Cuboid Sandstorm

Aliases: DEV-0228, IMPERIAL KITTEN

First seen
2021-07-01 00:00:00
Origin
IR
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:12:29

Targeted industries: defense-and-aerospace energy-and-utilities professional-services

Targeted regions: country_code:il

Context

Cuboid Sandstorm is an Iranian threat actor that targeted an Israel-based IT company in July 2021. They gained access to the company's network and used it to compromise downstream customers in the defense, energy, and legal sectors in Israel. The group also utilized custom implants, including a remote access Trojan disguised as RuntimeBroker.exe or svchost.exe, to establish persistence on victim hosts.

Reports & references

  • Microsoft — Iranian Targeting Of It Sector On The Rise (report)
  • raw.githubusercontent.com — Microsoftmapping (report)
  • Microsoft — Microsoft Threat Actor Naming (report)

External references