Actors Insights|Latest update27/08/2026

Mercury

Named by MicrosoftSuspected state sponsor: Islamic Republic of Iran

Mercury is Microsoft's legacy designation for the Iranian MOIS-linked threat cluster formally renamed Mango Sandstorm in 2023. Active since at least 2017, Mercury targeted government and telecommunications organizations across the Middle East using spear phishing and custom PowerShell implants. Microsoft retired the Mercury name as part of its updated threat actor naming taxonomy, replacing it with Mango Sandstorm. All Mercury reporting is now consolidated under the Mango Sandstorm designation, which covers the same MOIS-attributed MuddyWater cluster.

This threat actor's name is changed to Mango Sandstorm
First Seen:Nov 2019
Last Seen:May 2026
Indexed Reports:3
Public IOCs:49
Cluster: MuddyWaterMitre: MuddyWaterMisp: MuddyWater
also known as:
TEMP.Zagros (Mandiant)Static Kitten (CrowdStrike)Seedworm (Symantec)MERCURY (Microsoft)COBALT ULSTER (SecureWorks)G0069 (Mitre)ATK51 (Thales)Boggy SerpensMango Sandstorm (Microsoft)TA450 (Proofpoint)Earth Vetala (Trend Micro)MuddyWater (Palo Alto)

Targeted Regions

Israel
IL
Israel
Israel
Jul 2022 ~ Aug 2022
Jul 2022 ~ Aug 2022
Middle East
ME
Middle East
Middle East
Sep 2020 ~ Oct 2020
Jan 2020Sep 2026

Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.