Actors Insights|Latest update08/07/2026

Gray Sandstorm

Named by MicrosoftSuspected state sponsor: Islamic Republic of Iran

Gray Sandstorm is a Microsoft tracking name for a subset of activity attributed to the Iranian APT33 cluster. The designation follows Microsoft's Sandstorm naming convention for Iranian state-sponsored actors and reflects more recent operational activity observed in early 2026. The group shares the core tradecraft of the broader APT33 cluster — including password spray campaigns and intelligence collection targeting defense, aerospace, and energy sectors — and is assessed to operate in support of Iranian state interests alongside the wider Peach Sandstorm and HOLMIUM tracking identities.

First Seen:Mar 2026
Last Seen:Mar 2026
Indexed Reports:1
Public IOCs:5
Cluster: APT33Misp: Gray Sandstorm
also known as:
DEV-0343 (Microsoft)Gray Sandstorm (Microsoft)

Targeted Regions

Europe
EU
Europe
Europe
Mar 2026 ~ Mar 2026
Mar 2026 ~ Mar 2026
Mar 2026 ~ Mar 2026
Israel
IL
Israel
Israel
Mar 2026 ~ Mar 2026
Mar 2026 ~ Mar 2026
Mar 2026 ~ Mar 2026
Saudi Arabia
SA
Saudi Arabia
Saudi Arabia
Mar 2026 ~ Mar 2026
Mar 2026 ~ Mar 2026
Mar 2026 ~ Mar 2026
United Arab Emirates
AE
United Arab Emirates
United Arab Emirates
Mar 2026 ~ Mar 2026
Mar 2026 ~ Mar 2026
Mar 2026 ~ Mar 2026
United Kingdom
GB
United Kingdom
United Kingdom
Mar 2026 ~ Mar 2026
Mar 2026 ~ Mar 2026
Mar 2026 ~ Mar 2026
United States
US
United States
United States
Mar 2026 ~ Mar 2026
Mar 2026 ~ Mar 2026
Mar 2026 ~ Mar 2026
Jan 2026Dec 2026

Targeted Sectors

BankingFinancialGovernment Agencies and ServicesInformation TechnologyInsuranceLogisticsManufacturingMedicalProfessional ServiceRetailAerospaceEducationEnergyHealthcareScientific ResearchTransportation

Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.