Gray Sandstorm
Named by MicrosoftSuspected state sponsor: Islamic Republic of IranGray Sandstorm is a Microsoft tracking name for a subset of activity attributed to the Iranian APT33 cluster. The designation follows Microsoft's Sandstorm naming convention for Iranian state-sponsored actors and reflects more recent operational activity observed in early 2026. The group shares the core tradecraft of the broader APT33 cluster — including password spray campaigns and intelligence collection targeting defense, aerospace, and energy sectors — and is assessed to operate in support of Iranian state interests alongside the wider Peach Sandstorm and HOLMIUM tracking identities.
Targeted Regions
EuropeEurope
Mar 2026 ~ Mar 2026
Mar 2026 ~ Mar 2026
Mar 2026 ~ Mar 2026
IsraelIsrael
Mar 2026 ~ Mar 2026
Mar 2026 ~ Mar 2026
Mar 2026 ~ Mar 2026
Saudi ArabiaSaudi Arabia
Mar 2026 ~ Mar 2026
Mar 2026 ~ Mar 2026
Mar 2026 ~ Mar 2026
United Arab EmiratesUnited Arab Emirates
Mar 2026 ~ Mar 2026
Mar 2026 ~ Mar 2026
Mar 2026 ~ Mar 2026
United KingdomUnited Kingdom
Mar 2026 ~ Mar 2026
Mar 2026 ~ Mar 2026
Mar 2026 ~ Mar 2026
United StatesUnited States
Mar 2026 ~ Mar 2026
Mar 2026 ~ Mar 2026
Mar 2026 ~ Mar 2026
Targeted Sectors
Recent Indexed Reports
Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.