RST TI Report Digest: 24 Nov 2025
ID: c846665a-eeef-513e-986c-9d846f513d1d
STIX ID: report--c846665a-eeef-513e-986c-9d846f513d1d
Feed Name: RST Cloud Blog
UNC1549, an Iranian-linked APT, targets the aerospace and defense ecosystem using social engineering and compromised third-party accounts to gain access. The report describes custom backdoors (MINIBIKE, TWOSTROKE, DEEPROOT), persistence and evasion techniques (DLL search order hijacking, use of legitimate code-signing certificates), credential theft and reconnaissance, and the use of Microsoft Azure Web Apps for command-and-control, and includes a list of IPs, domains, and file hashes as IoCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
