This is the Trace Id: 60211e25c17eb2b41f2fb03cdf30d084

The 2025 Microsoft Digital Defense Report is now available! Read the report

Nation State Actor

Smoke Sandstorm

Blue hexagon pattern with O/O text.
Smoke Sandstorm (formerly BOHRIUM/DEV-0056) compromised email accounts at a Bahrain-based IT integration company in September 2021. This company works on IT integration with Bahrain Government clients, who were likely Smoke Sandstorm’s ultimate target. Smoke Sandstorm also compromised various accounts at a partially government-owned organization in the Middle East that provides information and communications technology to the defense and transportation sectors, which are targets of interest to the Iranian regime. In May of 2022, Microsoft took legal action to disrupt spear phishing operations linked to Smoke Sandstorm.

DETAILS

Country of origin:

Countries targeted:

Industries targeted:

Microsoft Threat Intelligence: Recent Smoke Sandstorm Articles

Microsoft disrupts Bohrium hackers’ spear-phishing operation

Civil Action No.

Iranian targeting of IT sector on the rise

Follow Microsoft Security