logo

UNC1549 Critical Infrastructure Espionage Attack

ID: c2280223-9232-543a-8b49-420e2cb36d4a

STIX ID: report--c2280223-9232-543a-8b49-420e2cb36d4a

Feed Name: FortiGuard Threat Signals

Threat Score
85/100

Date Published: 2025-12-03

Date Updated: 2026-07-28

...
...

This Outbreak Alert warns of active exploitation of critical on‑premises Microsoft Exchange zero‑day vulnerabilities (affecting Exchange Server 2013, 2016, 2019) and describes Iran‑linked cyber operations, including activity by UNC1549, that target aerospace, defense, and telecommunications across multiple regions. The actors use spear‑phishing, credential theft from third‑party services, and abuse of virtual desktop infrastructure (Citrix, VMware, Azure VDI) to gain initial access and move laterally; the report emphasizes patching exposed systems and monitoring for related tactics and exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.