Iran Cyber Threat · Full Landscape Assessment
Decentralized. Deniable. Persistent. Adaptive. Opportunistic. An OSINT assessment of Iran's full cyber delivery model — eight nodes, two institutions, one criminal ecosystem, and an expanding AI layer.
| Actor | Affiliation | Also Known As | Primary Activity |
|---|---|---|---|
APT35 / Charming Kitten | IRGC-IO | Mint Sandstorm · TA453 · TG18 · Educated Manticore | Espionage, credential harvest, election targeting, AI-enhanced ops |
APT42 | IRGC-IO | Sub-cluster of APT35 | Targeted surveillance, credential theft, iOS/Android spyware |
APT33 / Peach Sandstorm | IRGC | Elfin · Refined Kitten · MAGNALIUM | Energy/defense espionage, Azure cloud C2 blending |
Cotton Sandstorm | IRGC-EWCD | Emennet Pasargad · Haywire Kitten | Influence ops, disinformation, 2020 US election interference |
CyberAv3ngers NEW | IRGC-CEC | Sandcat | ICS/OT targeting, US water/wastewater PLCs, AI-assisted recon |
Fox Kitten / Pioneer Kitten | IRGC+IAB | Br0k3r · xplfinder · UNC757 · Lemon Sandstorm | Initial access brokering, ransomware partnerships |
Crimson Sandstorm | IRGC | Imperial Kitten · TortoiseShell · Phosphorus | Supply chain, defense sector espionage, AI phishing |
MuddyWater | MOIS | Mango Sandstorm · Seedworm · Static Kitten · Mercury | Espionage, pre-positioning, RaaS collaboration (Qilin) |
OilRig / APT34 | Joint | Helix Kitten · Evasive Serpens | Long-term espionage, credential harvesting, Gulf targets |
Agrius | MOIS | Pink Sandstorm · Agonizing Serpens · Marshtreader | Wiper malware disguised as ransomware, destructive ops |
Void Manticore NEW | MOIS | Handala · Homeland Justice · Karma · Banished Kitten | Wiper-first, hack-and-leak, Albania attacks 2022, Stryker 2026 |
Cyber Toufan Al-Aqsa NEW | MOIS-linked | Cyber Toufan | Largest Iran-linked data leak campaign vs Israel, post-Oct7 2023 |
DarkBit / DEV-1084 | MOIS | Storm-1084 | Post-intrusion destructive ops, Technion attack 2023 |
Domestic Kitten | MOIS | Persian Kitten | Internal surveillance, diaspora tracking, mobile spyware |
UNK_CraftyCamel NEW | IRGC-aligned | — | UAE aerospace/transport targeting, polyglot file delivery, Sosano backdoor |
| Storm ID | Common Name | Affiliation | Personas | Key Activity |
|---|---|---|---|---|
| Storm-1084 | DarkBit / DEV-1084 | MOIS | DarkBit | Post-intrusion destructive ops |
| Storm-0842 | Pink Sandstorm / Agrius | MOIS | Malek Team · Homeland Justice · MoneyBird | Wipers, fake ransomware, destructive ops vs Israel |
| — | Mango Sandstorm / MuddyWater | MOIS | Tears of War · No Voice · Hunters | Espionage, pre-positioning, RaaS collaboration |
| Storm-1364 | Unknown cluster | IRGC | Adil Ali · Open Hands · Saif al-Quds | Influence operations |
| — | Marigold Sandstorm / Cobalt Sapling | IRGC | Moses Staff · Abraham's Ax | Hack-and-leak, influence ops vs Israel |
| Storm-0784 | Shahid Kaveh / CyberAv3ngers | IRGC-CEC | Cyber Avengers · Soldiers of Solomon | ICS/OT targeting, critical infrastructure |
| — | Cotton Sandstorm / Emennet Pasargad | IRGC-EWCD | Anzu Team · Cyber Cheetahs · For Humanity | Election interference, influence ops, disinformation |
| — | Mint Sandstorm / APT35 | IRGC-IO | Cyber Flood · Al-Toufan · Forces of Light | Espionage, election targeting, AI-enhanced ops |
| — | Pioneer Kitten / Fox Kitten | IRGC+IAB | Br0k3r · xplfinder · Lemon Sandstorm | Initial access brokering, ransomware partnerships |
| — | Void Manticore | MOIS | Handala · Homeland Justice · Karma | Wiper attacks, hack-and-leak, Stryker 2026 |
| — | Cyber Toufan Al-Aqsa | MOIS-linked | Cyber Toufan | Largest Iran-linked data leak vs Israel, post-Oct7 |
| — | CyberAv3ngers | IRGC-CEC | Sandcat | ICS/SCADA, US water systems, PLC exploitation, AI recon |