Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory

Altoufan Team

Also known asAltoufan Team

Altoufan Team is a persona tied to Cotton Sandstorm. The provided reporting states that the persona was revived in the context of anticipated Iranian-linked cyber counteroffensive activity following Operation Epic Fury on February 28, 2026. Cotton Sandstorm is described as affiliated with the IRGC Cyber-Electronic Command (IRGC-CEC) and as conducting hack-and-leak and influence operations under personas including Altoufan Team. Based on the provided content, Altoufan Team should therefore be understood as part of Iranian state-linked cyber activity, specifically as a front/persona associated with Cotton Sandstorm rather than a distinct standalone intrusion group. No additional high-confidence targeting, malware, or TTP details are directly provided for Altoufan Team beyond its use in hack-and-leak and influence operations and its revival being noted in the reporting.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

2 of 15 tactics2 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0007
Discovery
1 technique
T1654
Log Enumeration
TA0040
Impact
1 technique
T1498×2
Network Denial of Service
ACTIVITY FEED

Recent activity

1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping2

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.