logo

Microsoft: Iran's Mint Sandstorm APT Blasts Educators, Researchers

ID: cd12241f-9f49-595e-b96c-afe610068dd1

STIX ID: report--cd12241f-9f49-595e-b96c-afe610068dd1

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2024-01-19

Date Updated: 2026-04-21

Author: Robert Lemos, Contributing Writer

...
...

Microsoft and industry reporting attribute a targeted espionage campaign to the Iran-linked Mint Sandstorm group (overlapping with APT35/Charming Kitten) that uses patient, highly skilled social engineering — often posing as journalists or researchers and leveraging compromised accounts — to trick academics, journalists, and policy experts into opening malicious RAR links. Successful engagements lead to deployment of custom backdoors (MediaPI and MischiefTut) and likely credential compromise to facilitate long-term surveillance and data theft, representing a sophisticated nation-state threat to researchers and institutions covering Middle Eastern and Iran-related topics.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.