Gray Sandstorm is a Microsoft-tracked Iran-attributed nation-state threat actor. It has been associated with credential-based intrusions against Microsoft 365 environments, particularly through password-spraying activity, and with follow-on access to cloud-hosted communications and other sensitive organizational data. Reporting has linked Gray Sandstorm-like activity to campaigns against organizations in Israel and the United Arab Emirates, with additional limited targeting in the United States, the United Kingdom, Saudi Arabia, and parts of Europe. The actor is known for using password spraying as an initial-access technique against cloud identity services, followed by authenticated access using compromised accounts. Observed tradecraft includes use of Tor exit nodes during spraying activity, use of commercial VPN infrastructure to blend post-compromise logins with expected geography, and use of red-team tooling during operations. Post-compromise behavior has included access to mailbox content and other sensitive information, indicating an espionage-oriented collection objective. Targeting has included government entities, municipalities, technology organizations, transportation and logistics organizations, energy-sector organizations, healthcare organizations, manufacturing organizations, and other private-sector cloud tenants. Gray Sandstorm falls within Microsoft’s Sandstorm family for Iran-attributed operators. Available reporting in this context supports an Iran nexus and patterns consistent with state-aligned cyber espionage rather than financially motivated ransomware activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An Iranian-linked threat actor associated here with password-spraying attacks against Microsoft 365 environments, using red-team tools via Tor exit nodes and showing similarities to the observed campaign.
Iran-linked threat actor linked in the reporting to password-spraying campaigns against Microsoft 365 accounts, using Tor exit nodes and red-team tools, likely to support intelligence collection and bomb-damage assessment.
Iran-linked nation-state threat actor listed in Microsoft's naming taxonomy mapping.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.