Lemon Sandstorm

Threat Actor updated a month ago (2024-11-29T13:53:56.473Z)
Download STIX
Preview STIX
Lemon Sandstorm, also known as Pioneer Kitten, Rubidium, Parasite, and Fox Kitten, is a threat actor group believed to originate from Iran. This group has been involved in executing actions with malicious intent, primarily through ransomware attacks targeting various countries. The group's activities have been diverse and widespread, causing significant concern within the cybersecurity industry due to its apparent lack of standard naming conventions and the complexity of its operations. In the recent past, Lemon Sandstorm has been particularly active. Late last month, the US Cybersecurity and Infrastructure Security Agency (CISA) issued a warning about the group's heightened activity, noting that it had launched ransomware attacks against multiple nations. In addition, another Iranian group, Charming Kitten or APT42, was reported to have targeted individuals associated with both Democratic and Republican presidential campaigns, further escalating the situation. Today, CISA, in collaboration with the Federal Bureau of Investigation (FBI) and the Department of Defense Cyber Crime Center (DC3), released a joint advisory on Iran-based cyber actors enabling ransomware attacks on U.S. organizations. This advisory specifically identifies Lemon Sandstorm, among others, as being responsible for targeting and exploiting U.S. and foreign organizations across multiple sectors. As a result, there is an urgent need for increased vigilance and enhanced cybersecurity measures to counteract these ongoing threats.
Description last updated: 2024-10-17T12:07:28.412Z
What's your take? (Question 1 of 1)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at. Create a free account to see the source evidence for each alias, and help fix any errors.
Alias DescriptionVotes
Pioneer Kitten is a possible alias for Lemon Sandstorm. Pioneer Kitten, also known as UNC757, Parisite, Lemon Sandstorm, and Rubidium, is a threat actor believed to be associated with the Government of Iran (GOI) and an Iranian IT company. This group has been tracked by various cybersecurity entities such as CrowdStrike Intelligence and the FBI. Investig
2
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Ransomware
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the Lemon Sandstorm Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more