Iran-Linked UNC1549 Hackers Target Middle East Aerospace & Defense Sectors
ID: 23046bcf-1240-5c09-a1a9-ae41c3eb2968
STIX ID: report--23046bcf-1240-5c09-a1a9-ae41c3eb2968
Feed Name: The Hacker News
Threat Score
Mandiant attributes ongoing Iran-nexus cyber espionage by UNC1549 against aerospace, aviation, and defense organizations in the Middle East (and other countries) since at least June 2022; the actor uses Azure cloud for C2, spear-phishing job- and Israel-Hamas-themed lures, and custom backdoors MINIBIKE and MINIBUS plus a tunneling tool LIGHTRAIL to collect intelligence and move within networks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
