Cotton Sandstorm: Hack-and-Leak, Iranian Influence and Trust Defense

Cotton Sandstorm: Hack-and-Leak, Iranian Influence and Trust Defense

Most organizations still think about Iranian cyber operations in terms of malware, encryption or disruption. Cotton Sandstorm is a reminder that the risk is broader: technical intrusion, data theft, media impersonation, timed leaking and psychological pressure. The group, also known as Emennet Pasargad and tracked under names such as NEPTUNIUM, Haywire Kitten, Holy Souls and MARNANBRIDGE, has been linked by Microsoft, US law-enforcement agencies and intelligence repositories such as Malpedia to Iranian cyber-enabled influence activity.

Instead of treating network access as the end goal, Cotton Sandstorm turns access into a public weapon: convincing executives, customers, voters or communities that the targeted organization has lost control. That means defending against this kind of actor is not just an EDR or firewall problem. It requires digital-asset monitoring, threat hunting, identity hardening, mobile security, crisis readiness and communications discipline.

For Israeli organizations, this is where Persist Security’s services become directly relevant: Quantum — Cyber Threat Intelligence for early warning on exposure and hostile narratives, Atlas — Mobile Threat Defense for protecting executives, employees and BYOD devices, Managed SentinelOne EDR + 24/7 SOC for endpoint detection and response, and Persist Security services for penetration testing, exposure assessment, threat hunting and Hack-and-Leak readiness.

Executive Summary

  • Cotton Sandstorm is an Iranian influence actor that connects intrusion, leaking, impersonation and public narrative manipulation.
  • The core risk is not only stolen data, but the use of that data to damage trust with customers, executives, employees and public audiences.
  • Israeli organizations should secure not only critical systems but also “soft” public assets: marketing sites, customer portals, mailing platforms, social-media accounts and forgotten domains.
  • Practical readiness combines SOC/MDR, CTI, mobile protection, identity controls, exposure testing and a rehearsed leak-response process.
  • Persist Security can help with exposure assessment, threat hunting, 24/7 SOC monitoring, mobile security, Hack-and-Leak tabletop exercises and incident response.

Who Is Cotton Sandstorm and What Makes Its Tactics Different?

Cotton Sandstorm is an Iranian actor focused on the intersection of cyber operations and influence operations. Microsoft uses the Cotton Sandstorm name under its “Sandstorm” taxonomy for Iranian actors, while other sources use Emennet Pasargad, the name of an Iranian company publicly tied to this activity. US authorities attributed to two Iranian nationals a 2020 election-related disinformation and intimidation campaign that included compromise of state election systems, threatening emails, a misleading video and attempts to spread false claims about voting-system weaknesses.

What separates Cotton Sandstorm from traditional espionage groups is the intended outcome. An espionage group may quietly collect documents; a destructive group may wipe systems; Cotton Sandstorm often seeks public impact. It can use technical access to construct a narrative: “we have your data,” “the system is vulnerable,” or “the public cannot trust this institution.” A seemingly small incident — a defaced webpage or a secondary database exposure — can become an influence tool if it is not handled quickly, accurately and transparently.

The group also operates through personas. The Holy Souls name has been associated with activity against Charlie Hebdo, while election operations used misleading identities designed to appear local. This is a familiar influence-operations pattern: the attacker does not only hide its origin; it chooses a mask that maximizes polarization, fear or media resonance. In Israel’s highly sensitive information environment, identifying the mask in time can be almost as important as identifying the IP address.

Lessons from Election Operations, Charlie Hebdo and the Israeli Context

The 2020 US election campaign is a classic example of combining technical access with influence. According to the Department of Justice, the attackers obtained voter information from at least one state election website, sent threatening emails designed to look as if they came from an extremist group, and produced a misleading video claiming vulnerabilities could be exploited in election systems. Even if the technical damage was limited, the objective was to undermine confidence in a democratic process.

In the Charlie Hebdo case, Malpedia and other sources describe Hack-and-Leak activity and exposure of personal information affecting more than 200,000 customers. The target selection was not random: a politically sensitive media organization, a global audience and a high likelihood of attention beyond the technical scope of the compromise. Once again, stolen data was not just intelligence; it was raw material for pressure, embarrassment and fear.

Microsoft reported in 2024 that Cotton Sandstorm was preparing for activity around the US election, including infrastructure and collection efforts. The broader reporting on Iranian actors shows that Iran uses cyber operations to amplify strategic influence, not only for isolated intrusion. Israeli organizations should assume that even an attack against a business may become part of a broader story: undermining public trust, creating pressure during regional conflict or projecting instability.

The Israeli risk becomes sharper when suppliers, customer systems and public assets are involved. A marketing site, customer portal, CRM, abandoned domain or old social-media account can all become a starting point. If the attacker obtains personal information, internal documents or access to a communications account, it can build a believable campaign without taking over core infrastructure. Defenders therefore need to protect not only critical servers, but also the public-facing assets that carry trust.

A Possible Attack Chain: From Reconnaissance to Influence Campaign

In the first stage, Cotton Sandstorm and similar actors map exposed assets: websites, CMS platforms, mail servers, VPN services, open databases, cloud accounts and public employee profiles. The goal is not always immediate exploitation. Sometimes collection is used to understand who makes decisions, which suppliers connect to the organization, where user records are stored and which topics will create public resonance.

The second stage is compromise or data acquisition. It may rely on known vulnerabilities, leaked passwords, targeted phishing, third-party account compromise or an unpatched system. CISA has previously warned that Iranian actors exploited Microsoft Exchange and Fortinet vulnerabilities, emphasizing fast patching, MFA and unique passwords. While that advisory is not exclusive to Cotton Sandstorm, it reflects a broader Iranian pattern: quickly exploiting existing exposure before organizations close the gap.

The third stage is choosing how to turn access into influence. One option is public leaking of data. Another is impersonating a local persona and sending threatening or divisive messages. A third is publishing partial “proof” — screenshots or a small set of files — to make victims and journalists assume the damage is larger. This is a critical point: a small amount of real data can look like a major breach when the organization lacks a clear picture of what happened.

The fourth stage is a battle for trust. If the organization responds late, publishes vague statements or cannot say which systems were affected, the attacker wins. If the organization can identify the source of the leak, block access, check data integrity, update customers and keep communications consistent, it can reduce the influence impact even before the technical investigation is complete. Against Cotton Sandstorm, public response time is part of the security control set.

Where Persist Security Fits into Hack-and-Leak Defense

Defending against Hack-and-Leak campaigns requires a broader view than a single security product. Persist Security can support several complementary layers, with defensible goals: reduce exposure, shorten detection time, improve response and limit reputational damage.

Quantum: Early Warning and Hostile Narrative Monitoring

Quantum is designed to identify early mentions of organizations, domains, executives, suppliers, leaked records and hostile narratives across open sources, dark-web locations, Telegram channels, leak forums and ransomware-related ecosystems. Against Cotton Sandstorm, early detection of the organization’s name, domain, executive identity or customer data can provide a critical response window before the story becomes public.

SOC/MDR and SentinelOne: Earlier Detection and Faster Response

Managed SentinelOne EDR + 24/7 SOC helps detect abnormal endpoint behavior, suspicious tools, attempted data theft, outbound staging activity and persistence techniques. When endpoint telemetry is combined with a SOC team that monitors, triages and escalates in real time, the organization has a better chance of detecting compromise or exfiltration before it turns into a public leak.

Atlas: Mobile Security for Executives, Employees and BYOD

In influence operations, a mobile device belonging to an executive, spokesperson, marketing manager or employee with access to social-media accounts can become a meaningful entry point. Atlas provides Mobile Threat Defense based on Check Point Harmony Mobile, monitored 24/7 by Persist Security’s SOC, against SMS, WhatsApp and browser phishing, malicious applications, spyware and hostile WiFi networks. For organizations with BYOD programs or sensitive executives, mobile protection is a critical layer.

Penetration Testing, External Exposure and Crisis Readiness

Persist Security also supports penetration testing, exposure assessment and cyber crisis readiness. Against Cotton Sandstorm, the key question is not only “can we be breached?” but “which asset could be turned into a headline?” An old customer portal, unpatched WordPress instance, abandoned domain, unprotected mailing platform or unnecessary cloud permission can create reputational damage even if the core systems remain intact.

How Israeli Organizations Should Prepare for Hack-and-Leak

Preparation begins with mapping public digital assets. Organizations should maintain an up-to-date inventory of domains, subdomains, legacy websites, SaaS platforms, social-media accounts, customer portals, mailing providers and databases that contain personal information. An unmanaged asset can become a headline. Regular external exposure scans should cover SSL certificates, DNS permissions, CMS versions, plugins and forgotten test environments.

The next layer is identity hardening. MFA should be enforced for email, cloud, social-media, mailing platforms and website-management systems. Personal accounts should be separated from service accounts, departed employees should be removed promptly, and logins from unusual countries, devices or hours should be monitored. In influence operations, a compromised marketing or communications mailbox can be almost as dangerous as an administrator account.

Organizations also need a leak-response process. That process should include technical teams, legal counsel, executives, communications and customer support. Before an incident, the organization should prepare Hebrew and English response templates, define who approves public statements, decide how leaked documents are validated, and know when to notify regulators or customers. If the first time the team discusses these questions is after the data appears on Telegram, it is already behind.

On the technical side, defenders should run threat hunting around unauthorized web access, unusual customer-data downloads, new account creation, DNS changes, mailbox forwarding rules, access to mailing platforms and bulk data export tools. Historical logs for 90 to 180 days matter, because an influence campaign can be based on data stolen long before publication.

Finally, organizations should rehearse. A good exercise starts with a public attacker claim, continues with validation of the leaked documents and tests whether the team can distinguish a real leak from recycled data and deliberate deception. The goal is not only closing a vulnerability; it is maintaining customer trust under pressure.

What the Leading Public Sources Miss — and What to Do This Week

The main public references on Cotton Sandstorm provide important but incomplete guidance for Israeli business leaders. Microsoft offers the most current context on 2024 election-related activity and the link between Iran and digital influence, but focuses mainly on the US arena. The Department of Justice provides detailed legal allegations around the 2020 campaign, but it is not a defensive playbook. Malpedia consolidates aliases and Hack-and-Leak context, but it is intentionally concise. CISA provides baseline controls for Iranian exploitation of known vulnerabilities, but it is not focused on influence campaigns. Rewards for Justice and FBI publications support attribution and identification of individuals, but do not fully explain how an Israeli company should prepare.

The central gap is the connection between information security and trust management. A practical plan for the coming week should include mapping public assets, enabling MFA across all publishing and communications channels, checking for exposed or legacy customer databases, preparing a leak-response playbook and running focused hunting around data export and suspicious logins. At the same time, executives should know who is authorized to publish a response if an attacker’s statement appears online.

Frequently Asked Questions

Is Cotton Sandstorm an espionage group or an influence actor?

Cotton Sandstorm connects cyber capability with influence operations. In different cases, it has been associated with data theft, impersonation, disinformation and leaking. It is best understood as an actor that can use technical intrusion to generate public and psychological impact.

Why is Hack-and-Leak dangerous even when the stolen data is limited?

Because the data becomes raw material for a narrative. Even one real file, screenshot or partial dataset can convince customers or journalists that the incident is bigger than it is, especially if the organization responds late or cannot explain what happened.

How can Quantum help against influence campaigns?

Quantum can support early identification of organization names, domains, executives, leaked data and hostile discussion across relevant intelligence sources. The goal is to help the organization detect signals before the story reaches mainstream channels.

Why is mobile security relevant to Cotton Sandstorm-style risk?

Influence campaigns often use phishing, impersonation and access to communications channels. A mobile device used by an executive, spokesperson or employee with social-media access can become an entry point. Atlas provides a Mobile Threat Defense layer to reduce this risk.

Key References

Conclusion: Protect the Server — But Also Protect Public Trust

Against Cotton Sandstorm, the question is not only whether an attacker entered the network. The question is whether that access can be turned into a public story that damages trust. Any organization that manages customer data, a mailing platform, a public brand or sensitive infrastructure needs the ability to detect exposure early, respond quickly, validate leaked material and communicate clearly.

Persist Security can help with exposure assessment, threat hunting, SOC/MDR, mobile security with Atlas, threat intelligence with Quantum and readiness exercises for Hack-and-Leak scenarios. Against actors like Cotton Sandstorm, protecting only the server may still leave public trust exposed.

Author: Paz Shwartz, CEO of Persist Security — cyber expert, CISO, penetration tester and threat researcher.

LinkedIn: https://www.linkedin.com/in/pazshwartz/

Publication date: 2026-07-29

Last updated: 2026-07-29

Picture of פז שורץ

פז שורץ

מנכ״ל פרסיסט סקיורטי