Cotton Sandstorm is an Iranian state-aligned threat actor associated with Iran’s Islamic Revolutionary Guard Corps Cyber-Electronic Command (IRGC-CEC). The cluster is widely linked to the organization and front-company names Emennet Pasargad, Shahid Shushtari, Haywire Kitten, Marnanbridge, Aria Sepehr Ayandehsazan, Ayandeh Sazan Sepehr Arya, Eeleyanet Gostar, and Net Peygard Samavat Company; additional reported personas and labels include Vice Leaker, Altoufan Team, Neptunium, Anzu Team, and Holy Souls. The actor has been active since at least 2018 and is known for combining cyber intrusion activity with hack-and-leak, propaganda, and broader influence operations. The group has conducted operations against Israel, the United States, France, and Sweden, and has also claimed activity in Bahrain. Reported targeting spans government, critical infrastructure, news and media, shipping, travel, energy, financial services, telecommunications, healthcare, and technology. Publicly attributed activity includes interference in the 2020 U.S. presidential election through theft of voter information, threatening messages sent under a false-flag far-right persona, and other cyber-enabled influence measures. The actor has also been tied to the 2023 compromise involving Charlie Hebdo subscriber data, propaganda activity during the 2024 Paris Olympics including hijacked advertising displays, and compromise of a Swedish SMS service used for intimidation messaging. Operationally, Cotton Sandstorm is associated with spearphishing, credential theft, reconnaissance, malware delivery, data exfiltration, and influence amplification. The group has used the modular WezRat information stealer and has been observed pre-positioning access ahead of geopolitical escalation. Reporting also links the actor to deployment of WhiteLock ransomware after WezRat infections, particularly in operations against Israeli targets. The actor routinely blends limited but real intrusions with exaggerated public claims and persona-driven amplification to maximize psychological and political impact. Its tradecraft includes false-flag spoofing, hack-and-leak operations, and coordinated messaging under personas such as Altoufan Team. Cotton Sandstorm is best understood as an Iranian cyber and influence operator that sits at the intersection of espionage, disruption, and information operations. Its campaigns consistently align with Iranian strategic interests, especially retaliatory or coercive activity directed at regional adversaries and Western targets.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
17 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Threat actor engaged in pre-positioning activity before the strikes, deploying WezRat and WhiteLock.
Identified as one of several Iranian threat groups showing elevated activity around the period following the U.S.-Israel strikes.
Actor using malware and persona-driven hack-and-leak amplification operations.
Conducted destabilization and data theft operations, including attacks against Charlie Hebdo subscribers, compromise of digital billboards to spread disinformation during the Paris 2024 Olympics, and infiltration of an SMS service in Sweden affecting thousands of citizens.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.