Bohrium (Smoke Sandstorm) is an Iranian threat actor known for spear-phishing using fake recruiter profiles.
Analyst brief
Bohrium, also known as Smoke Sandstorm or IMPERIAL KITTEN, is an Iranian threat actor. This group targets organizations primarily in the US, Middle East, and India, with a focus on the technology, transportation, government, and education sectors. Their main TTPs involve spear-phishing operations using fake social media profiles, often posing as recruiters, to trick victims into executing malware. Defenders should focus on social engineering awareness, scrutinize suspicious recruitment messages, and implement threat intelligence updates to block connections to their infrastructure, including the 41 domains seized by Microsoft.
Bohrium
Smoke SandstormBOHRIUMIMPERIAL KITTEN
unknown
Bohrium is an Iranian threat actor that has been involved in spear-phishing operations targeting organizations in the US, Middle East, and India. They often create fake social media profiles, particularly posing as recruiters, to trick victims into running malware on their computers. Microsoft's Digital Crimes Unit has taken legal action and seized 41 domains used by Bohrium to disrupt their activities. The group has shown a particular interest in sectors such as technology, transportation, government, and education.