Cuboid Sandstorm is an Iranian threat actor known for supply chain attacks targeting defense, energy, and legal sectors in Israel.
Analyst brief
Cuboid Sandstorm is an Iranian threat actor, also tracked as DEV-0228. It primarily targets organizations in the defense, energy, and legal sectors in Israel, leveraging supply chain compromises to reach downstream victims. The group uses custom implants, notably a remote access Trojan (RAT) disguised as RuntimeBroker.exe or svchost.exe, to establish persistence. Defenders should focus on monitoring for anomalous process behavior, especially instances of RuntimeBroker.exe or svchost.exe executing from non-standard paths.
Cuboid Sandstorm
DEV-0228
unknown
Cuboid Sandstorm is an Iranian threat actor that targeted an Israel-based IT company in July 2021. They gained access to the company's network and used it to compromise downstream customers in the defense, energy, and legal sectors in Israel. The group also utilized custom implants, including a remote access Trojan disguised as RuntimeBroker.exe or svchost.exe, to establish persistence on victim hosts.