Iran-Nexus Threat Actor UNC1549 Takes Aim at Aerospace
ID: f043026b-7a16-5366-a47b-7f02a3e5dd05
STIX ID: report--f043026b-7a16-5366-a47b-7f02a3e5dd05
Feed Name: Dark Reading
Mandiant (Google Cloud) researchers report that UNC1549, an Iran-nexus espionage actor linked to IRGC interests, has conducted sustained campaigns since mid-2024 against aerospace, aviation, and defense sectors — often leveraging spear-phishing and compromised third-party suppliers to pivot into high-value targets; the actor uses custom backdoors and tools (Twostroke, Lightrail, Deeproot, DCSyncer.Slick), SSH reverse tunnels, and techniques to evade forensics and exfiltrate sensitive IP, emails, and network documentation, with activity expanding geographically to include the US, UAE, Qatar, Spain, Saudi Arabia, Israel, and Greece.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
