Actors Insights|Latest update27/08/2026
Mercury
Named by MicrosoftSuspected state sponsor: Islamic Republic of IranMercury is Microsoft's legacy designation for the Iranian MOIS-linked threat cluster formally renamed Mango Sandstorm in 2023. Active since at least 2017, Mercury targeted government and telecommunications organizations across the Middle East using spear phishing and custom PowerShell implants. Microsoft retired the Mercury name as part of its updated threat actor naming taxonomy, replacing it with Mango Sandstorm. All Mercury reporting is now consolidated under the Mango Sandstorm designation, which covers the same MOIS-attributed MuddyWater cluster.
This threat actor's name is changed to Mango Sandstorm
First Seen:Nov 2019
Last Seen:May 2026
Indexed Reports:3
Public IOCs:49
also known as:
TEMP.Zagros (Mandiant)Static Kitten (CrowdStrike)Seedworm (Symantec)MERCURY (Microsoft)COBALT ULSTER (SecureWorks)G0069 (Mitre)ATK51 (Thales)Boggy SerpensMango Sandstorm (Microsoft)TA450 (Proofpoint)Earth Vetala (Trend Micro)MuddyWater (Palo Alto)
Targeted Regions
IsraelIsrael
Jul 2022 ~ Aug 2022
Jul 2022 ~ Aug 2022
Middle EastMiddle East
Sep 2020 ~ Oct 2020
Jan 2020Sep 2026
Recent Indexed Reports
Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.