Smoke Sandstorm — Threat Actor Profile, Campaigns & Targets

Threat entity extracted from intelligence sources

Frequency
13
occurrences
First Seen
November 5, 2025
Last Seen
August 26, 2026

Smoke Sandstorm is described in the provided articles as an Iranian APT activity associated with the alias SmudgedSerpent.

Overview

Smoke Sandstorm is described in the provided articles as an Iranian APT activity associated with the alias SmudgedSerpent. The group conducts targeted phishing campaigns against influential US policy wonks, indicating covert intelligence collection and influence operations. Its elusiveness and focus on high-value policy targets underscore the growing impact of state-sponsored cyber operations in geopolitical risk landscapes.

Related Threat Clusters

Recent Intelligence Reports

  • Securelist — securelist.com · August 26, 2026
  • UAE Fends Off Third Sector-Targeting Cyberattack of 2026; Finance First, Now Aviation, Energy — Techtimes · August 10, 2026
  • Cybersecurity Researchers Uncover Mirage Kitten Malware Sweeping Across Africa — Streamlinefeed.Co.Ke · July 30, 2026
  • Mirage Kitten targets Middle East and Africa region with new malware — Securelist · July 28, 2026
  • Nimbus Manticore APT Abuses Fake Recruitment Portal to Deliver Custom Malware — Cybersecuritynews · June 2, 2026
  • Nimbus Manticore APT Uses Fake Jobs to Deliver Custom Malware — Gbhackers · June 2, 2026
  • Iranian APT Group Targets Aviation and Software Firms with Updated Tools — Eplaneai · May 26, 2026
  • MiniUpdate RAT Abuses Azure C2 for Targeted Espionage — Gbhackers · May 25, 2026

CVSS v3.1 Breakdown