Cotton Sandstorm: Hack
Most organizations still think about Iranian cyber operations in terms of malware, encryption or disruption. Cotton Sandstorm is a reminder that the risk is broader: technical intrusion, data theft, media impersonation, timed leaking and psychological pressure.
📞 Contact Persist Security experts for tailored advice
The group, also known as Emennet Pasargad and tracked under names such as NEPTUNIUM, Haywire Kitten, Holy Souls and MARNANBRIDGE, has been linked by Microsoft, US law
That means defending against this kind of actor is not just an EDR or firewall problem. It requires digital
persistsec. com”>Quantum — Cyber Threat Intelligence for early warning on exposure and hostile narratives, com”>Persist Security services for penetration testing, exposure assessment, threat hunting and Hack
- Cotton Sandstorm is an Iranian influence actor that connects intrusion, leaking, impersonation and public narrative manipulation.
- The core risk is not only stolen data, but the use of that data to damage trust with customers, executives, employees and public audiences.
- Israeli organizations should secure not only critical systems but also “soft” public assets: marketing sites, customer portals, mailing platforms, social
- Practical readiness combines SOC/MDR, CTI, mobile protection, identity controls, exposure testing and a rehearsed leak
- Persist Security can help with exposure assessment, threat hunting, 24/7 SOC monitoring, mobile security, Hack
Who Is Cotton Sandstorm and What Makes Its Tactics Different?
Cotton Sandstorm is an Iranian actor focused on the intersection of cyber operations and influence operations.
Microsoft uses the Cotton Sandstorm name under its “Sandstorm” taxonomy for Iranian actors, while other sources use Emennet Pasargad, the name of an Iranian company publicly tied to this activity. US authorities attributed to two Iranian nationals a 2020 election
What separates Cotton Sandstorm from traditional espionage groups is the intended outcome. An espionage group may quietly collect documents; a destructive group may wipe systems; Cotton Sandstorm often seeks public impact. It can use technical access to construct a narrative: “we have your data,” “the system is vulnerable,” or “the public cannot trust this institution.
This is a familiar influence
Lessons from Election Operations, Charlie Hebdo and the Israeli Context
The 2020 US election campaign is a classic example of combining technical access with influence. According to the Department of Justice, the attackers obtained voter information from at least one state election website, sent threatening emails designed to look as if they came from an extremist group, and produced a misleading video claiming vulnerabilities could be exploited in election systems.
Even if the technical damage was limited, the objective was to undermine confidence in a democratic process. In the Charlie Hebdo case, Malpedia and other sources describe Hack
Once again, stolen data was not just intelligence; it was raw material for pressure, embarrassment and fear. Microsoft reported in 2024 that Cotton Sandstorm was preparing for activity around the US election, including infrastructure and collection efforts. The broader reporting on Iranian actors shows that Iran uses cyber operations to amplify strategic influence, not only for isolated intrusion.
Israeli organizations should assume that even an attack against a business may become part of a broader story: undermining public trust, creating pressure during regional conflict or projecting instability. The Israeli risk becomes sharper when suppliers, customer systems and public assets are involved.
A marketing site, customer portal, CRM, abandoned domain or old social
A Possible Attack Chain: From Reconnaissance to Influence Campaign
In the first stage, Cotton Sandstorm and similar actors map exposed assets: websites, CMS platforms, mail servers, VPN services, open databases, cloud accounts and public employee profiles. The goal is not always immediate exploitation.
Sometimes collection is used to understand who makes decisions, which suppliers connect to the organization, where user records are stored and which topics will create public resonance. The second stage is compromise or data acquisition. It may rely on known vulnerabilities, leaked passwords, targeted phishing, third
CISA has previously warned that Iranian actors exploited Microsoft Exchange and Fortinet vulnerabilities, emphasizing fast patching, MFA and unique passwords. While that advisory is not exclusive to Cotton Sandstorm, it reflects a broader Iranian pattern: quickly exploiting existing exposure before organizations close the gap.
The third stage is choosing how to turn access into influence. One option is public leaking of data. Another is impersonating a local persona and sending threatening or divisive messages.
A third is publishing partial “proof” — screenshots or a small set of files — to make victims and journalists assume the damage is larger. This is a critical point: a small amount of real data can look like a major breach when the organization lacks a clear picture of what happened. The fourth stage is a battle for trust.
If the organization responds late, publishes vague statements or cannot say which systems were affected, the attacker wins. If the organization can identify the source of the leak, block access, check data integrity, update customers and keep communications consistent, it can reduce the influence impact even before the technical investigation is complete.
Against Cotton Sandstorm, public response time is part of the security control set.
Where Persist Security Fits into Hack
Defending against Hack
Quantum: Early Warning and Hostile Narrative Monitoring
Quantum is designed to identify early mentions of organizations, domains, executives, suppliers, leaked records and hostile narratives across open sources, dark
Against Cotton Sandstorm, early detection of the organization’s name, domain, executive identity or customer data can provide a critical response window before the story becomes public.
SOC/MDR and SentinelOne: Earlier Detection and Faster Response
Microsoft:
gov/opa/pr/two gov/news
Against Cotton Sandstorm, the question is not only whether an attacker entered the network. The question is whether that access can be turned into a public story that damages trust. Any organization that manages customer data, a mailing platform, a public brand or sensitive infrastructure needs the ability to detect exposure early, respond quickly, validate leaked material and communicate clearly. Persist Security can help with exposure assessment, threat hunting, SOC/MDR, mobile security with Quantum and readiness exercises for Hack Against actors like Cotton Sandstorm, protecting only the server may still leave public trust exposed. —
Author: Paz Shwartz, CEO of Persist Security — cyber expert, CISO, penetration tester and threat researcher. LinkedIn:
- and-Leak, Iranian Influence and Trust Defense
- enforcement agencies and intelligence repositories such as Malpedia to Iranian cyber-enabled influence activity. Instead of treating network access as the end goal, Cotton Sandstorm turns access into a public weapon: convincing executives, customers, voters or communities that the targeted organization has lost control.
- asset monitoring, threat hunting, identity hardening, mobile security, crisis readiness and communications discipline. For Israeli organizations, this is where Persist Security’s services become directly relevant:
- and-Leak
- to-date inventory of domains, subdomains, legacy websites, SaaS platforms, social-media accounts, customer portals, mailing providers and databases that contain personal information. An unmanaged asset can become a headline. Regular external exposure scans should cover SSL certificates, DNS permissions, CMS versions, plugins and forgotten test environments.
- media, mailing platforms and website-management systems. Personal accounts should be separated from service accounts, departed employees should be removed promptly, and logins from unusual countries, devices or hours should be monitored.
- response process. That process should include technical teams, legal counsel, executives, communications and customer support.
- data downloads, new account creation, DNS changes, mailbox forwarding rules, access to mailing platforms and bulk data export tools. Historical logs for 90 to 180 days matter, because an influence campaign can be based on data stolen long before publication.
- related activity and the link between Iran and digital influence, but focuses mainly on the US arena.
- and-Leak context, but it is intentionally concise. CISA provides baseline controls for Iranian exploitation of known vulnerabilities, but it is not focused on influence campaigns.
- response playbook and running focused hunting around data export and suspicious logins.
- and-Leak dangerous even when the stolen data is limited?
- style risk?
- media access can become an entry point. Atlas provides a Mobile Threat Defense layer to reduce this risk.
- us/security/blog/2024/08/09/iran-targeting-2024-us-election/”>Iran targeting 2024 US election
- us/security/blog/2024/10/23/iran-steps-into-us-election-2024-with-cyber-enabled-influence-operations/”>Iran steps into US election 2024 with cyber-enabled influence operations
- iranian-nationals-charged-cyber-enabled-disinformation-and-threat-campaign-designed”>Two Iranian nationals charged in cyber-enabled disinformation and threat campaign
- events/cybersecurity-advisories/aa21-321a”>Iranian government-sponsored APT cyber actors exploiting Microsoft Exchange and Fortinet vulnerabilities
- and-Leak scenarios.
- 07-29
- 07-29
-
The group, also known as Emennet Pasargad and tracked under names such as NEPTUNIUM, Haywire Kitten, Holy Souls and MARNANBRIDGE, has been linked by Microsoft, US law-enforcement agencies and intelligence repositories such as Malpedia to Iranian cyber-enabled influence activity. Instead of treating network access as the end goal, Cotton Sandstorm turns access into a public weapon: convincing executives, customers, voters or communities that the targeted organization has lost control.
- Israeli organizations should secure not only critical systems but also “soft” public assets: marketing sites, customer portals, mailing platforms, social-media accounts and forgotten domains.
-
” A seemingly small incident — a defaced webpage or a secondary database exposure — can become an influence tool if it is not handled quickly, accurately and transparently. The group also operates through personas. The Holy Souls name has been associated with activity against Charlie Hebdo, while election operations used misleading identities designed to appear local.
-
A marketing site, customer portal, CRM, abandoned domain or old social-media account can all become a starting point. If the attacker obtains personal information, internal documents or access to a communications account, it can build a believable campaign without taking over core infrastructure. Defenders therefore need to protect not only critical servers, but also the public-facing assets that carry trust.
- Persist Security also supports penetration testing, exposure assessment and cyber crisis readiness. Against Cotton Sandstorm, the key question is not only “can we be breached? ” but “which asset could be turned into a headline?
-
In influence operations, a compromised marketing or communications mailbox can be almost as dangerous as an administrator account. Organizations also need a leak-response process. That process should include technical teams, legal counsel, executives, communications and customer support.
-
Conclusion: Protect the Server — But Also Protect Public Trust
💡 Practical Implementation Tips
- Start with Assessment: Map your current state before implementing changes
- Phased Planning: Break the process into clear, manageable phases
- Continuous Measurement: Set success metrics and monitor them regularly
- Team Training: Ensure all stakeholders understand the new processes
✅ Quick Checklist
📊 Success Metrics to Track
🔗 Related Services
🛡️ Managed SOC Services 24/7 – Continuous monitoring and response to cyber threats
💼 External CISO Services – Strategic information security management
⚡ Advanced Penetration Testing – Find vulnerabilities before attackers do
📊 Security Assessment – Comprehensive review of organizational security posture
🚀 Ready to Upgrade Your Security?
Contact us today for personalized consultation and comprehensive security strategy planning