Threats Feed|Mint Sandstorm|Last Updated 03/07/2026|AuthorCertfa Radar|Publish Date17/01/2024

Mint Sandstorm's Strategic Phishing Tactics and Persistent Threats to Research Organizations

  • Actor Motivations: Espionage,Exfiltration
  • Attack Vectors: Compromised Credentials,Backdoor,Downloader,Malware,Phishing
  • Attack Complexity: Medium
  • Threat Risk: High Impact/Low Probability

Threat Overview

The Mint Sandstorm campaign exhibited sophisticated cyberattack tactics targeting universities and research organizations. Notably, the campaign utilized compromised email accounts for phishing, leveraging social engineering by impersonating high-profile individuals, such as journalists. Initial emails were benign, building trust before delivering malicious content. The attacks involved using the curl command for connecting to a C2 server, downloading malicious files, and deploying custom backdoors like MediaPl and MischiefTut. MediaPl disguised as Windows Media Player, encrypted communications, and used unique persistence methods. The attackers aimed to exfiltrate data and maintain long-term access to compromised systems, posing significant risks to the confidentiality and reputation of the targeted organizations.

Detected Targets

TypeDescriptionConfidence
SectorJournalists
Verified
SectorResearchers
Verified
SectorUniversity
Verified
RegionBelgium
Verified
RegionFrance
Verified
RegionIsrael
Verified
RegionPalestine
Verified
RegionUnited Kingdom
Verified
RegionUnited States
Verified

Extracted IOCs

  • cloud-document-edit.onrender[.]com
  • coral-polydactyl-dragonfruit.glitch[.]me
  • east-healthy-dress.glitch[.]me
  • epibvgvoszemkwjnplyc.supabase[.]co
  • kwhfibejjyxregxmnpcs.supabase[.]co
  • ndrrftqrlblfecpupppp.supabase[.]co
  • f2dec56acef275a0e987844e98afcc44bf8b83b4661e83f89c6a2a72c5811d5f
download

Tip: 7 related IOCs (0 IP, 6 domain, 0 URL, 0 email, 1 file hash) to this threat have been found.

Overlaps

CharmingCypressCharmingCypress: Iranian Espionage Campaign Targets Global Think Tanks and Journalists

Source: Volexity - February 2024

Detection (five cases): f2dec56acef275a0e987844e98afcc44bf8b83b4661e83f89c6a2a72c5811d5f, cloud-document-edit.onrender[.]com, coral-polydactyl-dragonfruit.glitch[.]me, east-healthy-dress.glitch[.]me, ndrrftqrlblfecpupppp.supabase[.]co

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

Mint Sandstorm Cyber Campaign

A sophisticated cyber attack campaign was launched using highly deceptive emails to trick individuals into downloading malicious files. Once the victims interacted with these files, the attackers quietly installed custom software onto their computers. This allowed the attackers to remotely access and monitor the compromised systems.

The campaign was carried out by a threat actor group known as Mint Sandstorm. This group demonstrated patience, advanced technical skills, and a high level of resources to carefully select and compromise their targets.

The primary goal of the attack was to establish hidden, long-term remote access to victim computers. By maintaining this access, the attackers could spy on system activity, collect sensitive information, and issue new commands without the victim's knowledge.

Yes, the attackers specifically targeted individuals who possessed valuable insights or expertise on current events, such as the Israel-Hamas war. To gain their trust, the attackers impersonated high-profile individuals, like journalists from reputable news outlets.

The attackers began by sending harmless-looking emails to build trust and rapport with the victim. Once the victim agreed to collaborate on an article, they were sent a link to a fake document. Clicking this link and opening the file triggered a hidden process that secretly downloaded and installed the attackers' tools.

The targeted individuals likely had access to sensitive communications, strategic insights, or confidential data that the attackers wanted to acquire. Compromising these systems allowed the attackers to steal this information, which could lead to significant privacy and reputational risks for the victims and their organizations.

Organizations should enhance their network security by monitoring for unusual background activities and blocking deceptive file downloads. Individuals must remain highly cautious of unexpected emails asking for input or collaboration on documents, even if the sender appears to be a legitimate professional.

About Affiliation
Mint Sandstorm
Mint Sandstorm is Microsoft's current name for the Iranian state-sponsored threat cluster previously tracked as Phosphorus and widely known as Charming Kitten and APT35. The cluster is associated with the IRGC and comprises multiple subgroups with distinct operational focuses. Microsoft has documented one technically sophisticated subgroup that rapidly weaponizes N-day vulnerabilities to target critical infrastructure including seaports, energy companies, and transit systems, as well as high-value individuals in the defense and government sectors. A second subgroup focuses on credential phishing against journalists, activists, and policy researchers. Activity overlaps with APT35, APT42, and TA453.
View Mint Sandstorm's Insights