Actors Insights|Latest update24/07/2026

BOHRIUM

Named by MicrosoftSuspected state sponsor: Islamic Republic of Iran

BOHRIUM is Microsoft's legacy designation for an Iranian-linked threat actor that conducted spear phishing campaigns targeting technology, education, and government sector organizations. The group was publicly disrupted in June 2022 when Microsoft's Digital Crimes Unit seized 41 domains used by the actors, following a court order. BOHRIUM operations focused on credential harvesting through fake job lures, with victims primarily in India, the United States, and the Middle East. The group was subsequently renamed Smoke Sandstorm as part of Microsoft's 2023 threat actor taxonomy update, reflecting the cluster's assessed IRGC attribution and alignment with Imperial Kitten and UNC1549 tracking.

This threat actor's name is changed to Smoke Sandstorm
First Seen:Sep 2023
Last Seen:Nov 2025
Indexed Reports:0
Public IOCs:0
Cluster: UnclassifiedMisp: Bohrium
also known as:
Smoke Sandstorm (Microsoft)BOHRIUM (Microsoft)Imperial Kitten (CrowdStrike)

Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.