Mango Sandstorm
Named by MicrosoftSuspected state sponsor: Islamic Republic of IranMango Sandstorm is Microsoft's current designation for the Iranian MOIS-linked threat cluster widely known as MuddyWater. Active since at least 2017, the group targets government, telecommunications, defense, and energy organizations across the Middle East and beyond. Microsoft has documented Mango Sandstorm's use of legitimate remote administration tools alongside custom malware for persistent access, and its collaboration with the Storm-1084 subgroup in destructive operations against Israeli organizations. The Mango Sandstorm name replaced the earlier Mercury designation as part of Microsoft's 2023 threat actor naming taxonomy update.
Targeted Regions
IsraelIsrael
Jul 2022 ~ Aug 2022
Jul 2022 ~ Aug 2022
Middle EastMiddle East
Sep 2020 ~ Oct 2020
Recent Indexed Reports
Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.