UNC1549 Critical Infrastructure Espionage Attack
ID: d05d2498-3972-5019-a280-f1aebc3723da
STIX ID: report--d05d2498-3972-5019-a280-f1aebc3723da
Feed Name: FortiGuard Labs | FortiGuard Center - Outbreak Alerts
Suspected Iran-linked APT UNC1549 is conducting targeted espionage against high-value aerospace, defense, and telecom organizations using tailored spear-phishing, credential theft, abuse of VDI (Citrix/VMware/Azure VDI), exploitation of Exchange-related vulnerabilities (CVE-2021-26855, CVE-2020-0688), and multiple custom malware/tools (MINIBIKE, TWOSTROKE, DEEPROOT, LIGHTRAIL, GHOSTLINE) to establish long-term persistence and exfiltrate sensitive technical data; FortiGuard and other vendors provide detections and mitigations and public reporting from Mandiant, Google, and FortiGuard is cited.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
