Emennet Pasargad (Microsoft's Cotton Sandstorm) is an IRGC-affiliated Iranian actor specializing in influence operations, hack-and-leak, and intimidation campaigns — responsible for 2020 U.S. election-interference, sustained anti-Israel information operations during the 2023-2026 Gaza conflict, and, since 2024, operations run under the cover front Aria Sepehr Ayandehsazan (ASA).
Additional names this actor is known by across other vendors' naming schemes — cross-referenced from external crosswalk sources, not RaqibCTI's own curated aliases (shown at the top of this page). Each source is attributed to its own licence.
Emennet Pasargad is an Iranian cyber company assessed as affiliated with the Islamic Revolutionary Guard Corps (IRGC); Microsoft tracks the same actor as Cotton Sandstorm, and other vendors as Haywire Kitten, Marnanbridge, Neptune, and Yellow Garuda. The U.S. government has acted against it repeatedly: a November 2021 DOJ indictment and FBI advisory attributed the 2020 U.S. election-interference operation to two Emennet Pasargad contractors, the Treasury sanctioned the company, and a Rewards for Justice bounty was issued. In October 2024 FBI/CISA published AA24-290A detailing continued influence operations under a new cover identity, Aria Sepehr Ayandehsazan (ASA).
IMPORTANT attribution distinction — this actor must not be re-conflated with two other Iranian clusters it superficially resembles. (1) It is IRGC-affiliated, whereas Void Manticore (Storm-0842 / Handala / Karma / Homeland Justice) is an MOIS actor focused on data-wiping and destructive hack-and-leak; Emennet Pasargad's mission is information operations and psychological effect, not endpoint destruction. (2) It is distinct from CyberAv3ngers, an IRGC Cyber-Electronic Command (IRGC-CEC) actor focused on OT/ICS attacks (Unitronics PLCs, IOCONTROL). All three use fabricated hacktivist/front personas — the likely source of prior conflation — but they are separate groups under different Iranian command structures and must be tracked distinctly.
Its tradecraft blends modest intrusion with heavy information warfare: compromise of vulnerable web/CMS infrastructure, theft of data (voter records, personal information, media assets), and amplification via fabricated personas, mass email/SMS intimidation, and approaches to media outlets. In 2020 it impersonated the Proud Boys to send threatening emails to U.S. voters, pushed a disinformation video, and probed election websites. During the 2023-2026 Israel-Hamas war and Iran-Israel escalation, ASA-run operations targeted Israeli audiences — hacking and streaming compromised IP cameras, and running Gaza- and 2024-Olympics-themed influence and intimidation activity — extending the anti-Israel mission across the MENA-relevant window.
MENA relevance centers on Israel, where Emennet Pasargad/ASA is among the most persistent Iranian influence and hack-and-leak actors, alongside its U.S./Western election- and event-themed operations. It is assessed as active into 2025-2026, continually rebranding personas and cover companies to sustain operations despite exposure and sanctions.