Smoke Sandstorm — Threat Actor Profile, Campaigns & Targets

Threat entity extracted from intelligence sources

Frequency
9
occurrences
First Seen
November 5, 2025
Last Seen
June 2, 2026

Smoke Sandstorm is a apt_group tracked across 9 threat clusters and 9 intelligence report mentions on ThreatCluster. First observed November 5, 2025; most recent activity June 2, 2026.

Overview

Smoke Sandstorm is described in the provided articles as an Iranian APT activity associated with the alias SmudgedSerpent. The group conducts targeted phishing campaigns against influential US policy wonks, indicating covert intelligence collection and influence operations. Its elusiveness and focus on high-value policy targets underscore the growing impact of state-sponsored cyber operations in geopolitical risk landscapes.

Related Threat Clusters

Recent Intelligence Reports

  • Nimbus Manticore APT Abuses Fake Recruitment Portal to Deliver Custom Malware — Cybersecuritynews · June 2, 2026
  • Nimbus Manticore APT Uses Fake Jobs to Deliver Custom Malware — Gbhackers · June 2, 2026
  • Iranian APT Group Targets Aviation and Software Firms with Updated Tools — Eplaneai · May 26, 2026
  • MiniUpdate RAT Abuses Azure C2 for Targeted Espionage — Gbhackers · May 25, 2026
  • Iran-linked hackers target key US, allied sectors with sophisticated spear — Cybersecuritydive · May 22, 2026
  • Amazon security boss: Hostile countries use cyber targeting for physical military strikes — Theregister · November 19, 2025
  • Iranian Cyber Espionage: Proofpoint Uncovers UNK_SmudgedSerpent — Esecurityplanet · November 10, 2025
  • Iran's Elusive "SmudgedSerpent' APT Phishes Influential US Policy Wonks — Proofpoint · November 5, 2025

CVSS v3.1 Breakdown