logo

UNC1549 Critical Infrastructure Espionage Attack

ID: d05d2498-3972-5019-a280-f1aebc3723da

STIX ID: report--d05d2498-3972-5019-a280-f1aebc3723da

Feed Name: FortiGuard Labs | FortiGuard Center - Outbreak Alerts

Threat Score
85/100

Date Published: 2025-12-02

Date Updated: 2026-07-28

...
...

Suspected Iran-linked APT UNC1549 is conducting targeted espionage against high-value aerospace, defense, and telecom organizations using tailored spear-phishing, credential theft, abuse of VDI (Citrix/VMware/Azure VDI), exploitation of Exchange-related vulnerabilities (CVE-2021-26855, CVE-2020-0688), and multiple custom malware/tools (MINIBIKE, TWOSTROKE, DEEPROOT, LIGHTRAIL, GHOSTLINE) to establish long-term persistence and exfiltrate sensitive technical data; FortiGuard and other vendors provide detections and mitigations and public reporting from Mandiant, Google, and FortiGuard is cited.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.