🇮🇷

Cotton Sandstorm

APT Group

Also Known As 5 names

Emennet Pasargad HAYWIRE KITTEN Holy Souls MARNANBRIDGE NEPTUNIUM

Target Countries 18

Countries highlighted in red

United Arab Emirates Albania Bahrain Canada China France United Kingdom Indonesia Israel India Islamic Republic of Iran Lebanon Malaysia Saudi Arabia Sweden Turkey Ukraine United States

Sectors Targeted

Public Administration 92 Water Transportation 483 Sports Healthcare Military Religious, Grantmaking, Civic, Professional, and Similar Organizations 813 Commercial Banking 52211 Accommodation 721 Aerospace and Defense Dating Website Defence Computer and Electronic Product Manufacturing 334 military Software Publishers 5112 Finance Oil and Gas Extraction 211 government Technology financial NAICS:44 44 Financial Institutions Defense Utilities 22 Electronic Shopping and Mail-Order Houses 4541 Media Critical Infrastructure defense Space Research and Technology 927 Consumer Services NAICS:31 31 Data Processing, Hosting, and Related Services 51821 Think Tanks Human Rights Organizations 813311 Publishing Industries (except Internet) 511 Cryptocurrency Finance and Insurance 52 Professional, Scientific, and Technical Services 54 National Security and International Affairs 928110 Multiple sectors including shipping and logistics Telecommunications Computer Systems Design and Related Services 5415 Internet Publishing and Broadcasting and Web Search Portals 51913 Aerospace Government Electrical Equipment, Appliance, and Component Manufacturing 335 Computer Systems Design Services 541512 NAICS:48 48 Civil Society Energy Think tanks Other Services (except Public Administration) 81 Telecommunications 517 National Security and International Affairs 928 Data Processing, Hosting, and Related Services 518 Rail Information Technology aerospace Insurance Carriers and Related Activities 524 Government agencies Arts, Entertainment, and Recreation 71 healthcare High-Tech Air Transportation 481 Health Care and Social Assistance 62 IT Telecoms Other Information Services 519 Financial Information 51 Commodity Contracts Intermediation 523160 Monetary Authorities-Central Bank 521 NGOs Financial Services Justice, Public Order, and Safety Activities 922

Details

Origin 🇮🇷 IR
Last Updated 27 Jan 2024

MITRE ATT&CK 33

T1012 - Query Registry T1016 - System Network Configuration Discovery T1027 - Obfuscated Files or Information T1027.004 - Compile After Delivery T1033 - System Owner/User Discovery T1047 T1056.001 - Keylogging T1057 - Process Discovery T1059 - Command and Scripting Interpreter T1059.003 T1071.001 - Web Protocols T1082 - System Information Discovery T1083 - File and Directory Discovery T1105 - Ingress Tool Transfer T1113 - Screen Capture T1115 - Clipboard Data T1132.001 - Standard Encoding T1190 T1547.001 - Registry Run Keys / Startup Folder T1552.001 - Credentials In Files T1555.003 - Credentials from Web Browsers T1566.001 T1573.001 - Symmetric Cryptography T1583 - Acquire Infrastructure T1584 - Compromise Infrastructure T1585 - Establish Accounts T1586 - Compromise Accounts T1588 - Obtain Capabilities T1592 - Gather Victim Host Information T1596 - Search Open Technical Databases T1608 - Stage Capabilities T1610 - Deploy Container T1612 - Build Image on Host

Related Zero-Days

No zero-day CVE linked to this actor