Iran hacking group impersonates defense firms, hostage campaigners
ID: c45f0528-46c7-5cf6-825e-75192d3fc6ec
STIX ID: report--c45f0528-46c7-5cf6-825e-75192d3fc6ec
Feed Name: CyberScoop
Threat Score
Mandiant attributes an active Iranian-sponsored espionage campaign (UNC1549) to IRGC-linked operators using fake job postings and a hostage-themed website to direct victims to compromised sites that either harvest credentials or install two novel backdoors (MINIBUS, MINIBIKE); targets include aerospace, aviation and defense organizations across the Middle East and the campaign employs Azure-based infrastructure to blend with legitimate traffic.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
