WezRat is a custom, purpose-built modular information stealer associated with the Iranian threat actor Emennet Pasargad, also tracked as Cotton Sandstorm and Haywire Kitten. Reporting in the provided content states that the group routinely delivers WezRat via spearphishing campaigns masquerading as urgent software updates, and that it was deployed in intrusions in the months leading up to the February 28, 2026 conflict escalation. Check Point Research is cited as assessing that Cotton Sandstorm pre-positioned WezRat before the strikes, and that the malware was used alongside the Altoufan persona for hack-and-leak amplification. The content further states that WezRat has been followed in some cases by deployment of WhiteLock ransomware, including activity specifically described against Israeli targets. High-confidence context in the source material links WezRat to Iranian influence and intrusion operations targeting Israel and other countries in the Middle East, with Emennet Pasargad also described as conducting operations against the U.S., France, and Sweden. No specific file hashes, domains, or other concrete IOCs for WezRat are provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Cotton Sandstorm deployed WezRat and WhiteLock alongside the Altoufan persona for hack-and-leak amplification.
...‘WhiteLock’ ransomware, deployed after WezRat infostealer.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
“pivoting to exploit zero-day vulnerabilities in industrial time-management software…” and “identify and exploit public-facing applications at scale.”
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote access trojan/backdoor used by Cotton Sandstorm for pre-positioning access ahead of geopolitical escalation.
A RAT deployed by Cotton Sandstorm in support of hack-and-leak operations.
Custom modular infostealer used by an Iranian-linked threat group (Cotton Sandstorm/Haywire Kitten), delivered via spearphishing disguised as urgent software updates.
Modular information stealer with DLL-loaded capabilities including screen capture, keylogging, clipboard theft, and cookie harvesting.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.