Actors Insights|Latest update27/08/2026

Mango Sandstorm

Named by MicrosoftSuspected state sponsor: Islamic Republic of Iran

Mango Sandstorm is Microsoft's current designation for the Iranian MOIS-linked threat cluster widely known as MuddyWater. Active since at least 2017, the group targets government, telecommunications, defense, and energy organizations across the Middle East and beyond. Microsoft has documented Mango Sandstorm's use of legitimate remote administration tools alongside custom malware for persistent access, and its collaboration with the Storm-1084 subgroup in destructive operations against Israeli organizations. The Mango Sandstorm name replaced the earlier Mercury designation as part of Microsoft's 2023 threat actor naming taxonomy update.

This threat actor previously was known as Mercury
First Seen:Nov 2019
Last Seen:May 2026
Indexed Reports:3
Public IOCs:49
Cluster: MuddyWaterMitre: MuddyWaterMisp: MuddyWater
also known as:
TEMP.Zagros (Mandiant)Static Kitten (CrowdStrike)Seedworm (Symantec)MERCURY (Microsoft)COBALT ULSTER (SecureWorks)G0069 (Mitre)ATK51 (Thales)Boggy SerpensMango Sandstorm (Microsoft)TA450 (Proofpoint)Earth Vetala (Trend Micro)MuddyWater (Palo Alto)

Targeted Regions

Israel
IL
Israel
Israel
Jul 2022 ~ Aug 2022
Jul 2022 ~ Aug 2022
Middle East
ME
Middle East
Middle East
Sep 2020 ~ Oct 2020
Jan 2020Sep 2026

Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.