Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Iran🇮🇷 IR3 malware families

Cotton Sandstorm

Also known asaria_sepehr_ayandehsazanayandeh_sazan_sepehr_aryaCotton Sandstormeeleyanet_gostaremennet_pasargadHAYWIRE KITTENmarnanbridgeNEPTUNIUMnet_peygard_samavat_companyshahid_shushtariVice Leaker

Cotton Sandstorm is an Iranian threat actor affiliated with the Islamic Revolutionary Guard Corps, specifically described in multiple sources as operating under or affiliated with the IRGC Cyber-Electronic Command (IRGC-CEC). It is also identified as Emennet Pasargad and has been referred to by the U.S. government as Shahid Shushtari. Reported aliases include Haywire Kitten, Marnanbridge, Neptunium, Aria Sepehr Ayandehsazan, Ayandeh Sazan Sepehr Arya, Eeleyanet Gostar, Net Peygard Samavat Company, Vice Leaker, and in some reporting Emennet Pasargad is also known as Anzu Team or Holy Souls. The group has conducted both intrusion activity and cyber-enabled influence operations. It was sanctioned for interfering in the 2020 U.S. presidential election, where it stole confidential voter information and sent threatening emails while posing as far-right extremists. Microsoft reporting cited in the content describes this as a cyber-enabled influence operation in which the group spoofed the Proud Boys and used access to voter registries to lend credibility to the narrative. U.S. officials and later reporting state the group has targeted critical infrastructure and sectors including news, shipping, travel, energy, financial services, and telecommunications across the United States, Europe, and the Middle East. Additional countries explicitly mentioned as targets include Israel, France, and Sweden. Recent reporting describes sustained operations against Israel and regional targets, including hack-and-leak and influence activity under personas such as Altoufan Team. The group revived the Altoufan Team persona to claim website hacks in Bahrain and has been described as conducting hack-and-leak campaigns and influence operations under that persona. Check Point Research reported that Cotton Sandstorm pre-positioned access before the February 28 strikes and deployed the WezRat modular information stealer, in some cases followed by WhiteLock ransomware, including against Israeli targets. The content also states Cotton Sandstorm deployed WezRat and WhiteLock for hack-and-leak amplification. The group has also been linked to operations in Europe. Emennet Pasargad was sanctioned by the EU in 2026 for malicious cyber activity including the 2023 theft of Charlie Hebdo subscriber data, compromise of a French display provider during the Summer Olympics, hijacking advertising billboards during the 2024 Paris Olympic Games to display propaganda, and compromise of a Swedish SMS service. Microsoft tracked Emennet Pasargad as Neptunium and described it as an Iranian nation-state actor. Tradecraft directly mentioned in the content includes spear-phishing, phishing and malware delivery, broad reconnaissance, targeted intrusion activity, use of false-flag personas, and delivery of DNSpionage malware via spear-phishing and exploitation of Microsoft Exchange vulnerabilities. The group is also described as maintaining a fairly consistent pace of phishing and malware delivery activity since 2020. Known personas and fronts mentioned in the content include Altoufan Team and multiple front-company names used over time, including Emennet Pasargad, Aria Sepehr Ayandehsazan, Ayandeh Sazan Sepehr Arya, Eeleyanet Gostar, and Net Peygard Samavat Company.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Where they're from

Attributed origin per open-source reporting.

  • IR
MITRE ATT&CK

Tradecraft

17 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

7 of 15 tactics20 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0042
Resource Development
2 techniques
T1583×2
Acquire Infrastructure
T1584
Compromise Infrastructure
TA0001
Initial Access
2 techniques
T1190
Exploit Public-Facing Application
T1566×3
Phishing
TA0005
Stealth
1 technique
T1036
Masquerading
TA0006
Credential Access
3 techniques
T1056
Input Capture
T1056.001
Keylogging
T1539
Steal Web Session Cookie
T1555
Credentials from Password Stores
T1555.003
Credentials from Web Browsers
TA0009
Collection
3 techniques
T1005
Data from Local System
T1056
Input Capture
T1056.001
Keylogging
T1113
Screen Capture
TA0010
Exfiltration
2 techniques
T1041
Exfiltration Over C2 Channel
T1537
Transfer Data to Cloud Account
TA0040
Impact
4 techniques
T1485×2
Data Destruction
T1486×3
Data Encrypted for Impact
T1491×4
Defacement
T1498
Network Denial of Service
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping17

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal3

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.