WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Community Partnerships Threat Awareness – Iranian Threat Actor Mint Sandstorm Increasingly Targeting US Critical Infrastructure In 2023
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Directory
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Threat Awareness – Iranian Threat Actor Mint Sandstorm Increasingly Targeting US Critical Infrastructure In 2023

Author: April Zupan

Created: Thursday, April 20, 2023 - 17:06

Categories: Cybersecurity, Intelligence

Microsoft has posted a blog providing details on Mint Sandstorm, a threat actor group previously labeled PHOSPHORUS and who is believed to be associated with the Islamic Revolutionary Guard Corps, the intelligence arm of Iran’s military. Over the past year, the group has shifted from network reconnaissance activities to actively targeting U.S. critical infrastructure, including the energy, transportation systems, and chemical sectors.

Mint Sandstorm has the ability to rapidly weaponize N-day or zero-day vulnerabilities that have been publicly disclosed. Microsoft has observed the group rapidly repurposing publicly posted proof-of-concept code for zero-day exploitation multiple times this year. Additionally, Microsoft warns that the group also continues to exploit older vulnerabilities for initial compromise. Both capabilities which emphasize the need to apply patches for known vulnerabilities in a timely manner. This, combined with the use of custom network exploitation tools and targeted phishing campaigns, makes Mint Sandstorm a difficult threat for most critical infrastructure organizations to face. Microsoft includes mitigations against the group’s custom tools in the blog and additional recommendations that members are encouraged to examine. Read more at Microsoft.

Related Resources

Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated May 1, 2026)

May 1, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness

Tip of the Week – April 30, 2026

Apr 30, 2026 in Cybersecurity, Security Preparedness

(TLP:CLEAR) Cyber Readiness Institute Joins WaterISAC as a Community Partner to Strengthen Cyber Readiness Across the Water Sector

Apr 30, 2026 in Cybersecurity, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar