Actors Insights|Latest update04/07/2026

Smoke Sandstorm

Named by MicrosoftSuspected state sponsor: Islamic Republic of Iran

Smoke Sandstorm is a Microsoft tracking designation for recent Imperial Kitten activity, reflecting updated operational patterns observed from 2023 onward. The designation follows Microsoft's Sandstorm naming convention for IRGC-linked Iranian actors. Smoke Sandstorm activity includes job-recruitment phishing campaigns targeting aerospace and defense professionals, consistent with the broader Imperial Kitten cluster's long-running focus on defense sector intelligence collection. The name aligns with Proofpoint's TA455 tracking for the same activity period.

This threat actor previously was known as BOHRIUM
First Seen:Sep 2023
Last Seen:Nov 2025
Indexed Reports:0
Public IOCs:0
Cluster: Imperial KittenMisp: Bohrium
also known as:
Smoke Sandstorm (Microsoft)BOHRIUM (Microsoft)Imperial Kitten (CrowdStrike)

Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.