Cotton Sandstorm
Also reported as NEPTUNIUM, HAYWIRE KITTEN, Emennet Pasargad, Holy Souls, MARNANBRIDGE and 2 other names. Linked to Iran by three sources.
Reports per quarter
Techniques seen in the last two years
- T1071.001 1 report
- T1110.001 1 report
- T1110.002 1 report
- T1190 1 report
- T1219 1 report
- T1583 1 report
- T1587 1 report
- T1589 1 report
- T1589.002 1 report
- T1589.003 1 report
Show all 16 techniques Show fewer
Counts come from technique IDs in the actor's report text.
CVEs named in reports
- CVE-2009-1151 KEV
- CVE-2014-0160 KEV
- CVE-2016-10033 KEV
- CVE-2017-0213 KEV ransomware
- CVE-2017-0214
- CVE-2017-14723
- CVE-2017-14726
- CVE-2017-5611
- CVE-2017-5930
- CVE-2017-5963
- CVE-2017-8295
- CVE-2018-13379 KEV ransomware
Show all 27 CVEs Show fewer
- CVE-2018-7600 KEV ransomware
- CVE-2018-8639 KEV ransomware
- CVE-2018-8641
- CVE-2019-0044
- CVE-2019-0232
- CVE-2019-0604 KEV ransomware
- CVE-2019-0708 KEV ransomware
- CVE-2019-9621 KEV
- CVE-2021-21974
- CVE-2021-44228 KEV ransomware
- CVE-2022-27924 KEV ransomware
- CVE-2022-47966 KEV ransomware
- CVE-2022-47986 KEV ransomware
- CVE-2023-23397 KEV
- CVE-2023-38831 KEV ransomware
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
Shahid Hemmat Hackers: $10M Reward Offered by US
The original link failed its last check. Original publisher Detailsfor Shahid Hemmat Hackers: $10M Reward Offered by US
Show all 17 reports Show fewer
-
How Microsoft names threat actors
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor How Microsoft names threat actors
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Two Iranian Nationals Charged for Cyber-Enabled Disinformation and Threat Campaign Designed to Influence the 2020 U.S. Presidential Election ( Seyyed Mohammad Hosein Musa Kazemi & Sajjad Kashian )
-
ViceLeaker Operation- mobile espionage targeting Middle East
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor ViceLeaker Operation- mobile espionage targeting Middle East
Newest first. Details opens the report in Explore.