Microsoft's digital crimes unit says cyber crime attacks by nation-state actors are expected to increase in the coming years. Getty Images
Microsoft's digital crimes unit says cyber crime attacks by nation-state actors are expected to increase in the coming years. Getty Images
Microsoft's digital crimes unit says cyber crime attacks by nation-state actors are expected to increase in the coming years. Getty Images
Microsoft's digital crimes unit says cyber crime attacks by nation-state actors are expected to increase in the coming years. Getty Images

Iran Mint Sandstorm: how hackers and cyber criminals are nicknamed


Cody Combs
  • English
  • Arabic

Keeping track of people determined to wreak havoc through computer hacks and cyber crime isn’t easy, but Microsoft officials say naming the groups is a small but important step in stopping them.

Microsoft explained its naming system for nation-state-affiliated threat entities during The National's exclusive tour of the company's cyber crime centre in Redmond, Washington.

Microsoft's cyber crime centre uses cyber security experts from across the company to help protect, detect and respond to threats in real-time. Cody Combs / The National
Microsoft's cyber crime centre uses cyber security experts from across the company to help protect, detect and respond to threats in real-time. Cody Combs / The National

Mint Sandstorm, Storm-2035, Sefid Flood, Salt Typhoon, Cotton Sandstorm and Taizi Flood are just a few of the many names given to groups operating out of Iran, China, Russia and North Korea, which Microsoft told The National are home to some of the most active actors in the nation-state cyber crime space.

“We used to track everything as an element from the periodic table − like barium, strontium and phosphorus,” said Steven Masada, assistant general counsel of Microsoft's digital crimes unit, which leads the company's efforts to combat cyber crime around the world.

Mr Masada, who also served as assistant US attorney for the western district of Washington state, said that due to the sheer number of hacker and cyber crime groups around the world, Microsoft ran out of elements from the periodic table.

Microsoft said for the purposes of organising an increasing number of threats, it uses a naming taxonomy for threat actors based on weather.
Microsoft said for the purposes of organising an increasing number of threats, it uses a naming taxonomy for threat actors based on weather.

“So, we switched to the storm system, which despite some naysayers, has really caught on,” he added.

“Sleet is North Korea, Typhoon is China, Sandstorm is Iran and Blizzard is Russia,” Mr Masada continued, saying that once Microsoft researches the cyber criminals from various countries and their differing techniques, they add more details to the name, such as Mint Sandstorm, which was given to a nation-state nefarious computer cyber crime actor originating out of Iran.

Microsoft says its cybercrime defense operations centre is staffed 24 hours each day, seven days a week. Photo: Cody Combs
Microsoft says its cybercrime defense operations centre is staffed 24 hours each day, seven days a week. Photo: Cody Combs

For groups that aren't necessarily nation-state affiliated, Mr Masada said that other names are given.

“We use the word 'tempest' for financially motivated groups … there's one called Vanilla Tempest, which is an incredibly active ransomware group.

He added that any group with the word “flood” included in the name, is likely a disinformation or influence operation group.

Mr Masada said around the world there has been a significant increase in nation-state actor cyber crime activity. The 2024 US presidential election, coupled with the Israel-Gaza war, saw an uptick in cyber crime efforts based out of Iran.

Although Microsoft's cybercrimes centre is based in the company's headquarters of Redmond, Washington, it has branches and employees around the world. Cody Combs / The National
Although Microsoft's cybercrimes centre is based in the company's headquarters of Redmond, Washington, it has branches and employees around the world. Cody Combs / The National

“One example is Mint Sandstorm, it's an Iranian actor that we've taken action against … Mint Sandstorm targeted Donald Trump's campaign leading up to the most recent US election and hacked some senior advisers,” said Mr Masada.

In addition to sharing information with the hack victims and the US government, Mr Masada said Microsoft's digital crimes unit provided a criminal referral to the US Department of Justice, which later indicted three Iranians accused of the nefarious cyber activity.

The three men were allegedly employed by Iran’s Islamic Revolutionary Guard Corps, and their activities included a range of targets − including government officials, members of the media and non-governmental organisations, according to Justice Department.

Iran denied any involvement in Mint Sandstorm, yet the name, which originated from Microsoft, largely caught on.

“We do this purely to make it easy for professionals in the [cyber security] field to understand it all,” said Andrew Conway, vice president of security marketing at Microsoft.

“We associated a certain type of weather with a particular threat actor and then we made up modifiers for the types of weather,” he explained. One Russian group was given the name Midnight Blizzard.'

“We don't do this to glorify or try to make things cool, it's done for information design … we were expanding the number of threat actors that we tracked and we needed a hierarchy in which to refer to them,” said Mr Conway.

Microsoft recently released a threat intelligence report which it says shows an increased effort from hackers and cyber-influence group to impact the 2024 US presidential election. Photo: Microsoft
Microsoft recently released a threat intelligence report which it says shows an increased effort from hackers and cyber-influence group to impact the 2024 US presidential election. Photo: Microsoft

Microsoft has gone from tracking approximately 300 nefarious cyber crime groups to more than 1,500, he said.

Mr Conway said that although this naming convention seems to be catching on outside of Microsoft to some extent, not all companies, governments and organisations use the same naming system.

“There's no global standard for it,” he said.

Meanwhile, according to Microsoft, by 2028, estimates show that approximately $13 trillion could be lost to cyber crime tactics.

To blunt such cyber attacks, the Microsoft's cyber crime centre seeks to utilise security response experts from across the company to help protect, detect and respond to threats around the world.

It also uses AI to quicken the process of identifying potential threats or vulnerabilities as they come in.

Inside the cyber crime facility, there are specific offices occasionally used by the FBI, Secret Service and Department of Homeland Security to expedite investigations and collaboration efforts, depending on the cyber crime threats.

“We're increasingly seeing the blurring of lines where nation-state threat actors are becoming more sophisticated,” Mr Masada said.

“Microsoft, effectively, is a security company at this point in time,” he added, noting that besides ample technical and cyber security experts, the company also uses lawyers, investigators, data analysts and business professionals to blunt and prevent cyber crime.

According to the company, its digital crimes unit has disrupted 30 malware families, nation-state threat actors and distributors of malicious tools through civil actions resulting in the “rescue of more than 500 million victim devices”.

LILO & STITCH

Starring: Sydney Elizebeth Agudong, Maia Kealoha, Chris Sanders

Director: Dean Fleischer Camp

Rating: 4.5/5

MISSION: IMPOSSIBLE – FINAL RECKONING

Director: Christopher McQuarrie

Starring: Tom Cruise, Hayley Atwell, Simon Pegg

Rating: 4/5

PSG's line up

GK: Alphonse Areola (youth academy)

Defence - RB: Dani Alves (free transfer); CB: Marquinhos (€31.4 million); CB: Thiago Silva (€42m); LB: Layvin Kurzawa (€23m)

Midfield - Angel di Maria (€47m); Adrien Rabiot (youth academy); Marco Verratti (€12m)

Forwards - Neymar (€222m); Edinson Cavani (€63m); Kylian Mbappe (initial: loan; to buy: €180m)

Total cost: €440.4m (€620.4m if Mbappe makes permanent move)

 

 

Strait of Hormuz

Fujairah is a crucial hub for fuel storage and is just outside the Strait of Hormuz, a vital shipping route linking Middle East oil producers to markets in Asia, Europe, North America and beyond.

The strait is 33 km wide at its narrowest point, but the shipping lane is just three km wide in either direction. Almost a fifth of oil consumed across the world passes through the strait.

Iran has repeatedly threatened to close the strait, a move that would risk inviting geopolitical and economic turmoil.

Last month, Iran issued a new warning that it would block the strait, if it was prevented from using the waterway following a US decision to end exemptions from sanctions for major Iranian oil importers.

SPECS
%3Cp%3E%3Cstrong%3EEngine%3C%2Fstrong%3E%3A%202-litre%20direct%20injection%20turbo%20%0D%3Cbr%3E%3Cstrong%3ETransmission%3C%2Fstrong%3E%3A%207-speed%20automatic%20%0D%3Cbr%3E%3Cstrong%3EPower%3C%2Fstrong%3E%3A%20261hp%20%0D%3Cbr%3E%3Cstrong%3ETorque%3C%2Fstrong%3E%3A%20400Nm%20%0D%3Cbr%3E%3Cstrong%3EPrice%3C%2Fstrong%3E%3A%20From%20Dh134%2C999%26nbsp%3B%3C%2Fp%3E%0A
MATCH INFO

Watford 1 (Deulofeu 80' p)

Chelsea 2 (Abraham 5', Pulisic 55')

Company profile

Date started: December 24, 2018

Founders: Omer Gurel, chief executive and co-founder and Edebali Sener, co-founder and chief technology officer

Based: Dubai Media City

Number of employees: 42 (34 in Dubai and a tech team of eight in Ankara, Turkey)

Sector: ConsumerTech and FinTech

Cashflow: Almost $1 million a year

Funding: Series A funding of $2.5m with Series B plans for May 2020

Our legal consultants

Name: Hassan Mohsen Elhais

Position: legal consultant with Al Rowaad Advocates and Legal Consultants.

WHAT%20START-UPS%20IS%20VISA%20SEEKING%3F
%3Cp%3E%3Cstrong%3EEnablers%20of%20digital%20services%3C%2Fstrong%3E%3Cbr%3E%E2%80%A2%20Blockchain%20and%20cryptocurrency%3Cbr%3E%E2%80%A2%20Crowdfunding%3Cbr%3E%E2%80%A2%20Banking-as-a-service%3Cbr%3E%E2%80%A2%20Banking%20identification%20number%20sponsors%3Cbr%3E%E2%80%A2%20Issuers%2Fprocessors%3Cbr%3E%E2%80%A2%20Programme%20managers%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EDigital%20issuance%3C%2Fstrong%3E%3Cbr%3E%E2%80%A2%20Blockchain%20and%20cryptocurrency%3Cbr%3E%E2%80%A2%20Alternative%20lending%3Cbr%3E%E2%80%A2%20Personal%20financial%20management%3Cbr%3E%E2%80%A2%20Money%20transfer%20and%20remittance%3Cbr%3E%E2%80%A2%20Digital%20banking%20(neo%20banks)%3Cbr%3E%E2%80%A2%20Digital%20wallets%2C%20peer-to-peer%20and%20transfers%3Cbr%3E%E2%80%A2%20Employee%20benefits%3Cbr%3E%E2%80%A2%20Payables%3Cbr%3E%E2%80%A2%20Corporate%20cards%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EValue-add%20for%20merchants%2Fconsumers%3C%2Fstrong%3E%3Cbr%3E%E2%80%A2%20Data%20and%20analytics%3Cbr%3E%E2%80%A2%20ID%2C%20authentication%20and%20security%3Cbr%3E%E2%80%A2%20Insurance%20technology%3Cbr%3E%E2%80%A2%20Loyalty%3Cbr%3E%E2%80%A2%20Merchant%20services%20and%20tools%3Cbr%3E%E2%80%A2%20Process%20and%20payment%20infrastructure%3Cbr%3E%E2%80%A2%20Retail%20technology%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3ESME%20recovery%3C%2Fstrong%3E%3Cbr%3E%E2%80%A2%20Money%20movement%3Cbr%3E%E2%80%A2%20Acceptance%3Cbr%3E%E2%80%A2%20Risk%20management%3Cbr%3E%E2%80%A2%20Brand%20management%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3ENew%20categories%20for%202023%3C%2Fstrong%3E%3Cbr%3E%E2%80%A2%20Sustainable%20FinTechs%3Cbr%3E%E2%80%A2%20Risk%3Cbr%3E%E2%80%A2%20Urban%20mobility%3C%2Fp%3E%0A
The specs: 2018 BMW R nineT Scrambler

Price, base / as tested Dh57,000

Engine 1,170cc air/oil-cooled flat twin four-stroke engine

Transmission Six-speed gearbox

Power 110hp) @ 7,750rpm

Torque 116Nm @ 6,000rpm

Fuel economy, combined 5.3L / 100km

Living in...

This article is part of a guide on where to live in the UAE. Our reporters will profile some of the country’s most desirable districts, provide an estimate of rental prices and introduce you to some of the residents who call each area home.

The five pillars of Islam

1. Fasting 

2. Prayer 

3. Hajj 

4. Shahada 

5. Zakat 

Heather, the Totality
Matthew Weiner,
Canongate 

Updated: January 24, 2025, 7:53 AM`