Microsoft's digital crimes unit says cyber crime attacks by nation-state actors are expected to increase in the coming years. Getty Images
Microsoft's digital crimes unit says cyber crime attacks by nation-state actors are expected to increase in the coming years. Getty Images
Microsoft's digital crimes unit says cyber crime attacks by nation-state actors are expected to increase in the coming years. Getty Images
Microsoft's digital crimes unit says cyber crime attacks by nation-state actors are expected to increase in the coming years. Getty Images

Iran Mint Sandstorm: how hackers and cyber criminals are nicknamed


Cody Combs
  • English
  • Arabic

Keeping track of people determined to wreak havoc through computer hacks and cyber crime isn’t easy, but Microsoft officials say naming the groups is a small but important step in stopping them.

Microsoft explained its naming system for nation-state-affiliated threat entities during The National's exclusive tour of the company's cyber crime centre in Redmond, Washington.

Microsoft's cyber crime centre uses cyber security experts from across the company to help protect, detect and respond to threats in real-time. Cody Combs / The National
Microsoft's cyber crime centre uses cyber security experts from across the company to help protect, detect and respond to threats in real-time. Cody Combs / The National

Mint Sandstorm, Storm-2035, Sefid Flood, Salt Typhoon, Cotton Sandstorm and Taizi Flood are just a few of the many names given to groups operating out of Iran, China, Russia and North Korea, which Microsoft told The National are home to some of the most active actors in the nation-state cyber crime space.

“We used to track everything as an element from the periodic table − like barium, strontium and phosphorus,” said Steven Masada, assistant general counsel of Microsoft's digital crimes unit, which leads the company's efforts to combat cyber crime around the world.

Mr Masada, who also served as assistant US attorney for the western district of Washington state, said that due to the sheer number of hacker and cyber crime groups around the world, Microsoft ran out of elements from the periodic table.

Microsoft said for the purposes of organising an increasing number of threats, it uses a naming taxonomy for threat actors based on weather.
Microsoft said for the purposes of organising an increasing number of threats, it uses a naming taxonomy for threat actors based on weather.

“So, we switched to the storm system, which despite some naysayers, has really caught on,” he added.

“Sleet is North Korea, Typhoon is China, Sandstorm is Iran and Blizzard is Russia,” Mr Masada continued, saying that once Microsoft researches the cyber criminals from various countries and their differing techniques, they add more details to the name, such as Mint Sandstorm, which was given to a nation-state nefarious computer cyber crime actor originating out of Iran.

Microsoft says its cybercrime defense operations centre is staffed 24 hours each day, seven days a week. Photo: Cody Combs
Microsoft says its cybercrime defense operations centre is staffed 24 hours each day, seven days a week. Photo: Cody Combs

For groups that aren't necessarily nation-state affiliated, Mr Masada said that other names are given.

“We use the word 'tempest' for financially motivated groups … there's one called Vanilla Tempest, which is an incredibly active ransomware group.

He added that any group with the word “flood” included in the name, is likely a disinformation or influence operation group.

Mr Masada said around the world there has been a significant increase in nation-state actor cyber crime activity. The 2024 US presidential election, coupled with the Israel-Gaza war, saw an uptick in cyber crime efforts based out of Iran.

Although Microsoft's cybercrimes centre is based in the company's headquarters of Redmond, Washington, it has branches and employees around the world. Cody Combs / The National
Although Microsoft's cybercrimes centre is based in the company's headquarters of Redmond, Washington, it has branches and employees around the world. Cody Combs / The National

“One example is Mint Sandstorm, it's an Iranian actor that we've taken action against … Mint Sandstorm targeted Donald Trump's campaign leading up to the most recent US election and hacked some senior advisers,” said Mr Masada.

In addition to sharing information with the hack victims and the US government, Mr Masada said Microsoft's digital crimes unit provided a criminal referral to the US Department of Justice, which later indicted three Iranians accused of the nefarious cyber activity.

The three men were allegedly employed by Iran’s Islamic Revolutionary Guard Corps, and their activities included a range of targets − including government officials, members of the media and non-governmental organisations, according to Justice Department.

Iran denied any involvement in Mint Sandstorm, yet the name, which originated from Microsoft, largely caught on.

“We do this purely to make it easy for professionals in the [cyber security] field to understand it all,” said Andrew Conway, vice president of security marketing at Microsoft.

“We associated a certain type of weather with a particular threat actor and then we made up modifiers for the types of weather,” he explained. One Russian group was given the name Midnight Blizzard.'

“We don't do this to glorify or try to make things cool, it's done for information design … we were expanding the number of threat actors that we tracked and we needed a hierarchy in which to refer to them,” said Mr Conway.

Microsoft recently released a threat intelligence report which it says shows an increased effort from hackers and cyber-influence group to impact the 2024 US presidential election. Photo: Microsoft
Microsoft recently released a threat intelligence report which it says shows an increased effort from hackers and cyber-influence group to impact the 2024 US presidential election. Photo: Microsoft

Microsoft has gone from tracking approximately 300 nefarious cyber crime groups to more than 1,500, he said.

Mr Conway said that although this naming convention seems to be catching on outside of Microsoft to some extent, not all companies, governments and organisations use the same naming system.

“There's no global standard for it,” he said.

Meanwhile, according to Microsoft, by 2028, estimates show that approximately $13 trillion could be lost to cyber crime tactics.

To blunt such cyber attacks, the Microsoft's cyber crime centre seeks to utilise security response experts from across the company to help protect, detect and respond to threats around the world.

It also uses AI to quicken the process of identifying potential threats or vulnerabilities as they come in.

Inside the cyber crime facility, there are specific offices occasionally used by the FBI, Secret Service and Department of Homeland Security to expedite investigations and collaboration efforts, depending on the cyber crime threats.

“We're increasingly seeing the blurring of lines where nation-state threat actors are becoming more sophisticated,” Mr Masada said.

“Microsoft, effectively, is a security company at this point in time,” he added, noting that besides ample technical and cyber security experts, the company also uses lawyers, investigators, data analysts and business professionals to blunt and prevent cyber crime.

According to the company, its digital crimes unit has disrupted 30 malware families, nation-state threat actors and distributors of malicious tools through civil actions resulting in the “rescue of more than 500 million victim devices”.

Specs

Engine: 51.5kW electric motor

Range: 400km

Power: 134bhp

Torque: 175Nm

Price: From Dh98,800

Available: Now

How to apply for a drone permit
  • Individuals must register on UAE Drone app or website using their UAE Pass
  • Add all their personal details, including name, nationality, passport number, Emiratis ID, email and phone number
  • Upload the training certificate from a centre accredited by the GCAA
  • Submit their request
What are the regulations?
  • Fly it within visual line of sight
  • Never over populated areas
  • Ensure maximum flying height of 400 feet (122 metres) above ground level is not crossed
  • Users must avoid flying over restricted areas listed on the UAE Drone app
  • Only fly the drone during the day, and never at night
  • Should have a live feed of the drone flight
  • Drones must weigh 5 kg or less
The%20Hunger%20Games%3A%20The%20Ballad%20of%20Songbirds%20%26%20Snakes
%3Cp%3E%3Cstrong%3EDirector%3A%3C%2Fstrong%3E%C2%A0Francis%20Lawrence%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EStars%3A%C2%A0%3C%2Fstrong%3ERachel%20Zegler%2C%20Peter%20Dinklage%2C%20Viola%20Davis%2C%20Tom%20Blyth%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3ERating%3A%20%3C%2Fstrong%3E3%2F5%3C%2Fp%3E%0A
ESSENTIALS

The flights

Emirates flies from Dubai to Phnom Penh via Yangon from Dh2,700 return including taxes. Cambodia Bayon Airlines and Cambodia Angkor Air offer return flights from Phnom Penh to Siem Reap from Dh250 return including taxes. The flight takes about 45 minutes.

The hotels

Rooms at the Raffles Le Royal in Phnom Penh cost from $225 (Dh826) per night including taxes. Rooms at the Grand Hotel d'Angkor cost from $261 (Dh960) per night including taxes.

The tours

A cyclo architecture tour of Phnom Penh costs from $20 (Dh75) per person for about three hours, with Khmer Architecture Tours. Tailor-made tours of all of Cambodia, or sites like Angkor alone, can be arranged by About Asia Travel. Emirates Holidays also offers packages. 

Sheer grandeur

The Owo building is 14 storeys high, seven of which are below ground, with the 30,000 square feet of amenities located subterranean, including a 16-seat private cinema, seven lounges, a gym, games room, treatment suites and bicycle storage.

A clear distinction between the residences and the Raffles hotel with the amenities operated separately.

Tips to stay safe during hot weather
  • Stay hydrated: Drink plenty of fluids, especially water. Avoid alcohol and caffeine, which can increase dehydration.
  • Seek cool environments: Use air conditioning, fans, or visit community spaces with climate control.
  • Limit outdoor activities: Avoid strenuous activity during peak heat. If outside, seek shade and wear a wide-brimmed hat.
  • Dress appropriately: Wear lightweight, loose and light-coloured clothing to facilitate heat loss.
  • Check on vulnerable people: Regularly check in on elderly neighbours, young children and those with health conditions.
  • Home adaptations: Use blinds or curtains to block sunlight, avoid using ovens or stoves, and ventilate living spaces during cooler hours.
  • Recognise heat illness: Learn the signs of heat exhaustion and heat stroke (dizziness, confusion, rapid pulse, nausea), and seek medical attention if symptoms occur.
Company%20profile
%3Cp%3E%3Cstrong%3ECompany%20name%3A%3C%2Fstrong%3E%20Ogram%3Cbr%3E%3Cstrong%3EStarted%3A%20%3C%2Fstrong%3E2017%3Cbr%3E%3Cstrong%3EFounders%3A%3C%2Fstrong%3E%20Karim%20Kouatly%20and%20Shafiq%20Khartabil%3Cbr%3E%3Cstrong%3EBased%3A%20%3C%2Fstrong%3EDubai%2C%20UAE%3Cbr%3E%3Cstrong%3EIndustry%3A%3C%2Fstrong%3E%20On-demand%20staffing%3Cbr%3E%3Cstrong%3ENumber%20of%20employees%3A%3C%2Fstrong%3E%2050%3Cbr%3E%3Cstrong%3EFunding%3A%20%3C%2Fstrong%3EMore%20than%20%244%20million%3Cbr%3E%3Cstrong%3EFunding%20round%3A%3C%2Fstrong%3E%20Series%20A%3Cbr%3E%3Cstrong%3EInvestors%3A%20%3C%2Fstrong%3EGlobal%20Ventures%2C%20Aditum%20and%20Oraseya%20Capital%3Cbr%3E%3C%2Fp%3E%0A
Ticket prices

General admission Dh295 (under-three free)

Buy a four-person Family & Friends ticket and pay for only three tickets, so the fourth family member is free

Buy tickets at: wbworldabudhabi.com/en/tickets

W.
Wael Kfoury
(Rotana)

The Meg
Director: Jon Turteltaub
Starring:   
Two stars

What are the GCSE grade equivalents?
 
  • Grade 9 = above an A*
  • Grade 8 = between grades A* and A
  • Grade 7 = grade A
  • Grade 6 = just above a grade B
  • Grade 5 = between grades B and C
  • Grade 4 = grade C
  • Grade 3 = between grades D and E
  • Grade 2 = between grades E and F
  • Grade 1 = between grades F and G
FIGHT CARD

 

1.           Featherweight 66kg

Ben Lucas (AUS) v Ibrahim Kendil (EGY)

2.           Lightweight 70kg

Mohammed Kareem Aljnan (SYR) v Alphonse Besala (CMR)

3.           Welterweight 77kg

Marcos Costa (BRA) v Abdelhakim Wahid (MAR)

4.           Lightweight 70kg

Omar Ramadan (EGY) v Abdimitalipov Atabek (KGZ)

5.           Featherweight 66kg

Ahmed Al Darmaki (UAE) v Kagimu Kigga (UGA)

6.           Catchweight 85kg

Ibrahim El Sawi (EGY) v Iuri Fraga (BRA)

7.           Featherweight 66kg

Yousef Al Husani (UAE) v Mohamed Allam (EGY)

8.           Catchweight 73kg

Mostafa Radi (PAL) v Abdipatta Abdizhali (KGZ)

9.           Featherweight 66kg

Jaures Dea (CMR) v Andre Pinheiro (BRA)

10.         Catchweight 90kg

Tarek Suleiman (SYR) v Juscelino Ferreira (BRA)

Global state-owned investor ranking by size

1.

United States

2.

China

3.

UAE

4.

Japan

5

Norway

6.

Canada

7.

Singapore

8.

Australia

9.

Saudi Arabia

10.

South Korea

RACE CARD

6.30pm Mazrat Al Ruwayah – Group 2 (PA) $36,000 (Dirt) 1,600m

7.05pm Handicap (TB) $68,000 (Turf) 2,410m

7.40pm Meydan Trophy – Conditions (TB) $50,000 (T) 1,900m

8.15pm Al Maktoum Challenge Round 2 - Group 2 (TB) $293,000 (D) 1,900m

8.50pm Al Rashidiya – Group 2 (TB) $163,000 (T) 1,800m

9.25pm Handicap (TB) $65,000 (T) 1,000m

The candidates

Dr Ayham Ammora, scientist and business executive

Ali Azeem, business leader

Tony Booth, professor of education

Lord Browne, former BP chief executive

Dr Mohamed El-Erian, economist

Professor Wyn Evans, astrophysicist

Dr Mark Mann, scientist

Gina MIller, anti-Brexit campaigner

Lord Smith, former Cabinet minister

Sandi Toksvig, broadcaster

 

'Falling%20for%20Christmas'
%3Cp%3EDirector%3A%20Janeen%20Damian%3Cbr%3E%3Cbr%3EStars%3A%20Lindsay%20Lohan%2C%20Chord%20Overstreet%2C%20Jack%20Wagner%2C%20Aliana%20Lohan%3Cbr%3E%3Cbr%3ERating%3A%201%2F5%3C%2Fp%3E%0A
What%20is%20cystic%20fibrosis%3F
%3Cul%3E%0A%3Cli%3ECystic%20fibrosis%20is%20a%20genetic%20disorder%20that%20affects%20the%20lungs%2C%20pancreas%20and%20other%20organs.%3C%2Fli%3E%0A%3Cli%3EIt%20causes%20the%20production%20of%20thick%2C%20sticky%20mucus%20that%20can%20clog%20the%20airways%20and%20lead%20to%20severe%20respiratory%20and%20digestive%20problems.%3C%2Fli%3E%0A%3Cli%3EPatients%20with%20the%20condition%20are%20prone%20to%20lung%20infections%20and%20often%20suffer%20from%20chronic%20coughing%2C%20wheezing%20and%20shortness%20of%20breath.%3C%2Fli%3E%0A%3Cli%3ELife%20expectancy%20for%20sufferers%20of%20cystic%20fibrosis%20is%20now%20around%2050%20years.%3C%2Fli%3E%0A%3C%2Ful%3E%0A
The specs

Engine: 2.3-litre, turbo four-cylinder

Transmission: 10-speed auto

Power: 300hp

Torque: 420Nm

Price: Dh189,900

On sale: now

Updated: January 24, 2025, 7:53 AM`