Actors Insights|Latest update04/07/2026
Smoke Sandstorm
Named by MicrosoftSuspected state sponsor: Islamic Republic of IranSmoke Sandstorm is a Microsoft tracking designation for recent Imperial Kitten activity, reflecting updated operational patterns observed from 2023 onward. The designation follows Microsoft's Sandstorm naming convention for IRGC-linked Iranian actors. Smoke Sandstorm activity includes job-recruitment phishing campaigns targeting aerospace and defense professionals, consistent with the broader Imperial Kitten cluster's long-running focus on defense sector intelligence collection. The name aligns with Proofpoint's TA455 tracking for the same activity period.
This threat actor previously was known as BOHRIUM
First Seen:Sep 2023
Last Seen:Nov 2025
Indexed Reports:0
Public IOCs:0
Cluster: Imperial KittenMisp: Bohrium
also known as:
Smoke Sandstorm (Microsoft)BOHRIUM (Microsoft)Imperial Kitten (CrowdStrike)
Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.