Actors Insights|Latest update24/07/2026

Storm-0784

Named by MicrosoftSuspected state sponsor: Islamic Republic of Iran

Storm-0784 is Microsoft's tracking designation for an Iranian-linked threat actor active since at least early 2026. The Storm prefix in Microsoft's naming taxonomy indicates an assessed or confirmed nation-state nexus; the 0784 identifier places this cluster within the unclassified staging range used before sufficient evidence is available for a permanent named attribution. Storm-0784 activity has been observed in the context of Iranian state cyber operations targeting organizations of interest to IRGC or MOIS intelligence priorities, though specific tooling, targeting, and definitive organizational attribution have not been fully detailed in public reporting at this stage.

First Seen:Mar 2026
Last Seen:Apr 2026
Indexed Reports:0
Public IOCs:0
Cluster: Unclassified
also known as:
Storm-0784 (Microsoft)

Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.