🇮🇷
Cotton Sandstorm
APT Group
Also Known As 5 names
Emennet Pasargad
HAYWIRE KITTEN
Holy Souls
MARNANBRIDGE
NEPTUNIUM
Target Countries 18
Countries highlighted in red
United Arab Emirates
Albania
Bahrain
Canada
China
France
United Kingdom
Indonesia
Israel
India
Islamic Republic of Iran
Lebanon
Malaysia
Saudi Arabia
Sweden
Turkey
Ukraine
United States
Sectors Targeted
Public Administration
92
Water Transportation
483
Sports
Healthcare
Military
Religious, Grantmaking, Civic, Professional, and Similar Organizations
813
Commercial Banking
52211
Accommodation
721
Aerospace and Defense
Dating Website
Defence
Computer and Electronic Product Manufacturing
334
military
Software Publishers
5112
Finance
Oil and Gas Extraction
211
government
Technology
financial
NAICS:44
44
Financial Institutions
Defense
Utilities
22
Electronic Shopping and Mail-Order Houses
4541
Media
Critical Infrastructure
defense
Space Research and Technology
927
Consumer Services
NAICS:31
31
Data Processing, Hosting, and Related Services
51821
Think Tanks
Human Rights Organizations
813311
Publishing Industries (except Internet)
511
Cryptocurrency
Finance and Insurance
52
Professional, Scientific, and Technical Services
54
National Security and International Affairs
928110
Multiple sectors including shipping and logistics
Telecommunications
Computer Systems Design and Related Services
5415
Internet Publishing and Broadcasting and Web Search Portals
51913
Aerospace
Government
Electrical Equipment, Appliance, and Component Manufacturing
335
Computer Systems Design Services
541512
NAICS:48
48
Civil Society
Energy
Think tanks
Other Services (except Public Administration)
81
Telecommunications
517
National Security and International Affairs
928
Data Processing, Hosting, and Related Services
518
Rail
Information Technology
aerospace
Insurance Carriers and Related Activities
524
Government agencies
Arts, Entertainment, and Recreation
71
healthcare
High-Tech
Air Transportation
481
Health Care and Social Assistance
62
IT
Telecoms
Other Information Services
519
Financial
Information
51
Commodity Contracts Intermediation
523160
Monetary Authorities-Central Bank
521
NGOs
Financial Services
Justice, Public Order, and Safety Activities
922
Details
Origin
🇮🇷 IR
Last Updated
27 Jan 2024
MITRE ATT&CK 33
T1012 - Query Registry
T1016 - System Network Configuration Discovery
T1027 - Obfuscated Files or Information
T1027.004 - Compile After Delivery
T1033 - System Owner/User Discovery
T1047
T1056.001 - Keylogging
T1057 - Process Discovery
T1059 - Command and Scripting Interpreter
T1059.003
T1071.001 - Web Protocols
T1082 - System Information Discovery
T1083 - File and Directory Discovery
T1105 - Ingress Tool Transfer
T1113 - Screen Capture
T1115 - Clipboard Data
T1132.001 - Standard Encoding
T1190
T1547.001 - Registry Run Keys / Startup Folder
T1552.001 - Credentials In Files
T1555.003 - Credentials from Web Browsers
T1566.001
T1573.001 - Symmetric Cryptography
T1583 - Acquire Infrastructure
T1584 - Compromise Infrastructure
T1585 - Establish Accounts
T1586 - Compromise Accounts
T1588 - Obtain Capabilities
T1592 - Gather Victim Host Information
T1596 - Search Open Technical Databases
T1608 - Stage Capabilities
T1610 - Deploy Container
T1612 - Build Image on Host