Skip to Content
logologo
AI Incident Database
Open TwitterOpen RSS FeedOpen FacebookOpen LinkedInOpen GitHub
Open Menu
Discover
Submit
  • Welcome to the AIID
  • Discover Incidents
  • Spatial View
  • Table View
  • List view
  • Entities
  • Taxonomies
  • Submit Incident Reports
  • Submission Leaderboard
  • Blog
  • AI News Digest
  • Risk Checklists
  • Random Incident
  • Sign Up
Collapse
Discover
Submit
  • Welcome to the AIID
  • Discover Incidents
  • Spatial View
  • Table View
  • List view
  • Entities
  • Taxonomies
  • Submit Incident Reports
  • Submission Leaderboard
  • Blog
  • AI News Digest
  • Risk Checklists
  • Random Incident
  • Sign Up
Collapse

Incident 971: Iranian Hacker Group Cotton Sandstorm Integrating AI into Cyber Influence Operations

Description: The Iranian state-sponsored group Cotton Sandstorm, linked to the IRGC, has integrated generative AI into cyber influence operations. In December 2023, it launched Operation “For Humanity," using AI-crafted messaging to hijack a U.S.-based IPTV streaming service with propaganda about the Israel-Hamas conflict. The group also engages in election-related reconnaissance, which suggests they used AI-enhanced influence efforts ahead of the 2024 U.S. election.
Editor Notes: Other associated names of Cotton Sandstorm: Emennet Pasargad; Aria Sepehr Ayandehsazan (ASA) (since the middle of 2024, reportedly); Haywire Kitten; Al-Toufan; Anzu Team; Cyber Cheetahs; Cyber Flood; For Humanity; Menelaus; Market of Data; and NEPTUNIUM. Some other notes: (1) Cotton Sandstorm has been expanding its cyber influence operations by incorporating deepfakes and image manipulation, along with voice modulation techniques, to spread propaganda. (2) They are also associated with having compromised a French commercial display provider during the 2024 Olympics in Paris with the goal of broadcasting anti-Israel messages. (3) In May 2024, the first reported instances of their work performing reconnaissance on U.S. election and media sites was found; the purported aim was to begin laying the groundwork for operations in advance of the November 2024 elections in the United States. (4) They have also allegedly stolen data from IP cameras while harvesting information on Israeli fighter pilots and UAV operators. The date of this incident ID, 05/02/2023, is based off of the Microsoft Threat Analysis Center's report "Rinse and repeat: Iran accelerates its cyber influence operations worldwide," which points to earlier attacks attributed to Cotton Sandstorm between 2020 and the publication of the report.

Tools

New ReportNew ReportNew ResponseNew ResponseDiscoverDiscoverView HistoryView History

Entities

View all entities
Alleged: Islamic Revolutionary Guard Corps (IRGC) , Government of Iran , Cotton Sandstorm and Unknown generative AI developers developed an AI system deployed by Islamic Revolutionary Guard Corps (IRGC) , Government of Iran and Cotton Sandstorm, which harmed U.S. elections , political candidates , Media organizations , General public of the United States , Electoral integrity , Democracy and American voters.
Alleged implicated AI systems: Voicemod , Unknown generative AI tools , Social media platforms , Remini AI Photo Enhancer , News media systems , Murf AI , IPTV streaming service , Election-related websites and Appy Pie

Incident Stats

Incident ID
971
Report Count
13
Incident Date
2023-05-02
Editors

Incident Reports

Reports Timeline

+1
Rinse and repeat: Iran accelerates its cyber influence operations worldwide
Report: Iran Accelerates Cyberattacks+5
As the U.S. election nears, Russia, Iran and China step up influence efforts
+3
FBI: Iranian cyber group targeted Summer Olympics with attack on French display provider
America Resilient in the Face of Aggressive Foreign Malign Influence Targeting the 2024 U.S. Elections
Rinse and repeat: Iran accelerates its cyber influence operations worldwide

Rinse and repeat: Iran accelerates its cyber influence operations worldwide

blogs.microsoft.com

Report: Iran Accelerates Cyberattacks

Report: Iran Accelerates Cyberattacks

iranprimer.usip.org

As the U.S. election nears, Russia, Iran and China step up influence efforts

As the U.S. election nears, Russia, Iran and China step up influence efforts

blogs.microsoft.com

'Cotton Sandstorm': Microsoft claims Iranian hacking group targeting US election websites, media ahead of presidential vote

'Cotton Sandstorm': Microsoft claims Iranian hacking group targeting US election websites, media ahead of presidential vote

timesofindia.indiatimes.com

Influence campaigns from Iran, China, Russia ramping up ahead of elections, Microsoft finds

Influence campaigns from Iran, China, Russia ramping up ahead of elections, Microsoft finds

politico.com

Iranian hacker group aims at US election websites and media before vote, Microsoft says

Iranian hacker group aims at US election websites and media before vote, Microsoft says

reuters.com

Iranian Hackers Target U.S. Election Systems Ahead of 2024 Presidential Race

Iranian Hackers Target U.S. Election Systems Ahead of 2024 Presidential Race

thecyberexpress.com

Putin's pro-Trump trolls accuse Harris of poaching rhinos

Putin's pro-Trump trolls accuse Harris of poaching rhinos

theregister.com

FBI: Iranian cyber group targeted Summer Olympics with attack on French display provider

FBI: Iranian cyber group targeted Summer Olympics with attack on French display provider

therecord.media

Inside Iran’s Cyber Playbook: AI, Fake Hosting, and Psychological Warfare

Inside Iran’s Cyber Playbook: AI, Fake Hosting, and Psychological Warfare

thehackernews.com

US and Israel Warn of Iranian Threat Actor’s New Tradecraft

US and Israel Warn of Iranian Threat Actor’s New Tradecraft

infosecurity-magazine.com

Iranian APT Group Targets IP Cameras, Extends Attacks Beyond Israel

Iranian APT Group Targets IP Cameras, Extends Attacks Beyond Israel

darkreading.com

America Resilient in the Face of Aggressive Foreign Malign Influence Targeting the 2024 U.S. Elections

America Resilient in the Face of Aggressive Foreign Malign Influence Targeting the 2024 U.S. Elections

fdd.org

Rinse and repeat: Iran accelerates its cyber influence operations worldwide
blogs.microsoft.com · 2023

Iran continues to be a significant threat actor, and it is now supplementing its traditional cyberattacks with a new playbook, leveraging cyber-enabled influence operations (IO) to achieve its geopolitical aims.

Microsoft has detected these…

Report: Iran Accelerates Cyberattacks
iranprimer.usip.org · 2023

For the full report, please visit the original source at the United States Institute of Peace website.

On May 2, 2023, Microsoft announced that Iran had been "rapidly accelerating" cyberattacks since mid-2022. The tech giant attributed 24 c…

As the U.S. election nears, Russia, Iran and China step up influence efforts
blogs.microsoft.com · 2024

With two weeks until Election Day 2024, the Microsoft Threat Analysis Center (MTAC) observes sustained influence efforts by Russia, Iran, and China aimed at undermining U.S. democratic processes. Since our last two reports, the U.S. governm…

'Cotton Sandstorm': Microsoft claims Iranian hacking group targeting US election websites, media ahead of presidential vote
timesofindia.indiatimes.com · 2024

An Iranian hacking group, identified by Microsoft as "Cotton Sandstorm" and linked to Iran's Islamic Revolutionary Guard Corps, is conducting reconnaissance on US election-related websites and media outlets as the upcoming election nears, M…

Influence campaigns from Iran, China, Russia ramping up ahead of elections, Microsoft finds
politico.com · 2024

Iranian hackers are gearing up for a potentially major influence operation ahead of the U.S. elections, running parallel to increased election interference efforts from China and Russia, Microsoft said in a report released Wednesday.

The fi…

Iranian hacker group aims at US election websites and media before vote, Microsoft says
reuters.com · 2024

Oct 23 (Reuters) - An Iranian hacking group is actively scouting U.S. election-related websites and American media outlets as Election Day nears, with activity suggesting preparations for more "direct influence operations," according to a M…

Iranian Hackers Target U.S. Election Systems Ahead of 2024 Presidential Race
thecyberexpress.com · 2024

As the US presidential election approaches, an Iranian hacking group known as Cotton Sandstorm is actively targeting election-related websites and media outlets in the United States, according to a recent report by Microsoft. Linked to Iran…

Putin's pro-Trump trolls accuse Harris of poaching rhinos
theregister.com · 2024

Russian, Iranian, and Chinese trolls are all ramping up their US election disinformation efforts ahead of November 5, but – aside from undermining faith in the democratic process and confidence in the election result – with very different o…

FBI: Iranian cyber group targeted Summer Olympics with attack on French display provider
therecord.media · 2024

The FBI and other agencies accused Iranian cyber actors of targeting the 2024 Summer Olympics, including an attempt to take over display boards to denounce Israel.

The U.S. Department of Treasury and Israel National Cyber Directorate joined…

Inside Iran’s Cyber Playbook: AI, Fake Hosting, and Psychological Warfare
thehackernews.com · 2024

U.S. and Israeli cybersecurity agencies have published a new advisory attributing an Iranian cyber group to targeting the 2024 Summer Olympics and compromising a French commercial dynamic display provider to show messages denouncing Israel…

US and Israel Warn of Iranian Threat Actor’s New Tradecraft
infosecurity-magazine.com · 2024

The US and Israel have warned that the Iranian state-sponsored threat actor Cotton Sandstorm is deploying new tradecraft to target networks, including leveraging generative AI tools.

The joint advisory highlighted how the group, also known …

Iranian APT Group Targets IP Cameras, Extends Attacks Beyond Israel
darkreading.com · 2024

An Iranian cyber-operations group, Emennet Pasargad --- also known as Cotton Sandstorm --- has broadened its attacks, expanding its targets beyond Israel and the United States and targeting new IT assets, such as IP cameras.

In an advisory …

America Resilient in the Face of Aggressive Foreign Malign Influence Targeting the 2024 U.S. Elections
fdd.org · 2024

America’s adversaries did not significantly affect the results of the 2024 U.S. elections — but not for lack of trying. Russia, Iran, and China waged aggressive influence operations targeting America’s political system, but America proved r…

Variants

A "variant" is an incident that shares the same causative factors, produces similar harms, and involves the same intelligent systems as a known AI incident. Rather than index variants as entirely separate incidents, we list variations of incidents under the first similar incident submitted to the database. Unlike other submission types to the incident database, variants are not required to have reporting in evidence external to the Incident Database. Learn more from the research paper.

Similar Incidents

By textual similarity

Did our AI mess up? Flag the unrelated incidents

Bug in Facebook’s Anti-Spam Filter Allegedly Blocked Legitimate Posts about COVID-19

Bug in Facebook’s Anti-Spam Filter Allegedly Blocked Legitimate Posts about COVID-19

Mar 2020 · 1 report
Warehouse robot ruptures can of bear spray and injures workers

Warehouse robot ruptures can of bear spray and injures workers

Dec 2018 · 17 reports
Fake LinkedIn Profiles Created Using GAN Photos

Fake LinkedIn Profiles Created Using GAN Photos

Feb 2022 · 4 reports
Previous IncidentNext Incident

Similar Incidents

By textual similarity

Did our AI mess up? Flag the unrelated incidents

Bug in Facebook’s Anti-Spam Filter Allegedly Blocked Legitimate Posts about COVID-19

Bug in Facebook’s Anti-Spam Filter Allegedly Blocked Legitimate Posts about COVID-19

Mar 2020 · 1 report
Warehouse robot ruptures can of bear spray and injures workers

Warehouse robot ruptures can of bear spray and injures workers

Dec 2018 · 17 reports
Fake LinkedIn Profiles Created Using GAN Photos

Fake LinkedIn Profiles Created Using GAN Photos

Feb 2022 · 4 reports

Research

  • Defining an “AI Incident”
  • Defining an “AI Incident Response”
  • Database Roadmap
  • Related Work
  • Download Complete Database

Project and Community

  • About
  • Contact and Follow
  • Apps and Summaries
  • Editor’s Guide

Incidents

  • All Incidents in List Form
  • Flagged Incidents
  • Submission Queue
  • Classifications View
  • Taxonomies

2023 - AI Incident Database

  • Terms of use
  • Privacy Policy
  • Open twitterOpen githubOpen rssOpen facebookOpen linkedin
  • 30ebe76