The US and Israel have warned that the Iranian state-backed Cotton Sandstorm is developing new commercial means to target networks, including leveraging artificial intelligence production tools.
See also: Iranian hackers sell access to critical infrastructure as brokers

The joint advisory highlighted how the group, also known as Marnanbridge or Haywire Kitten, has recently shifted from “hack and leak” operations against organizations primarily in Israel to a broader range of attacks affecting multiple countries, including Israel, France, Sweden and the US.
This includes actively targeting websites and media outlets related to the US election, suggesting that it is preparing to conduct operations as Presidential Election Day approaches.
The group has conducted multiple cyber operations targeting the 2024 Paris Olympics, including the breach of a French commercial dynamic display provider and has undertaken a project to collect content from IP cameras.
The agencies added that since April 2024, Cotton Sandstorm has used the online persona “Cyber Court” to promote the activities of several alleged hacktivist groups conducting malicious activities against various countries as a means of protesting the Israel-Hamas conflict.
See also: Iranian OilRig hackers exploit Windows vulnerability
The FBI said it has credible information that as of mid-2024, Cotton Sandstorm has been operating under the name Aria Sepehr Ayandehsazan (ASA) as a front name, including for human resources and financial purposes.

Microsoft's 2024 Digital Defense Report identified Cotton Sandstorm as part of the Islamic Revolutionary Guard Corps (IRGC), which conducts offensive cyber operations on behalf of Tehran.
The advisory highlighted several new tactics, techniques and procedures (TTPs) that Cotton Sandstorm has been observed using. The agencies added that Cotton Sandstorm continues to undertake significant reconnaissance, initial access, persistence and credential access as part of its operations.
See also: Multiple Iranians accused of hacking Donald Trump's campaign
In recent years, Iranian hackers have garnered attention on the global stage for their sophisticated cyberattacks .These hackers are often associated with state-sponsored groups and are known to target critical infrastructure, government sectors, and private industry in various countries. Their cyber activities range from espionage and data theft to actions such as ransomware or interference with digital communications systems. The motivation behind these attacks is usually linked to geopolitical goals, where cyberwarfare is used as a strategic tool to exert influence and gather information, making cybersecurity a primary concern for nations worldwide.
Source: infosecurity-magazine
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
