Smoke Sandstorm is a apt_group tracked across 9 threat clusters and 9 intelligence report mentions on ThreatCluster. First observed November 5, 2025; most recent activity June 2, 2026.
Smoke Sandstorm is described in the provided articles as an Iranian APT activity associated with the alias SmudgedSerpent. The group conducts targeted phishing campaigns against influential US policy wonks, indicating covert intelligence collection and influence operations. Its elusiveness and focus on high-value policy targets underscore the growing impact of state-sponsored cyber operations in geopolitical risk landscapes.
Iranian state-aligned hackers, known as Nimbus Manticore (UNC1549), have intensified cyberattacks against the US aviation sector amid the ongoing US-Iran military conflict. Utilizing career-themed phishing and a novel…
The Screening Serpens group, linked to Iran, has initiated a targeted espionage campaign using a new remote access Trojan (RAT) named MiniUpdate. This campaign primarily targets technology professionals in the United…
The Iranian-aligned threat group Nimbus Manticore has launched a cyber campaign targeting aerospace and defense organizations. This operation utilizes a fake recruitment portal to distribute custom malware via a…
Following U.S. military strikes on Iran, there is an anticipated increase in cyber warfare activities targeting U.S. operational technology and critical infrastructure. Iran is expected to retaliate with cyber attacks…
Amazon's Threat Intelligence team has identified a trend where nation-state actors utilize cyber operations to facilitate physical military strikes, termed 'cyber-enabled kinetic targeting.' This new operational model…
Between June and August 2025, a previously unidentified Iranian cyber actor, dubbed UNK_SmudgedSerpent, conducted targeted phishing attacks against US academics and foreign policy experts. The campaign aimed to steal…
Amazon's threat intelligence teams have identified a trend where nation-state actors are using cyber operations to enhance physical military strikes, termed 'cyber-enabled kinetic targeting.' This new operational model…
Between June and August 2025, the Iranian-linked APT UNK_SmudgedSerpent conducted targeted phishing campaigns against US academics and foreign policy experts. The group employed techniques such as credential theft and…
Between June and August 2025, a cyber group identified as UNK_SmudgedSerpent targeted U.S. academics and foreign policy experts focused on Iran. The attackers initiated contact through seemingly benign conversations to…