Actors Insights|Latest update30/05/2025

Mango Sandstorm

Named by MicrosoftSuspected state sponsor: Islamic Republic of Iran
This threat actor previously was known as Mercury
First Seen:Sep 2020
Last Seen:Apr 2025
Indexed Reports:3
Public IOCs:49
Cluster: MuddyWaterMitre: MuddyWaterMisp: MuddyWater
also known as:
TEMP.Zagros (Mandiant)Static Kitten (CrowdStrike)Seedworm (Symantec)MERCURY (Microsoft)COBALT ULSTER (SecureWorks)G0069 (Mitre)ATK51 (Thales)Boggy SerpensMango Sandstorm (Microsoft)TA450 (Proofpoint)Earth Vetala (Trend Micro)MuddyWater (Palo Alto)

Targeted Regions

Israel
IL
Israel
Israel
Jul 2022 ~ Aug 2022
Middle East
ME
Middle East
Middle East
Sep 2020 ~ Oct 2020
Sep 2020 ~ Oct 2020
Jan 2020Oct 2025

Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.