Actors Insights|Latest update04/07/2026

Cotton Sandstorm

Named by MicrosoftSuspected state sponsor: Islamic Republic of Iran

Cotton Sandstorm is an Iranian state-sponsored threat cluster linked to the IRGC and known for combining cyberattacks with influence operations. Active since at least 2023, the group conducts website defacements, DDoS attacks, and hack-and-leak campaigns primarily targeting Israeli and Western organizations, with operations intensifying following the October 2023 Hamas-Israel conflict. The US Treasury sanctioned the affiliated Iranian company Emennet Pasargad for its role in these operations. Microsoft tracks this cluster as Cotton Sandstorm; CrowdStrike uses the name Haywire Kitten.

First Seen:Jun 2023
Last Seen:Oct 2024
Indexed Reports:0
Public IOCs:0
also known as:
Emennet Pasargad (real name)Holy SoulsMARNANBRIDGE (Google)NEPTUNIUM (Microsoft)Haywire Kitten (CrowdStrike)Cotton Sandstorm (Microsoft)

Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.