Sandstorm is a threat actor name associated with cloud-focused intrusion activity. It has been observed leveraging phishing and cloud misconfigurations for initial access, then abusing cloud-native tooling and OAuth application consent flows to steal credentials and tokens, reach highly privileged users, and exfiltrate email and other cloud-hosted data. Reported tradecraft includes credential theft, session or token theft, privilege escalation through delegated application access, persistence in cloud environments, and post-compromise movement between on-premises and cloud resources in hybrid enterprise environments. Sandstorm has been linked to attacks that target organizational cloud services such as email and collaboration platforms, with emphasis on data access and exfiltration rather than ransomware or disruptive operations. High-confidence reporting in the available material supports cloud account compromise, OAuth abuse, and email exfiltration, but does not provide sufficient corroborated detail to attribute a specific nation-state sponsor, origin country, or victim geography.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.