Gray Sandstorm is an Iran-linked threat actor active since 2012, targeting defense and maritime sectors.
Analyst brief
Gray Sandstorm (also tracked as DEV-0343) is an Iran-linked threat actor active since at least 2012. They primarily target US and Israeli defense technology firms, maritime transportation companies, and Persian Gulf ports of entry. Their main TTP is password spraying, utilizing tools like o365spray to gain initial access. Defenders should prioritize enforcing strong authentication policies, especially multi-factor authentication, and closely monitor for anomalous login attempts.
Gray Sandstorm
DEV-0343
unknown
Gray Sandstorm is an Iran-linked threat actor that has been active since at least 2012. They have targeted defense technology companies, maritime transportation companies, and Persian Gulf ports of entry. Their primary method of attack is password spraying, and they have been observed using tools like o365spray. They have a specific focus on US and Israeli targets and are likely operating in support of Iranian interests.