Cotton Sandstorm: Hack-and-Leak, Iranian Influence and Trust Defense

Cotton Sandstorm: Hack
Most organizations still think about Iranian cyber operations in terms of malware, encryption or disruption. Cotton Sandstorm is a reminder that the risk is broader: technical intrusion, data theft, media impersonation, timed leaking and psychological pressure.

📞 Contact Persist Security experts for tailored advice

The group, also known as Emennet Pasargad and tracked under names such as NEPTUNIUM, Haywire Kitten, Holy Souls and MARNANBRIDGE, has been linked by Microsoft, US law

That means defending against this kind of actor is not just an EDR or firewall problem. It requires digital

persistsec. com”>Quantum — Cyber Threat Intelligence for early warning on exposure and hostile narratives, com”>Persist Security services for penetration testing, exposure assessment, threat hunting and Hack

  • Cotton Sandstorm is an Iranian influence actor that connects intrusion, leaking, impersonation and public narrative manipulation.
  • The core risk is not only stolen data, but the use of that data to damage trust with customers, executives, employees and public audiences.

  • Israeli organizations should secure not only critical systems but also “soft” public assets: marketing sites, customer portals, mailing platforms, social
  • Practical readiness combines SOC/MDR, CTI, mobile protection, identity controls, exposure testing and a rehearsed leak
  • Persist Security can help with exposure assessment, threat hunting, 24/7 SOC monitoring, mobile security, Hack

Who Is Cotton Sandstorm and What Makes Its Tactics Different?

Cotton Sandstorm is an Iranian actor focused on the intersection of cyber operations and influence operations.

Microsoft uses the Cotton Sandstorm name under its “Sandstorm” taxonomy for Iranian actors, while other sources use Emennet Pasargad, the name of an Iranian company publicly tied to this activity. US authorities attributed to two Iranian nationals a 2020 election

What separates Cotton Sandstorm from traditional espionage groups is the intended outcome. An espionage group may quietly collect documents; a destructive group may wipe systems; Cotton Sandstorm often seeks public impact. It can use technical access to construct a narrative: “we have your data,” “the system is vulnerable,” or “the public cannot trust this institution.

This is a familiar influence

Lessons from Election Operations, Charlie Hebdo and the Israeli Context

The 2020 US election campaign is a classic example of combining technical access with influence. According to the Department of Justice, the attackers obtained voter information from at least one state election website, sent threatening emails designed to look as if they came from an extremist group, and produced a misleading video claiming vulnerabilities could be exploited in election systems.

Even if the technical damage was limited, the objective was to undermine confidence in a democratic process. In the Charlie Hebdo case, Malpedia and other sources describe Hack

Once again, stolen data was not just intelligence; it was raw material for pressure, embarrassment and fear. Microsoft reported in 2024 that Cotton Sandstorm was preparing for activity around the US election, including infrastructure and collection efforts. The broader reporting on Iranian actors shows that Iran uses cyber operations to amplify strategic influence, not only for isolated intrusion.

Israeli organizations should assume that even an attack against a business may become part of a broader story: undermining public trust, creating pressure during regional conflict or projecting instability. The Israeli risk becomes sharper when suppliers, customer systems and public assets are involved.

A marketing site, customer portal, CRM, abandoned domain or old social

A Possible Attack Chain: From Reconnaissance to Influence Campaign

In the first stage, Cotton Sandstorm and similar actors map exposed assets: websites, CMS platforms, mail servers, VPN services, open databases, cloud accounts and public employee profiles. The goal is not always immediate exploitation.

Sometimes collection is used to understand who makes decisions, which suppliers connect to the organization, where user records are stored and which topics will create public resonance. The second stage is compromise or data acquisition. It may rely on known vulnerabilities, leaked passwords, targeted phishing, third

CISA has previously warned that Iranian actors exploited Microsoft Exchange and Fortinet vulnerabilities, emphasizing fast patching, MFA and unique passwords. While that advisory is not exclusive to Cotton Sandstorm, it reflects a broader Iranian pattern: quickly exploiting existing exposure before organizations close the gap.

The third stage is choosing how to turn access into influence. One option is public leaking of data. Another is impersonating a local persona and sending threatening or divisive messages.

A third is publishing partial “proof” — screenshots or a small set of files — to make victims and journalists assume the damage is larger. This is a critical point: a small amount of real data can look like a major breach when the organization lacks a clear picture of what happened. The fourth stage is a battle for trust.

If the organization responds late, publishes vague statements or cannot say which systems were affected, the attacker wins. If the organization can identify the source of the leak, block access, check data integrity, update customers and keep communications consistent, it can reduce the influence impact even before the technical investigation is complete.

Against Cotton Sandstorm, public response time is part of the security control set.

Where Persist Security Fits into Hack
Defending against Hack

Quantum: Early Warning and Hostile Narrative Monitoring

Quantum is designed to identify early mentions of organizations, domains, executives, suppliers, leaked records and hostile narratives across open sources, dark

Against Cotton Sandstorm, early detection of the organization’s name, domain, executive identity or customer data can provide a critical response window before the story becomes public.

SOC/MDR and SentinelOne: Earlier Detection and Faster Response

Microsoft:

gov/opa/pr/two

  • Malpedia:

    gov/news

    Against Cotton Sandstorm, the question is not only whether an attacker entered the network.

    The question is whether that access can be turned into a public story that damages trust. Any organization that manages customer data, a mailing platform, a public brand or sensitive infrastructure needs the ability to detect exposure early, respond quickly, validate leaked material and communicate clearly.

    Persist Security can help with exposure assessment, threat hunting, SOC/MDR, mobile security with Quantum and readiness exercises for Hack

    Against actors like Cotton Sandstorm, protecting only the server may still leave public trust exposed. —
    Author: Paz Shwartz, CEO of Persist Security — cyber expert, CISO, penetration tester and threat researcher. LinkedIn:

  • persistsec.

    • The group, also known as Emennet Pasargad and tracked under names such as NEPTUNIUM, Haywire Kitten, Holy Souls and MARNANBRIDGE, has been linked by Microsoft, US law-enforcement agencies and intelligence repositories such as Malpedia to Iranian cyber-enabled influence activity. Instead of treating network access as the end goal, Cotton Sandstorm turns access into a public weapon: convincing executives, customers, voters or communities that the targeted organization has lost control.

    • Israeli organizations should secure not only critical systems but also “soft” public assets: marketing sites, customer portals, mailing platforms, social-media accounts and forgotten domains.
    • ” A seemingly small incident — a defaced webpage or a secondary database exposure — can become an influence tool if it is not handled quickly, accurately and transparently. The group also operates through personas. The Holy Souls name has been associated with activity against Charlie Hebdo, while election operations used misleading identities designed to appear local.

    • A marketing site, customer portal, CRM, abandoned domain or old social-media account can all become a starting point. If the attacker obtains personal information, internal documents or access to a communications account, it can build a believable campaign without taking over core infrastructure. Defenders therefore need to protect not only critical servers, but also the public-facing assets that carry trust.

    • Persist Security also supports penetration testing, exposure assessment and cyber crisis readiness. Against Cotton Sandstorm, the key question is not only “can we be breached? ” but “which asset could be turned into a headline?

    • In influence operations, a compromised marketing or communications mailbox can be almost as dangerous as an administrator account. Organizations also need a leak-response process. That process should include technical teams, legal counsel, executives, communications and customer support.

    • Conclusion: Protect the Server — But Also Protect Public Trust

    💡 Practical Implementation Tips

    • Start with Assessment: Map your current state before implementing changes
    • Phased Planning: Break the process into clear, manageable phases
    • Continuous Measurement: Set success metrics and monitor them regularly
    • Team Training: Ensure all stakeholders understand the new processes

    ✅ Quick Checklist

    Initial Assessment – Review current state
    Strategic Planning – Set goals and timelines
    Phased Implementation – Deploy in stages
    Monitoring & Control – Track results

    📊 Success Metrics to Track

    < 24 hours
    Incident Response Time
    95%+
    Threat Detection Rate
    99.9%
    System Uptime
    0
    Critical Security Incidents

    🔗 Related Services

    🚀 Ready to Upgrade Your Security?

    Contact us today for personalized consultation and comprehensive security strategy planning

    Picture of פז שורץ

    פז שורץ

    מנכ״ל פרסיסט סקיורטי