This is the Trace Id: c4b0e5271d80c5d1930f966cfc67adf7

Unmasking cyberthreat actors: Join Microsoft Security at Black Hat 2025 in August. Register now.

Nation State Actor

Hazel Sandstorm

Blue hexagon pattern with O/O text.
Hazel Sandstorm (formerly EUROPIUM) has been publicly linked to Iran’s Ministry of Intelligence and Security (MOIS). Microsoft assessed with high confidence that on July 15, 2022, actors sponsored by the Iranian government conducted a destructive cyberattack against the Albanian government, disrupting government websites and public services. Microsoft Threat Intelligence teams assess with moderate confidence that the actors linked to the state-sponsored actor, Hazel Sandstorm, gained initial access and exfiltrated data as part of this destructive cyberattack.

DETAILS

Country of origin:

Countries targeted:

Industries targeted:

Microsoft Threat Intelligence: Recent Hazel Sandstorm Articles

Microsoft investigates Iranian attacks against the Albanian government

Follow Microsoft Security