Cotton Sandstorm is an Iranian nation-state actor known for cyber espionage and hack-and-leak operations targeting government, finance, and energy sectors.
Analyst brief
Cotton Sandstorm is an Iranian nation-state threat actor known for conducting cyber espionage and hack-and-leak operations. They primarily target government, finance, high-tech, energy, and NGO sectors across the United States, Israel, Europe, and the Middle East. Their main TTPs involve data exfiltration followed by public leakage, as demonstrated by the breach of Charlie Hebdo where they leaked over 200,000 customer records. Defenders should prioritize monitoring for outbound data flows, identify assets at risk of public exposure, and heighten awareness against phishing and social engineering attempts, especially in targeted sectors.
Cotton Sandstorm
Emennet PasargadHoly SoulsMARNANBRIDGE
nation-state
Cotton Sandstorm is an Iranian threat actor involved in hack-and-leak operations. They have targeted various organizations, including the French satirical magazine Charlie Hebdo, where they obtained and leaked personal information of over 200,000 customers. The group has been linked to the Iranian government and has been sanctioned by the US Treasury
origin (suspected)
🇮🇷Iran· state-sponsoredattribution confidence: medium (50)