logo

Iran hacking group impersonates defense firms, hostage campaigners

ID: c45f0528-46c7-5cf6-825e-75192d3fc6ec

STIX ID: report--c45f0528-46c7-5cf6-825e-75192d3fc6ec

Feed Name: CyberScoop

Threat Score
85/100

Date Published: 2024-02-28

Date Updated: 2026-04-21

Author: AJ Vicens

...
...

Mandiant attributes an active Iranian-sponsored espionage campaign (UNC1549) to IRGC-linked operators using fake job postings and a hostage-themed website to direct victims to compromised sites that either harvest credentials or install two novel backdoors (MINIBUS, MINIBIKE); targets include aerospace, aviation and defense organizations across the Middle East and the campaign employs Azure-based infrastructure to blend with legitimate traffic.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.