Cotton Sandstorm is an Iranian state-aligned threat actor associated with Emennet Pasargad and assessed to operate on behalf of, or in close affiliation with, the Islamic Revolutionary Guard Corps Cyber-Electronic Command (IRGC-CEC). The cluster is also tracked under aliases including Haywire Kitten, Marnanbridge, Neptunium, Shahid Shushtari, Aria Sepehr Ayandehsazan, Ayandeh Sazan Sepehr Arya, Eeleyanet Gostar, Net Peygard Samavat Company, Vice Leaker, and Emennet Pasargad. It has conducted cyber-enabled influence operations, hack-and-leak activity, targeted intrusions, and disruptive campaigns across the Middle East, Europe, and the United States. The actor is widely known for interference activity targeting the 2020 U.S. presidential election, including theft of voter-related data, threatening messaging under false-flag personas, and broader influence amplification intended to intimidate voters and shape perceptions. It has also been linked to operations against Israel, France, Sweden, and Bahrain, including website compromises and defacements, propaganda amplification, compromise of a French display provider during the Paris Olympics period, theft of Charlie Hebdo subscriber data, and compromise of a Swedish SMS service used for coercive messaging. Operationally, Cotton Sandstorm blends reconnaissance, phishing, malware delivery, data theft, and information operations. Reported tradecraft includes broad reconnaissance and targeted intrusion activity, spearphishing, deployment of the modular WezRat information stealer, and use of WhiteLock ransomware in operations against Israeli targets. In multiple cases, WezRat was reportedly pre-positioned before subsequent disruptive or leak-oriented activity. The group has also operated under personas such as Altoufan Team to claim intrusions and amplify psychological and political impact. Targeting has included government and public-sector entities, news and media, shipping and travel, energy, financial services, telecommunications, healthcare, and technology organizations. The actor’s behavior is consistent with Iranian cyber operations that combine limited but real network access with exaggerated public claims, persona-driven messaging, and coordinated influence narratives. Its dominant role is best characterized as an Iranian intrusion-and-influence actor supporting state objectives, especially espionage and influence operations aligned with Tehran’s geopolitical interests.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
17 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Threat actor engaged in pre-positioning activity before the strikes, deploying WezRat and WhiteLock.
Identified as one of several Iranian threat groups showing elevated activity around the period following the U.S.-Israel strikes.
Actor using malware and persona-driven hack-and-leak amplification operations.
Conducted destabilization and data theft operations, including attacks against Charlie Hebdo subscribers, compromise of digital billboards to spread disinformation during the Paris 2024 Olympics, and infiltration of an SMS service in Sweden affecting thousands of citizens.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.