States, Europe, Israel, and the Middle East.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
17 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Iranian group accused of conducting cyberattacks against U.S. organizations.
Threat actor engaged in pre-positioning activity before the strikes, deploying WezRat and WhiteLock.
Identified as one of several Iranian threat groups showing elevated activity around the period following the U.S.-Israel strikes.
Actor using malware and persona-driven hack-and-leak amplification operations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.