Cotton Sandstorm
Aliases: Emennet Pasargad, Holy Souls, MARNANBRIDGE, NEPTUNIUM, HAYWIRE KITTEN, Vice Leaker, DEV-0198
- Origin
- IR
- Primary motivation
- ideology
- Sophistication
- intermediate
- Resource level
- government
- Actor type
- Information Operations
- Profile updated
- 2026-07-07 11:52:06
Targeted industries: government-and-public-sector media-and-entertainment
Targeted regions: country_code:fr country_code:us country_code:il
Context
Cotton Sandstorm is an Iranian threat actor involved in hack-and-leak operations. They have targeted various organizations, including the French satirical magazine Charlie Hebdo, where they obtained and leaked personal information of over 200,000 customers. The group has been linked to the Iranian government and has been sanctioned by the US Treasury
Reports & references
- services.google.com — Tool Of First Resort Israel Hamas War Cyber (report)
- blog.sekoia.io — Iran Cyber Threat Overview (report)
- Microsoft — Dtac Charlie Hebdo Hack Iran Neptunium (report)
- ic3.gov — 220126 (report)
- Microsoft — Iran Response For Charlie Hebdo Attacks (report)
- raw.githubusercontent.com — Microsoftmapping (report)
- Microsoft — Microsoft Threat Actor Naming (report)