WezRat
WezRat is a custom, purpose-built modular information stealer associated with the Iranian threat actor Emennet Pasargad, also tracked as Cotton Sandstorm and Haywire Kitten. Reporting in the provided content states that the group routinely delivers WezRat via spearphishing campaigns masquerading as urgent software updates, and that it was deployed in intrusions in the months leading up to the February 28, 2026 conflict escalation. Check Point Research is cited as assessing that Cotton Sandstorm pre-positioned WezRat before the strikes, and that the malware was used alongside the Altoufan persona for hack-and-leak amplification. The content further states that WezRat has been followed in some cases by deployment of WhiteLock ransomware, including activity specifically described against Israeli targets. High-confidence context in the source material links WezRat to Iranian influence and intrusion operations targeting Israel and other countries in the Middle East, with Emennet Pasargad also described as conducting operations against the U.S., France, and Sweden. No specific file hashes, domains, or other concrete IOCs for WezRat are provided in the content.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Cotton Sandstorm deployed WezRat and WhiteLock alongside the Altoufan persona for hack-and-leak amplification.
...‘WhiteLock’ ransomware, deployed after WezRat infostealer.
Techniques & procedures
12 distinct techniques documented for this family, organized by ATT&CK tactic.
Initial Access
3 techniques
Initial Access
“pivoting to exploit zero-day vulnerabilities in industrial time-management software…” and “identify and exploit public-facing applications at scale.”
Stealth
2 techniques
Stealth
Credential Access
4 techniques
Credential Access
Collection
2 techniques
Collection
Exfiltration
1 technique
Exfiltration
Recent activity
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote access trojan/backdoor used by Cotton Sandstorm for pre-positioning access ahead of geopolitical escalation.
A RAT deployed by Cotton Sandstorm in support of hack-and-leak operations.
Custom modular infostealer used by an Iranian-linked threat group (Cotton Sandstorm/Haywire Kitten), delivered via spearphishing disguised as urgent software updates.
Modular information stealer with DLL-loaded capabilities including screen capture, keylogging, clipboard theft, and cookie harvesting.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.