Gray Sandstorm

Aliases: DEV-0343

First seen
2012-01-01 00:00:00
Origin
IR
Primary motivation
espionage
Sophistication
intermediate
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 11:51:52

Targeted industries: defense-and-aerospace transportation-and-logistics technology-and-telecommunications

Targeted regions: country_code:us country_code:il

Context

Gray Sandstorm is an Iran-linked threat actor that has been active since at least 2012. They have targeted defense technology companies, maritime transportation companies, and Persian Gulf ports of entry. Their primary method of attack is password spraying, and they have been observed using tools like o365spray. They have a specific focus on US and Israeli targets and are likely operating in support of Iranian interests.

Reports & references

  • Microsoft — Evolving Trends In Iranian Threat Actor Activity Mstic Presentation At Cyberwarcon 2021 (report)
  • Microsoft — Iran Linked Dev 0343 Targeting Defense Gis And Maritime Sectors (report)
  • raw.githubusercontent.com — Microsoftmapping (report)
  • Microsoft — Microsoft Threat Actor Naming (report)

External references