logo

Iran-Nexus Threat Actor UNC1549 Takes Aim at Aerospace

ID: f043026b-7a16-5366-a47b-7f02a3e5dd05

STIX ID: report--f043026b-7a16-5366-a47b-7f02a3e5dd05

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2025-11-18

Date Updated: 2026-04-21

Author: Alexander Culafi

...
...

Mandiant (Google Cloud) researchers report that UNC1549, an Iran-nexus espionage actor linked to IRGC interests, has conducted sustained campaigns since mid-2024 against aerospace, aviation, and defense sectors — often leveraging spear-phishing and compromised third-party suppliers to pivot into high-value targets; the actor uses custom backdoors and tools (Twostroke, Lightrail, Deeproot, DCSyncer.Slick), SSH reverse tunnels, and techniques to evade forensics and exfiltrate sensitive IP, emails, and network documentation, with activity expanding geographically to include the US, UAE, Qatar, Spain, Saudi Arabia, Israel, and Greece.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.