Cobalt Obelisk is an Iran-linked threat actor associated with Shahid Shushtari and assessed to be affiliated with the Islamic Revolutionary Guard Corps Cyber-Electronic Command (IRGC-CEC). Reported aliases include Cotton Sandstorm, Haywire Kitten, Marnanbridge, and UNC5866. The actor has been tied to disruptive and influence-oriented cyber activity as well as intrusions affecting government and private-sector organizations. The group has been publicly linked to operations including compromise of telecommunications-related data, unauthorized access to subscriber information, and disinformation activity conducted through compromised digital advertising infrastructure during the 2024 Paris Olympic Games. U.S. government reporting has also attributed significant financial damage and disruption to U.S. businesses and government agencies to members of Shahid Shushtari. Observed targeting includes government entities and commercial organizations, with victims documented in the United States, Sweden, and France. The actor's activity profile is consistent with Iranian state-linked cyber operations that combine network intrusion with information operations and disruptive effects. Based on the available high-confidence information, Cobalt Obelisk is best characterized as an Iran-linked actor engaged primarily in influence operations, with additional disruptive cyber activity against public- and private-sector targets.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.