Home/Threat Actor/Cotton Sandstorm
Threat Actor

Cotton Sandstorm

cotton_sandstorm · iran · active since 2017-01

Cotton Sandstorm (Microsoft canonical.

formerly NEPTUNIUM) is an Iran-affiliated cyber espionage and cyber-enabled influence operations cluster operating under the Iranian government contractor entity Emennet Pasargad (FBI-indicted November 2021, OFAC-sanctioned) and its successor entity Aria Sepehr Ayandehsazan (OFAC-sanctioned September 2024); assessed with high confidence to be IRGC-EC affiliated; signature operational mission is cyber-enabled influence operations integrating technical cyber intrusion (credential phishing, web-application exploitation, voter database access) with sock-puppet persona infrastructure, fake media outlets, synthetic media, and hack-and-leak publication operations.

tracked operational history spans 2020 US election interference (Proud Boys impersonation voter intimidation, "Enemies of the People" hack-and-leak), 2022-2024 Albania-targeting operations (Homeland Justice persona, anti-MEK messaging), and post-October 2023 Israel- targeting cyber-enabled influence operations supporting the Iranian government strategic information-operations objectives in the Israel-Hamas conflict context.

operationally distinct from all other Iranian clusters curated separately in this corpus (Agrius, APT34, APT35, APT39, MuddyWater, Pioneer Kitten, Imperial Kitten, Scarred Manticore / UNC1860, CyberAv3ngers, Predatory Sparrow).

iran confidence: high 15 aliases

Profile

Cotton Sandstorm (Microsoft canonical designation, Sandstorm taxonomy assigned to Iranian clusters in Microsoft's 2023 naming framework.

previously tracked as NEPTUNIUM under Microsoft's legacy framework) is an Iran-affiliated cyber espionage and cyber-enabled influence operations cluster that operates under the Iranian government contractor entity Emennet Pasargad (FBI-indicted November 2021, OFAC-sanctioned November 2021) and its successor entity Aria Sepehr Ayandehsazan (OFAC-sanctioned September 2024). The cluster is uniquely well-documented in the public record among Iranian-aligned clusters because of the formal FBI indictment and OFAC sanctions disclosing operational entity, named operators, and operational tradecraft. The cluster's signature operational mission is cyber-enabled influence operations, a combined operational model that integrates technical cyber intrusion (credential phishing, web-application exploitation, voter registration database access) with social-media-mediated influence operations using cluster-controlled sock-puppet personas, fake media outlets, synthetic media production, and hack-and-leak publication infrastructure. The cyber-enabled influence operational model is operationally distinct from pure espionage clusters (which collect intelligence for state consumption) and from pure destructive clusters (which destroy victim data), Cotton Sandstorm operates by stealing intelligence AND publishing curated portions of stolen data through sock-puppet infrastructure designed to advance Iranian government strategic information-operations objectives. The cluster's tracked operational history spans three operationally-distinct phases: (1) 2020 US ELECTION INTERFERENCE (PRIMARY HISTORICAL OPERATIONS). In October-November 2020, Cotton Sandstorm (then-Emennet Pasargad) conducted multi-pronged cyber-enabled influence operations designed to interfere in the US presidential election. Operations included voter registration database access in multiple US states, Proud Boys impersonation voter intimidation emails sent to thousands of Democratic voters with threats and demands to vote for Donald Trump (October 20, 2020, late-stage election interference), production and dissemination of a video purporting to show US election hacking, and hack-and-leak publication of stolen voter registration data via "Enemies of the People" sock- puppet personas. The FBI / DNI public attribution to Iran on October 21, 2020 was an unusual pre-election public attribution.

the November 2021 FBI indictment named the operators as Emennet Pasargad contractors. (2) ALBANIA OPERATIONS PERIOD (2022-2024). From July 2022, severe cyber attacks against Albanian government IT infrastructure, claimed by the "Homeland Justice" sock- puppet persona with anti-MEK messaging, demonstrated the cluster's destructive-cyber-operations capability alongside its influence-operations tradecraft. Microsoft and US government attribution linked Homeland Justice to broader Iranian operations including Cotton Sandstorm operational tradecraft elements, though some analytical uncertainty exists regarding whether Homeland Justice is a Cotton Sandstorm sub-operation or a related-but-distinct cluster. Albania attacks continued through 2023-2024 with periodic operational tempo correlating with MEK-related geopolitical events. (3) POST-OCTOBER 2023 ISRAEL-TARGETING CYBER-ENABLED INFLUENCE OPERATIONS (CURRENT PRIMARY OPERATIONS). Following the October 7, 2023 Hamas attack on Israel, Cotton Sandstorm's operational tempo and targeting profile shifted dramatically toward Israel-targeting cyber-enabled influence operations. Sock-puppet personas mimicking Israeli activists, journalists, and victims.

hack-and-leak operations targeting Israeli critical infrastructure and government organizations.

synthetic- media impersonation of Israeli government and military spokespersons.

coordinated influence operations targeting Israeli diaspora communities.

and additional destructive- cyber-operations against Israeli targets via personas including "Alharbi the Storm of Jerusalem." Microsoft's August 2024 Threat Analysis Center report (Iran Surges Cyber-Enabled Influence Operations in Support of Hamas) documented the operational tempo increase as a significant scaling of the cluster's resourcing reflecting Iranian government strategic priorities in the Israel-Hamas conflict context. The cluster's operational toolkit emphasizes sock-puppet persona infrastructure, fake media outlets, and hack-and-leak publication infrastructure, operationally distinguishing Cotton Sandstorm from technical-espionage-focused Iranian clusters (APT34, APT35, MuddyWater) and from destructive- focused clusters (Agrius). Conventional intrusion tooling (credential phishing, webshell variants, mimikatz, publicly- available pen-testing tools) is used for the technical access phase of operations but the operational distinctiveness lies in the cyber-enabled-influence integration rather than the technical sophistication of the intrusion phase. Cotton Sandstorm is operationally distinct from all other Iranian clusters in this corpus, including the destructive Agrius (agrius.yaml), the espionage-focused APT34 (apt34_oilrig.yaml), APT35 (apt35_charmingkitten.yaml), APT39 (apt39_chafer.yaml), MuddyWater (muddywater.yaml), the initial-access-focused Pioneer Kitten (pioneer_kitten_fox_kitten.yaml) and Imperial Kitten (imperial_kitten_tortoiseshell.yaml), the passive-backdoor-focused Scarred Manticore / UNC1860 (scarred_manticore_unc1860.yaml), the OT-targeting CyberAv3ngers (cyberav3ngers.yaml), and the GHOSTBYTE / sabotage-adjacent Predatory Sparrow (predatory_sparrow.yaml). The cluster fills the cyber-enabled-influence-operations cell in this curated Iranian-cluster coverage and provides analytically-distinct coverage of the IRGC-EC affiliated influence-operations sub- ecosystem.

Aliases

15
cotton_sandstormcotton sandstormneptuniumemennet_pasargademennet pasargademennet pasargad companyiran cyber newsiran cyber news agencyhometown heroesanzu teamalharbi the storm of jerusalemaria_sepehr_ayandehsazanaria sepehr ayandehsazan (asa)iran-irgc-ec-affiliated-influence-clustercottonsandstorm

Notable Campaigns

5
2024OFAC Sanctions Against Aria Sepehr Ayandehsazan (ASA), Cluster Operational Successor Entity (September 2024)
2023-2025Post-October 2023 Israel-Targeting Cyber-Enabled Influence Operations (October 2023 onwards)
2022-2024Albania Government Cyber Attacks, Homeland Justice Operations Adjacent-Cluster Context (July 2022 onwards)
2021OFAC Sanctions Against Emennet Pasargad and Affiliated Individuals (November 18, 2021)
2020Emennet Pasargad 2020 US Presidential Election Interference (October-November 2020)

Attribution & Reporting

Attributed by
Microsoft Threat Intelligence (MSTIC)FBI (Federal Bureau of Investigation)US Department of the Treasury OFACUS Department of Justice (Southern District of New York indictment)CISA (US Cybersecurity and Infrastructure Security Agency)Mandiant (Google Threat Intelligence)CrowdStrikeRecorded Future Insikt GroupSentinelOneReuters investigative reportingIsraeli National Cyber Directorate (INCD)Albanian government / CERT-ALCitizen Lab (University of Toronto Munk School)Graphika (social-media-influence-analysis specialist firm)DFRLab (Atlantic Council Digital Forensic Research Lab)
Key reporting
reportFBI / DOJ: Two Iranian Nationals Charged with Cyber-Enabled Disinformation and Threat Campaign (November 18, 2021), canonical attribution
reportUS Department of Treasury OFAC: Treasury Sanctions Iranian Cyber Actors for Attempting to Influence the 2020 US Presidential Election (November 18, 2021)
reportUS Department of Treasury OFAC: Iran Election Interference Sanctions Update (September 27, 2024), ASA entity designation
reportMicrosoft Threat Analysis Center: Iran Surges Cyber-Enabled Influence Operations in Support of Hamas (August 2024)
reportMicrosoft Threat Intelligence: Iranian Cyber Actor Targets Albania (September 2022)
reportFBI / CISA / DHS: Joint Cybersecurity Advisory on Iranian Government-Sponsored APT Actors (AA22-257A)
reportCrowdStrike: Iran-Affiliated Influence Operations Tracking
reportRecorded Future Insikt Group: Iran Election Interference Operational Analysis
reportGraphika: Iran-Aligned Influence Operations Network Analysis
reportMalpedia Actor Profile: Cotton Sandstorm / Emennet Pasargad

Operational

State sponsor

Iran-affiliated cyber espionage and influence operations cluster assessed by Microsoft Threat Intelligence (canonical Cotton Sandstorm designation, Sandstorm taxonomy assigned to Iranian clusters in Microsoft's 2023 naming framework; previously tracked as NEPTUNIUM) with high confidence as operating under the Iranian Islamic Revolutionary Guard Corps Electronic Command (IRGC-EC) or affiliated IRGC organizational structures. The Iranian state-affiliation assessment is uniquely well-supported in the public record because the FBI indicted (October 20, 2021) two Iranian nationals, Seyyed Mohammad Hosein Musa Kazemi and Sajjad Kashian, operating out of the Iranian government contractor company Emennet Pasargad for conducting cyber-enabled influence operations designed to interfere in the 2020 US presidential election. The US Department of the Treasury's Office of Foreign Assets Control (OFAC) subsequently sanctioned Emennet Pasargad and affiliated individuals.

The IRGC-EC affiliation is further assessed based on the cluster's targeting profile (US election interference, Israeli targeting accelerating post-October 2023, Albanian government targeting in coordination with adjacent Iranian clusters), operational pattern (cyber-enabled influence operations combining hack- and-leak operations with social-media-mediated influence campaigns using sock-puppet personas), and longitudinal tracking of the cluster's infrastructure and operational personas across multiple years. Subsequent OFAC actions (September 2024) sanctioned additional entities including "Aria Sepehr Ayandehsazan (ASA)", the cluster's reorganized operational entity following the 2021 indictment. The cluster is operationally distinct from APT34 / OilRig (apt34_oilrig.yaml, MOIS espionage), APT35 / Charming Kitten (apt35_charmingkitten.yaml, IRGC-IO espionage), APT39 / Chafer (apt39_chafer.yaml, MOIS surveillance), MuddyWater (muddywater.yaml, MOIS espionage), Agrius (agrius.yaml, destructive operations), Pioneer Kitten / Fox Kitten (pioneer_kitten_fox_kitten.yaml), Imperial Kitten / Tortoiseshell (imperial_kitten_tortoiseshell.yaml), and Scarred Manticore / UNC1860 (scarred_manticore_unc1860.yaml), all curated separately, while operating within the broader Iranian state-affiliated cyber-operations ecosystem.

Motivations
cyber_enabled_influence_operations, election_interference, hack_and_leak_operations, voter_intimidation_and_disinformation, israeli_targeting_post_october_2023, iranian_strategic_information_operations, hacktivist_persona_driven_psychological_operations
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)54/60 · 90%
Analytics (MITRE CAR)25/60 · 41%
Runtime / container (Falco)13/60 · 21%
File / malware (YARA)1/60 · 1%
Network (Suricata/Snort)18/60 · 30%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

1 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
SOCK PUPPET PERSONA INFRASTRUCTURE

CVEs Exploited

3
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin